Post the job and hope for an overlap
Recruitment takes longer than the notice period essentially always, so the overlap does not happen. The new person arrives to an estate nobody can explain and spends their first six months rediscovering it.
What lived in one person's head is about to leave the building.
The instinct is to start recruiting, and that is the second thing to do. The first is to get out of one person's memory everything that exists nowhere else, because the notice period is the only time when the person who knows and the systems they know are both still here. Most of what matters is not technical documentation. It is which vendor to call, which server must never be rebooted on a Tuesday, and which account is in whose name.
The visible problem is rarely the one that decides how this goes. These are the parts that are true whether or not anybody has said them out loud.
There is usually documentation. What is missing is the part that was never written because one person always knew it: the exceptions, the workarounds, and the reasons.
Domain registrar, tenant global admin, the backup console, the firewall. Frequently in an individual's name, sometimes on a personal email address, and always discovered at the worst moment.
The MSP account manager, the line-of-business software rep, the electrician who knows the comms room. None of these are on a contract and all of them were one person's phone.
Replace like for like, hand it to the MSP, or change the shape of the function. That is a considered decision and it is about to be made in a hurry.
Recruitment takes longer than the notice period essentially always, so the overlap does not happen. The new person arrives to an estate nobody can explain and spends their first six months rediscovering it.
Treat the notice period as a knowledge transfer project with a checklist, and make the successor decision afterwards with the estate written down. The hire is easier, the MSP conversation is fairer, and neither is made from a position of not knowing.
The order matters more than the individual steps. Most of the cost in these situations comes from doing the right things in the wrong sequence.
Every administrative account, every domain, every licence portal, every vendor login. Whose name it is in, and what happens to it on the last day.
Interviews against a checklist, recorded, covering the exceptions and the reasons rather than the parts already written down.
What the systems say, from their own exports, checked against what you were told. This is where the gaps between the two show up while somebody is still here to ask.
Hire, outsource, or fractional leadership over a managed service. Made calmly, with an inventory in hand, rather than in the first fortnight.
Each of these has a real answer and a plausible one. Knowing which you are giving is most of the job.
Which administrative accounts are in an individual's name?
What runs where, and who else can get into it today?
What do we do on the day their access is revoked?
Do we need the same role again, or a different shape?