The short answer: recover access first, then screen
A company locked out of its own Microsoft 365 or Google Workspace tenant can still qualify to license its data. A former MSP sitting on the passwords does not take ownership of the company's records. What it does do is stop the process at step one: nobody can inventory, scope or export records the company cannot reach, and "nobody can export the data" is one of the red flags that parks a company. Recover admin control, confirm what history survived, then make the introduction.
For an incoming MSP this is a familiar first project. It is also why you may be the best person to raise data licensing: within weeks you will know more about the company's systems and history than anyone outside it.
What is actually true when a former MSP holds the keys
- Credentials are not ownership. Records employees create as part of their jobs generally belong to the employer; the US Copyright Office's circular on works made for hire explains that for such works the employer, not the individual, is the author and owner. A former provider holding the passwords does not change that.
- The contract sets the exit terms. The services agreement's termination, transition-assistance and data-return clauses usually govern what the former MSP must hand over and when. Read them before escalating.
- Vendors have owner-recovery routes. Major cloud platforms and domain registrars generally offer a documented way for a verified business owner to regain admin control, often by proving control of the company's domain. Follow each vendor's own process.
- Some records were never the company's. Tickets, notes and scripts in the former MSP's own ticketing and remote-management tools are the MSP's business records. The company can license what it created, not its old provider's systems.
- Lapsed subscriptions put history at risk. If billing ran through the former MSP and stops, accounts and their data can be suspended or deleted under the vendor's retention rules. That makes recovery urgent.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting on a contract dispute.
Which systems to recover and why each matters
| System | Typical recovery route | Why it matters for licensing |
|---|---|---|
| Microsoft 365 or Google Workspace tenant | Vendor ownership verification, usually through the company's domain | Years of email, chat and shared documents, often the deepest history |
| Domain registrar and DNS | Registrar account recovery with business documents | Needed to prove domain control for most other recoveries |
| CRM, accounting, field-service and other SaaS the company pays for directly | Vendor support reassigns admin to a verified officer | Structured records with outcomes: deals, invoices, jobs |
| Backups in the former MSP's backup account | Export or transfer under the services agreement | May hold deleted mailboxes and older file versions |
| On-premises servers and storage | Physical possession plus a local admin reset | Legacy file shares and old line-of-business databases |
| Former MSP's own ticketing and remote tools | Not recoverable as company data | Belongs to the MSP; ask only for copies of the company's documentation |
Why admin control comes before any inventory or export
A data inventory lists each system, how many years it covers and what can be exported. Without admin access none of that can be checked: retention policies, archive mailboxes, legal holds and deleted-item recovery are all admin-only views.
Control also decides who acts for the company. If a deal happens, the company directs any export itself, and only once a license is signed, delivery is approved and the redaction terms set at the outset are in place. In your referral role you never export, upload or describe confidential records to SourceX; you make the introduction and share basic fit information.
The keys-first sequence for an incoming MSP
- Get authority in writing. An owner, CEO or CFO signs a letter naming your firm as IT provider and authorizing recovery of every tenant and account.
- Map from the outside. Use invoices, the domain registrar, user devices and staff memory to list every platform, its license count and who pays for it.
- Ask the former MSP formally. Send a dated written request under the services agreement for admin credentials, MFA and break-glass accounts, backup exports and documentation.
- Start vendor recovery in parallel. Do not wait on the former MSP; open ownership-verification cases with each vendor on day one.
- Lock it down. Remove the former MSP's delegated and partner access, rotate credentials, review audit logs and set retention so nothing ages out while the company decides.
- Record what survived. Note date ranges, gaps and any systems lost; honest gaps beat optimistic guesses.
- Then screen. Try the company fit checker for a preliminary read, then check the result against the who qualifies baseline.
If the hold-up is a billing dispute, keep it separate from recovery and let the company's counsel handle it.
What to say
To the former MSP, keep it short and contractual:
To the client owner, once access is back:
When the concern is valid
Sometimes lost access really does end the conversation, at least for now:
- The tenant was deleted after subscriptions lapsed and no backup survives.
- The only backups sit with the former MSP and it will not release them.
- Servers were wiped, or the hardware left with the old provider.
- Ownership or authority is disputed, for example between departed founders, or a lawsuit with the former MSP is active.
- What survived is too thin: a few recent years in one or two systems will not show several years of operations across many systems.
In these cases, list what survived honestly. SaaS the company contracted directly, such as CRM, accounting or field-service tools, may hold years of history the MSP never controlled. Offline and paper archives can be described too; see whether older paper records count. Check headcount at the same time: for carriers that rely on owner-operators, the trucking headcount question explains how the 50+ full-time employees at peak (contractors excluded) baseline applies. For clinics and care agencies, patient records follow stricter rules, covered on the home health page.
How the reward works for the incoming MSP
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. It is paid only after the buyer pays and SourceX receives its fee; a lead, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed. The reward comes out of SourceX's fee, never out of the client's proceeds.
Tell the client you are a referral partner before you introduce them; it protects the trust you earned by getting their systems back. The managed service providers page covers which MSP clients tend to fit and how to raise the topic.
Next step
Finish the recovery and document what survived. Then register as a partner to get your referral link, and either submit the client through the referral form or send the owner the link so they can start at sourcex.si/apply with your credit attached.