A facility can be fully staffed on paper and still depend on one person for the work that keeps it operating. The manager knows which gate condition requires a technician, where the current emergency contacts live, which report must reconcile before close, how a customer-access restriction is documented and who can approve a vendor response. When that manager is unavailable, the portfolio discovers that the process was stored in a person rather than in the operating system.
The usual backup plan is too loose: call the regional manager, borrow help from a nearby property or ask whoever has worked there longest. That may provide labor. It does not establish authority, usable access, current instructions or a reliable transfer of state.
Multi-location operators need a stronger unit of continuity: the continuity pair. For every critical facility function, name a primary owner and a tested alternate. Give the alternate a bounded activation rule, the records required to understand current state, the access required to perform the work, and a clear limit on what must still be escalated.
This is not about creating a second manager for every site. It is about removing hidden single-person dependencies from the functions the portfolio cannot afford to guess through.
Start With Functions, Not Job Titles
“Back up the manager” is not a usable continuity requirement. A manager's role contains dozens of functions with different clocks, skills, systems and consequences. Some work can wait until the next day. Some requires same-shift triage. Some cannot move without a qualified technician, a central finance owner, a legal or insurance review, or emergency authority under the property's approved plan.
List the functions that become consequential when delayed or abandoned. In a self-storage portfolio, the review might include opening and closing controls, access-incident escalation, customer-access restrictions, payment and deposit reconciliation, urgent maintenance routing, severe-weather status communication, vendor entry, system-administration continuity and the preservation of incident records. The list will vary by property. It should be based on the facility's actual operating model, not copied from another site.
For each function, define the longest assumed deferral before operating risk materially changes. That interval is a local planning input, not an industry benchmark. It forces the team to distinguish a task that can wait 24 hours from a condition that needs a qualified owner within minutes.
FEMA's 2024 Continuity Guidance Circular is written for broad public- and private-sector continuity planning. It begins with essential functions and treats orders of succession, delegations of authority, communications, vital records, training, testing and exercises as separate continuity elements.[1] A self-storage operator does not need to adopt federal terminology or build a government continuity program. The useful discipline is to identify the function first and then prove what allows it to continue.
Separate Availability From Authority
An alternate can be available and still be unable to act.
Consider five different states:
- Named: A role or person appears in the continuity record.
- Reachable: Current contact and escalation routes work.
- Ready: The alternate has current instructions, required knowledge and usable non-shared access.
- Activated: A defined condition has placed the function with the alternate.
- Reconciled: The alternate's work has been reviewed against the governing record and handed back or closed.
Calling an area manager does not activate authority. Forwarding a password does not create readiness. Completing a task does not prove that the governing system reflects the result.
A written delegation should state the function, activation condition, permitted actions, prohibited actions, approval ceiling, effective period and termination rule. FEMA distinguishes an order of succession from a delegation of authority: succession identifies who occupies a leadership position, while delegation grants authority for specified purposes and carries limits.[1] Actual legal, financial, employment, safety and emergency authority must be established by the qualified owners for the organization and jurisdiction. A continuity matrix can record that authority; it cannot invent it.
The alternate should never rely on a shared credential, another person's multifactor-authentication device or a generic administrator account passed through email. If the system does not support an appropriately scoped continuity identity, record the function as not ready and establish an approved manual or escalation path. “We can probably get in” is an unresolved dependency.
Build a Function Packet Small Enough to Use
The alternate does not need a binder that attempts to explain the entire facility. The alternate needs a current packet for the bounded function.
The packet should contain:
- exact facility and function identity;
- primary and alternate owner roles;
- activation condition and activation authority;
- maximum assumed deferral and next review time;
- current instruction or runbook version;
- governing records and where they are held;
- required systems, roles and verified access state;
- external contacts and contractual boundaries;
- prohibited actions and mandatory escalation points;
- current open work, restrictions and unresolved exceptions;
- required completion and handback evidence; and
- last test, result, correction owner and next review date.
Do not place passwords, recovery codes, customer data or sensitive security details in the matrix. Reference the approved system or vault location without copying the secret. Protect continuity records according to their contents and the organization's policies.
NIST's contingency-planning guide for federal information systems says recovery teams should understand their own procedures and cross-team dependencies, remain viable when some members are unavailable, and designate alternates for team leaders.[2] The publication concerns information systems, not self-storage staffing. Its practical transfer is limited but useful: naming a backup is insufficient unless the backup has the skills, procedure and coordination context required for the function.
Test the Handover, Not the Document
A document review can confirm that fields are populated. It cannot establish that the alternate can perform the function.
Use a bounded walkthrough or tabletop exercise. Give the alternate a fictional or safely staged condition and ask that person to locate the current record, state whether activation is authorized, identify the first permitted action, name the stop condition, show where evidence would be written and describe how the function returns to the primary owner.
For a higher-consequence function, use an approved non-destructive test. Verify that the alternate's own identity can reach the necessary system and only the intended scope. Do not create a live customer restriction, change a gate schedule, move money, contact emergency services, enter a rented unit or dispatch a vendor merely to prove readiness. Simulate or inspect until the applicable owners approve a safer live test.
NIST SP 800-53's contingency-planning controls call for defined roles, training consistent with assigned responsibilities, plan testing, review of test results and corrective action.[3] The catalog is a federal security and privacy control source, not a self-storage operating standard. It supports the shape of the test, not a claim that a property is compliant or certified.
FEMA's Continuity of Essential Functions exercise materials describe tabletop resources as scalable, flexible and adaptable, and connect exercises to after-action and improvement planning.[4] That last step matters. A failed lookup, expired account or missing phone number should become a correction with an owner and due time. It should not be softened into “the team knows what to do.”
Use the Portfolio to Supply Real Redundancy
Multi-location operations create a continuity advantage only when the portfolio makes it explicit.
A nearby manager may understand the operating model but lack access to the affected site's records. A regional leader may have authority but not know the current restriction. A central accounting specialist may control reconciliation but be unable to verify what happened at the property. A vendor may know the equipment but have no authority to decide whether the facility reopens.
Build the pair by function, drawing alternates from the location, region or central team according to the work. Avoid placing every alternate with the same shared dependency. If the primary and alternate rely on the same inaccessible office, shared phone, undocumented spreadsheet or unavailable regional approver, the pair has not removed the failure point.
GAO's 2025 Green Book requires federal management to establish structure, assign responsibility, delegate authority, support competence and hold people accountable for internal-control responsibilities.[5] It does not govern private self-storage companies. Used cautiously, it reinforces a sound management rule: responsibility, authority, competence and accountability are different design decisions and should be visible together.
A Fictional Four-Function Review
Consider Northstar Storage Group, a fictional six-facility portfolio created only to demonstrate the method.
At fictional Cedar Row Storage, the facility-opening function lists the site manager as primary and a manager from another fictional property as alternate. The alternate is reachable and has read the procedure, but the access-control role is limited to the other property. The result is not ready. The correction is not to share the primary manager's login. The identity owner must provision and verify a bounded role or document an approved escalation path.
The same site lists urgent water-intrusion escalation. The alternate can locate the site emergency plan, current owner and restoration contacts, but the packet does not identify who may authorize customer-space entry. The result is ready with restriction: the alternate may establish the safety boundary and route the incident, but any entry remains held for the authorized owner under site policy and applicable requirements.
At fictional Harbor Lane Storage, deposit reconciliation has a central finance alternate with current system access and a recent walkthrough. The alternate can reproduce the expected-versus-posted check, preserve an unresolved variance and hand the record back without approving a payment. The result is ready for the defined function, not a broad grant of financial authority.
At fictional Pine Junction Storage, severe-weather status communication has two named alternates, but both depend on a contact list last reviewed 14 months earlier. The result is not evaluated until the contacts and communication routes are verified. Age alone does not prove the list is wrong; it proves the current test evidence is missing.
Every facility name, person, event, system state and test result in this example is fictional. The example reports no real portfolio practice or outcome.
The Monthly Continuity Review
Do not turn the matrix into another annual file that looks complete while the operating state changes beneath it.
Once a month, review a small number of critical functions across the portfolio. Prioritize functions with an upcoming absence, a role change, a failed access check, a new vendor, a revised procedure, a system migration or an unresolved test gap. Ask six questions:
- Is the function still essential on the stated clock?
- Are the primary and alternate roles still correct?
- Is the delegation active, bounded and available?
- Can the alternate reach the current records and systems using an approved identity?
- Has a safe handover test passed under the current procedure and dependencies?
- Is every gap owned, due and paired with an operating restriction?
Use clear dispositions: ready, ready with restriction, not ready, not evaluated or retired. Never convert missing evidence into a pass. Never call a named alternate ready when access, authority or the current procedure has not been tested.
The goal is not perfect duplication of every employee. It is controlled continuity for the functions that matter most. A portfolio becomes more resilient when it can move one critical function to a prepared alternate, preserve the boundaries around that work and prove the state when the primary owner returns.
Download the Continuity Pair Tools
The template and all populated example rows are fictional training data.
Sources
- Federal Emergency Management Agency, Continuity Guidance Circular: 2018 Continuity Guidance Circular (2024 Update), August 2024. The guidance is broad continuity guidance and does not establish a self-storage emergency plan, delegation or legal authority.
- National Institute of Standards and Technology, SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems, May 2010, updated November 2010. It addresses federal information-system contingency planning, not property staffing or facility safety.
- National Institute of Standards and Technology, SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations, including Release 5.2.0 dated August 27, 2025. The cited contingency-planning controls are tailorable security and privacy controls, not proof of implementation, effectiveness, certification or self-storage applicability.
- Federal Emergency Management Agency, Continuity of Essential Functions — Exercise Starter Kits, accessed August 30, 2026. The materials support exercise design and improvement planning; they do not validate this article's method or any facility plan.
- U.S. Government Accountability Office, Standards for Internal Control in the Federal Government: 2025 Revision, effective for fiscal year 2026. The Green Book governs federal internal control and is used here only as an authoritative management-control reference.
