Tag: Risk Management

  • Business Continuity Plan (BCP) Template

    Business Continuity Plan (BCP) Template

    Business Continuity Plan (BCP) Template

    $29

    Delivered by email after checkout.

    Buy Now →

    Secure checkout via Square — all major cards accepted

    You can copy this method and build a real Business Continuity Plan yourself. You do not need a consultant. You need to start. Buy Now is the packaged Notion duplicate: the plan page plus the five databases already wired, delivered by email after checkout.

    This walks a property manager, a restoration company, or any shop that needs a living plan (not a binder on a shelf) through the same structure. Fill the fields. Practice the tree. Update it every six months.

    What a good BCP actually is

    Five steps: risks, roles, comms, vendors, drill for a restoration BCP
    A good BCP is practiced — not laminated and forgotten.

    It is not about the document. It is about the capability. A plan in a drawer is worthless. A plan your team has practiced, your vendors know about, and you update on a review cycle is the difference between a company that keeps running and one that does not.

    Three frames sit under this template:

    • FEMA: essential functions must still get done during any disruption.
    • ISO 22301: deliver services inside acceptable timeframes.
    • Belfor Code Red ACT: Assessment, Communication, Training.

    This template combines those into something you can build and maintain yourself. Restoration ERP-style cloud BCP tools exist if you need branded mobile apps and automated SMS. This is the planning foundation: the thinking, the structure, the documentation. That is the part that matters most, and you can customize it.

    Start with the plan header

    Write these six fields on page one. Do it today.

    • Plan Owner: a named person, not “the office.”
    • Organization: legal name people will see on the copy.
    • Last Updated: today’s date.
    • Next Review Date: six months from now.
    • Plan Version: start at 1.0.
    • Distribution: who gets a copy (owner, ops, office, key vendors).

    Build it in this order

    Restoration SOP clipboard with checklist, moisture meter, and gloves on a jobsite table
    Build it in order — functions, risks, tree, vendors, drill.

    Eleven sections. Do them in sequence. Each one is a how-to, not an essay.

    1. Business Impact Analysis (BIA). Identify the functions that matter most and how long you can survive without them.
    2. Risk Assessment. What threats exist, how likely, how severe.
    3. Critical Functions and Recovery Objectives. RTO and RPO for every essential function.
    4. Emergency Contact and Communication Tree. Who to call, in what order, through what channels.
    5. Incident Response Procedures. Step-by-step for the first 24–72 hours.
    6. Recovery Strategies. How to restore each critical function.
    7. Facility and Infrastructure. Building systems, utility shutoffs, alternate locations.
    8. Vendor and Contractor Directory. Pre-qualified emergency vendors with contracts on file.
    9. IT and Data Recovery. Backups, cloud access, cybersecurity incident response.
    10. Training and Exercise Log. Tabletop exercises, drills, lessons learned.
    11. Plan Maintenance and Review. Keep the plan alive.

    How to fill Critical Business Functions

    Make one row per function. Restoration shops usually start with dispatch / first notice, mitigation crews, equipment, claims / documentation, billing, and payroll. Use the real names you use in the shop.

    For each function, fill:

    • Function Name
    • Department. Operations, Finance / Accounting, Sales / Business Dev, IT / Technology, HR / People, Legal / Compliance, Customer Service, Facilities, or Executive
    • Owner: person responsible in a crisis
    • Alternate: backup if the owner is unavailable
    • Priority. P1 Mission Critical, P2 Essential, P3 Important, P4 Deferrable
    • RTO (Recovery Time Objective, max acceptable downtime). 0–4 hours, 4–12 hours, 12–24 hours, 1–3 days, 3–7 days, or 7+ days
    • RPO (Recovery Point Objective, max acceptable data loss). Zero data loss, 1 hour, 4 hours, 24 hours, or 7 days
    • Impact if Down: what actually happens if this stops
    • Revenue Impact. Direct revenue loss, Delayed revenue, Indirect cost increase, Reputational, or Minimal
    • Dependencies: systems, people, vendors this function needs
    • Systems Required: software, hardware, access
    • Recovery Strategy: how you restore it
    • Last Tested and Notes

    If you cannot name an Alternate, that function is a single point of failure. Write that down. Fix it in the recovery strategy, not later.

    How to fill Risk Assessment

    One row per threat. Categories in the template: Natural Disaster, Fire, Water / Flood, Cybersecurity, Pandemic / Health, Utility Failure, Supply Chain, Key Person Loss, Legal / Regulatory, Civil Unrest, Infrastructure Failure, Other.

    For each threat, fill:

    • Threat / Risk: a specific sentence, not “weather”
    • Likelihood. Almost Certain, Likely, Possible, Unlikely, Rare
    • Impact Severity. Catastrophic, Major, Moderate, Minor, Negligible
    • Risk Score. Critical, High, Medium, Low (your call from likelihood × severity)
    • Affected Functions: which rows from the functions table this hits
    • Current Mitigation: what you already have
    • Additional Mitigation Needed: the gap
    • Insurance Coverage. Fully Covered, Partially Covered, Not Covered, Unknown
    • Owner, Last Reviewed, Notes

    Start with the threats you have already lived: a freeze, a key tech leaving, a software outage, a shop fire, a Category 3 loss at your own building. Then add the ones you have not lived yet.

    How to fill the Communication Tree

    One row per person. Call Order 1 is the first call. If you cannot reach them, you call their Backup Person.

    Fields:

    • Name, Role (Plan Owner, Executive Team, Department Head, Team Lead, Key Employee, Board / Ownership, or External: Legal, Insurance, IT, Restoration, Government, Media)
    • Phone – Primary and Phone – Alternate
    • Email, Location
    • Call Order (number)
    • Backup Person
    • Responsibilities in Crisis
    • Can Authorize Spending (yes/no)
    • Can Speak to Media (yes/no)

    Print a copy. Put one in the go-bag and one at the shop. A tree that only lives in a laptop fails when the laptop is in a flooded office.

    How to fill the Vendor Directory

    Pre-qualify before you need them. Categories in the template: Restoration / Mitigation, General Contractor, Plumbing, Electrical, HVAC, Roofing, IT / Cybersecurity, Data Recovery, Security / Guard, Cleaning / Janitorial, Temporary Staffing, Equipment Rental, Document Recovery, Environmental / Hazmat, Legal, Insurance Adjuster, Other.

    For each vendor: name, contact, phone, email, service area, 24/7 available, response time (Under 1 hour through Next day, or Unknown), contract on file, contract expiry, rate notes, rating (Excellent through Do Not Use), last used, notes.

    If Contract on File is no, that is this week’s homework, not a crisis-day task.

    How to run a tabletop (Training & Exercise Log)

    Restoration technicians training in a shop bay with equipment demo and whiteboard
    Tabletop drill: the log proves you trained, not just wrote.

    A BCP you have never practiced is a draft. Log every exercise.

    • Exercise Name, Date, Duration, Facilitator, Participants
    • Type. Tabletop Exercise, Walk-Through, Functional Drill, Full-Scale Exercise, Training Session, or After-Action Review
    • Scenario: the disaster you simulated
    • Key Findings: what worked, what failed, what surprised you
    • Action Items: specific improvements
    • Status. Scheduled, Completed, Cancelled, Action Items Open, All Actions Closed
    • Next Exercise Due

    Pick one P1 function and one High risk. Walk the first 24 hours out loud with the people on the tree. Write what broke. Close the action items before the next review date.

    The other sections, short

    • Incident response (first 24–72 hours): who declares the incident, who calls the tree, who talks to staff and customers, who authorizes spend, where you meet if the shop is unusable.
    • Recovery strategies: one paragraph per P1/P2 function. Point at the Alternate, the Systems Required, and the vendor who can stand it up.
    • Facility: shutoff locations, generator, alternate location, key box, who has after-hours access.
    • IT and data: where backups live, who can restore, what happens if email or the CRM is down, how you handle a cyber incident without guessing.
    • Maintenance: review date on the header is a real date. After any real incident or any exercise, bump the version.

    If you want the packaged Notion workspace

    You can build every table above in a spreadsheet. Buy Now is the Notion duplicate with the plan page and the five databases already built (Critical Business Functions, Risk Assessment, Emergency Contact & Communication Tree, Vendor & Contractor Directory, Training & Exercise Log). Delivered by email after checkout. Same Square button at the top of this page.

    Related: Front door: Complete Restoration Operations Kit ($97). Stack: The Restoration.

  • Owner Freedom Kit

    Owner Freedom Kit

    Owner Freedom Kit

    $397

    Delivered by email after checkout.

    Buy Now →

    Secure checkout via Square — all major cards accepted

    You can copy this method and do it yourself. Audit where the business depends on you. Build a bench. Run a 12-week plan to step back. Buy Now is the packaged bundle: five Notion tools plus the matching Claude skills, so you are not assembling the doer-to-leader system from blank pages.

    This is the premium tier of the Restoration Leadership Toolkit. For owners serious about getting out of the truck, and eventually building something they can sell. The full system: audit, bench, 90-day plan, succession stress test, and the 1-3-1 handoff.

    What’s in the kit

    Four-phase board covering a 12-week owner freedom transition
    A 12-week arc from naming why to review and repeat.
    1. Owner Dependency Audit
    2. Restoration Leadership Bench Builder
    3. 90-Day Doer-to-Leader Transition Plan
    4. 5 Ds Succession Risk Checklist
    5. 1-3-1 Delegation Worksheet

    The matching skills from the Leadership Claude Edition: owner-dependency-audit, leadership-bench-builder, doer-to-leader-90-day, succession-5ds-checklist, delegation-1-3-1.

    Run them in this order. The 90-day plan is the spine. The other four feed it.

    Week 0: name why you are stepping back

    Before Week 1, write three lines:

    • My #1 reason to step back (what I would do with the time)
    • The one person I am betting on as my first real manager
    • Start date / target Week-12 date

    Block 30-45 minutes every Friday. Do not skip ahead. Each phase sets up the next.

    Weeks 1-2: identify the bottlenecks

    Run the Owner Dependency Audit. Rate Low / Med / High across nine areas: sales, production, finance, customer-issue resolution, hiring, vendor relationships, estimating / project management, emergency response, decision rights. Scoring: Low = 1 (runs without you; a real backup has done it), Med = 2 (limps; backup needs you on call), High = 3 (stops cold). Total is 9-27.

    For each area write: what happens if you are gone 30 days, who the backup is today, and what would have to be true for this to be Low.

    Then fill a Decision-Rights Map. Starter rows: approve a job estimate over $25k; authorize overtime / call-in crew; issue a refund or credit; hire or fire; approve a vendor / sub payment; take an out-of-area or unusual job; sign a contract or insurance scope; pull a crew off one job for another; spend on new equipment; set or discount a price. Who decides today vs who should.

    End of the phase: a written top-3 bottleneck list, and the team knows the shift is coming. Tell them: “I’m working a 90-day plan to push decisions down. Expect me to hand more back to you.”

    For one full week, tally every interrupt for a decision. Sort into Delegate now / Delegate after training / Keep (truly owner-only).

    Weeks 3-4: install 1-3-1

    Three panels showing one problem, three options, one recommendation
    1-3-1: one problem, three options, one recommendation.

    Stop being the answer key. The old way: “The dehu on Maple St died. What do you want me to do?” You just took back the problem, the thinking, and the decision.

    The 1-3-1 way:

    • 1 issue. The fork in the road, one or two sentences. Not the whole story.
    • 3 real options. Each with pros, cons, and rough cost or effort. “Do nothing” can be one when it is honest.
    • 1 recommendation. The option they would pick if it were their call, and why in one line.
    • A default. What they will do if they do not hear back by a deadline, so the job does not stall.

    When someone brings a raw problem, ask: “What are your three options, and which do you recommend?” Then wait. Run at least five real 1-3-1 conversations this phase. Approve the recommendation whenever it is reasonable. Note who takes to it. That is a signal for your manager pick.

    Phase done when at least one person is bringing 1-3-1s without being reminded.

    Weeks 5-6: write decision rights

    List the 10-15 recurring decisions (refunds, equipment, scheduling, scope changes, hiring, pricing exceptions). For each: a dollar or scope threshold people can decide under without asking you, and who owns it when you are not in the room. Walk the team through it: “Under this line, you don’t need me. Decide and tell me after.”

    Hand off one decision completely this phase. Do not take it back.

    Weeks 7-8: develop one manager

    Restoration technicians training in a shop bay with equipment demo and whiteboard
    Weeks 7–8: develop one manager — teach, don’t just assign.

    Open the Bench Builder. One row per key function. Fields: Role, current owner, future-leader candidate, backup depth (None / Thin / Solid), key skill gaps, 90-day development action (observable: shadow X, own Y file end-to-end, run Monday huddle), delegation plan, accountability rhythm (Weekly / Biweekly / Monthly), status (Identified / Developing / Ready). A blank candidate is itself a finding.

    Go deep on ONE person. A single real manager beats five people you are “keeping an eye on.” Have the conversation: “I want to grow you into running X.” Hand them one area end-to-end. Set a weekly 30-minute 1-on-1 and protect it. Let them make a real decision. Coach the outcome instead of grading it.

    Weeks 9-10: accountability rhythm

    Stand up a weekly 15-minute huddle with a fixed agenda: numbers, jobs at risk, who needs what. Pick 3-5 numbers the team reviews every week (jobs in WIP, days-to-dry, AR, callbacks, leads). Someone other than you owns each number. Have your developing manager run the huddle at least once while you sit in.

    Hold one real accountability conversation this phase. Issue, behavior that needs to change, what has already been allowed, the expectation, the consequence or support, what success looks like in 30 days. About the work, not the person.

    Weeks 11-12: review and repeat

    Re-run the Dependency Audit and compare to Week 1. Take a planned half-day fully off and note what broke. That is the next bottleneck. List what got delegated vs what bounced back, and why. Give the developing manager direct feedback. Raise one decision-rights threshold. Duplicate the 90-day page and start the next cycle.

    Success at 90 days: a full day off without the phone melting; the team brings 1-3-1s; a written decision-rights list; one person owns one area end-to-end; a huddle someone else can run; a lower dependency score; next quarter’s target already named.

    Run the 5 Ds while you are in it

    Succession is a what-if-tomorrow problem, not a retirement problem. Check a box only if it is true and current today. The five:

    1. Death. Will, funded buy-sell, key-person life, second check-signer, someone who can legally bind the company, a recoverable password place, a named person who can run production 30+ days.
    2. Divorce. Separate vs marital property actually confirmed, commingling cleaned up, a valuation method in writing, operating cash structured so a personal dispute cannot freeze payroll.
    3. Disease. Someone has actually run production on a vacation test. Backup estimator. Payroll / AP / AR without your hands. Disability and business-overhead coverage. A one-page interim chain-of-command.
    4. Drugs / dependency. Dual approval over a dollar threshold. A second set of eyes on the books. No single point of failure, including you. A trusted advisor allowed to tell you the truth.
    5. Departure / disaster. Tribal knowledge written down. Relationships not owned by one person. Off-site backups you have test-restored. A continuity plan for your own shop. Backup vendor / equipment list.

    45 boxes. Count the blanks. 0-6 resilient; 7-15 moderate; 16-27 high; 28+ you are the company. Pick the three blank boxes that would hurt most if the D hit tomorrow. Name an owner and a date. This is an awareness tool, not legal, financial, or insurance advice. Use it to walk into the attorney, agent, and CPA prepared.

    If you want the packaged kit

    You can run this from the outline above. Buy Now is the bundle delivered by email after checkout: the five Notion pages (duplicate each so the master stays clean), plus the matching Claude skills if you want the interviews walked. Same Square button at the top of this page.

    Coaching and operational tools only. Not legal or HR advice.

    Related on Tygart Media: owner dependency audit · leadership OS · operations kit AI edition.

  • Conference Starter Pack

    Conference Starter Pack

    Conference Starter Pack

    $97

    Delivered by email after checkout.

    Buy Now →

    Secure checkout via Square — all major cards accepted

    You can copy this method and do it yourself. Score where you are still the bottleneck. Install 1-3-1 so the next problem comes back as a recommendation. Walk the 5 Ds as a what-if-tomorrow check. Buy Now is the packaged bundle: three Notion tools plus the matching Claude skills, so you are not assembling the starter pack from blank pages.

    The grab-and-go pack from the Restoration Leadership Toolkit. Three of the most-used tools, bundled. For restoration owners who just heard the doer-to-leader message and want something they can run this week, not a 12-week program on day one.

    What’s in the pack

    Four-phase board covering a 12-week owner freedom transition
    Conference pack: start with the bottleneck assessment.
    1. 1-3-1 Delegation Worksheet
    2. Owner Bottleneck Self-Assessment
    3. 5 Ds Succession Risk Checklist

    The matching skills from the Leadership AI plugin: delegation-1-3-1, owner-bottleneck-assessment, succession-5ds-checklist.

    Run them in this order. The bottleneck names the constraint. 1-3-1 is the first habit. The 5 Ds is the exposure you do not want to discover the hard way.

    1. Owner Bottleneck Self-Assessment

    Find out where your company still depends on you. An owner bottleneck exists when growth, decision speed, and consistency are limited by your personal involvement in day-to-day decisions. You become both the most important and the most constraining person in the business.

    Check the box for each statement that is true today. Count the checks in each section, then total them. Range is 0-25. Be honest. The value is in the truth.

    1. Decisions only you make. Estimate / pricing approvals over a set dollar amount. Hiring and firing. Vendor choices. Which jobs you take. Refunds, credits, concessions.
    2. Interruptions by department. Production calls daily. Office pulls you into billing or scheduling. Sales checks pricing before quoting. Techs call from job sites. Customer complaints land on you.
    3. Recurring questions. The same operational questions every week. People wait for you. “Ask the owner” is the default. You re-explain the same processes. Things stall when you are unavailable.
    4. Tasks that should be delegated. Estimates you could hand off. Scheduling / dispatch. Collections / AR. Ordering equipment. Work others could produce.
    5. Areas with no backup. No one else can run production. Only you hold key carrier relationships. Only you see the full financial picture. No written SOPs for the things you do. If you are gone a week, something breaks.

    Bands: 0-6 Mild (tighten the remaining gaps). 7-13 Moderate (you are the bottleneck in one or two areas; fix the worst one first). 14-19 Heavy (the business runs through you; start delegating now, deliberately). 20-25 Severe (you ARE the business; this is the #1 risk to growth and to an exit).

    Write your top 3 to delegate first. For one full week after you score, log every interrupt for a decision. Sort into Delegate now / Delegate after training / Keep (truly owner-only). The department with the most checks is this quarter’s target. Install 1-3-1 there first.

    2. 1-3-1 Delegation Worksheet

    Three panels showing one problem, three options, one recommendation
    1-3-1 worksheet — force recommendations on the floor.

    The old way (escalation): “Hey boss, the dehu on the Maple St job died. What do you want me to do?” You just took back the problem, the thinking, and the decision. That is three jobs.

    The 1-3-1 way (delegation): “The dehu on Maple St died. Here are three options I looked at, here is the cost of each, and here is what I would do. Just need your yes.” You own one job: the decision.

    • 1. One issue. The decision that is actually needed, in one or two sentences. Not the whole story. The fork in the road.
    • 3. Three real options. Each with pros, cons, and a rough cost or effort. “Do nothing” can be one when it is honest. Stuck at two? Push for a third. Even “do nothing and revisit Friday” or “escalate to the carrier.”
    • 1. One recommendation. The option they would pick if it were their call, and why in one line.
    • A default. What they will do if they do not hear back by a deadline, so the job does not stall waiting on you.

    Explain the rule once, out loud. Pin the format where decisions get made (truck, office, group chat). When someone brings a raw problem, ask: “What are your three options, and which do you recommend?” Then wait. Run at least five real conversations. Approve the recommendation whenever it is reasonable. Resist solving it yourself, even when you are faster. Note who takes to it quickly. That is a signal for a future-manager pick.

    The first few 1-3-1s will be lopsided. Three fake options, or a recommendation with no reasoning. Coach it. Do not grade it. Phase done when at least one person is bringing 1-3-1s without being reminded.

    Worksheet fields if you are copying it: prepared by, date, job / account, urgency (Today / This week / No rush); the issue; three options (what it is, two pros, two cons, rough cost); the recommendation and what they need from you; the default deadline; owner sign-off (Approved as recommended / Approved with changes / Chose a different option / Let’s talk).

    Owner gut-check before you sign: could this person have made this call without me? If yes, tell them so, and next time push it all the way down.

    3. 5 Ds Succession Risk Checklist

    Five colored panels labeled Do, Delegate, Defer, Delete, Decide
    5 Ds succession risk — decide what leaves with you.

    Succession is not a retirement problem. It is a what-if-tomorrow problem. Check a box only if it is true and current today. Not “mostly.” Not “we talked about it once.” A box you want to be true is still a blank box. Half-true protections fail exactly when the D hits.

    1. Death. Current signed will that names the business. Funded buy-sell if there are partners. Key-person life payable to the company. A second check-signer on file at the bank. Someone who can legally bind the company. Passwords in a recoverable place. A named person who can run production 30+ days. Spouse / heirs know who to call.
    2. Divorce. Separate vs marital property actually confirmed, not guessed. Prenup, postnup, or buy-sell provision. Books not commingled. A valuation method in writing. Operating cash structured so a personal dispute cannot freeze payroll.
    3. Disease. Someone has actually run production on a vacation test. Backup estimator. Payroll / AP / AR without your hands. Carrier relationships that will not collapse if you are unreachable. Disability and business-overhead coverage. A one-page interim chain-of-command with dollar thresholds.
    4. Drugs / dependency. Dual approval over a dollar threshold. A second set of eyes on the books. No single point of failure, including you. A trusted advisor allowed to tell you the truth. Key roles documented and cross-covered.
    5. Departure / disaster. Tribal knowledge written down. Relationships not owned by one person. Off-site backups you have test-restored. A continuity plan for your own shop. Backup vendor / equipment list.

    Count the blanks. Published bands on the scored sheet: 0-6 resilient; 7-15 moderate; 16-27 high; 28+ you are the company. Pick the three blank boxes that would hurt most if the D hit tomorrow. Name an owner and a date. Re-run it every year, and after any life or business change. This is an awareness tool, not legal, financial, or insurance advice. Use it to walk into the attorney, agent, and CPA prepared.

    What to do after the three

    Take the top-3 bottleneck list into a 90-day doer-to-leader plan (Weeks 1-2 are this assessment). After 1-3-1 sticks, write decision rights so people stop defaulting to you out of habit. The 5 Ds blanks that are also “no backup” boxes on the bottleneck assessment are the same exposure. Name them once.

    If you want the next layer after this pack: Leadership Readiness Kit (checklist, scorecard, planner, 1-3-1) or Owner Freedom Kit (audit, bench, 90-day, 5 Ds, 1-3-1).

    If you want the packaged pack

    You can run the three tools from the outline above. Buy Now is the bundle delivered by email after checkout: the three Notion pages (duplicate each so the master stays clean), plus the matching skills if you want the interviews walked. Same Square button at the top of this page.

    Coaching and operational tools only. Not legal, financial, insurance, or HR advice.

    Related on Tygart Media: leadership OS · owner freedom kit.

  • 5 Ds Succession Risk Checklist

    5 Ds Succession Risk Checklist

    5 Ds Succession Risk Checklist

    $29

    Delivered by email after checkout.

    Buy Now →

    Secure checkout via Square — all major cards accepted

    You can copy this method and do it yourself. Stress-test the company against Death, Divorce, Disease, Drugs/dependency, and Departure/Disaster. Check a box only if it is true and current today. Buy Now is the packaged Notion checklist with the scored sheet and mitigation notes, so you are not rebuilding the 5 Ds from a blank doc.

    Succession is not a retirement problem. It is a what-if-tomorrow problem. The blank boxes are your exposure. Honesty rule: a box you want to be true is still a blank box. Half-true protections fail exactly when the D hits.

    How to run it

    Five colored panels labeled Do, Delegate, Defer, Delete, Decide
    Run the 5 Ds as a risk checklist — not a slogan.
    1. Walk each of the 5 Ds. Check a box only if it is true and current today. Not “mostly.” Not “we talked about it once.”
    2. Read the mitigation note under each D. That is the concrete fix for the boxes you left blank.
    3. Count the blanks. Find your band. Pick your top 3 shore-ups. Name an owner and a date.
    4. Re-run it every year, and immediately after any life or business change: a new partner, a marriage or divorce, a major new account, an acquisition, or a health scare.

    1. Death. If you died tomorrow

    If you were gone permanently, could the business survive the week, pay people, and not get sold for scraps?

    • There is a current, signed will and the business is named in it.
    • There is a buy-sell agreement (if there are partners) defining who buys your share, at what price, and how it is funded.
    • Key-person life insurance exists on you, payable to the company, sized to cover payroll plus obligations while it stabilizes.
    • At least one other person can sign checks (signatory on file at the bank, not just “knows the login”).
    • Someone other than you can legally bind the company (contracts, AOBs, subcontracts). Documented authority, not assumed.
    • Your spouse / heirs know who to call and where the documents live.
    • Passwords, accounts, and licenses are in a recoverable place a trusted person can reach.
    • A named person can run production and keep jobs moving for 30+ days without you.

    Mitigation. Get a buy-sell drafted by an attorney and fund it with life insurance. An unfunded buy-sell is a wish, not a plan. Add a second check-signer and a documented officer who can bind the company. Put credentials in a password manager with an emergency-access contact. Write a one-page “if I am gone” sheet. Tell your spouse where it is.

    2. Divorce. If your marriage ended

    A divorce can put your ownership stake, your cash, and your focus in play. A contested split can starve a cash-hungry shop.

    • You know whether the business is separate vs marital/community property in your state. Confirmed, not guessed.
    • There is a prenup, postnup, or buy-sell provision that addresses ownership in a divorce.
    • The business is not commingled with personal finances (clean books, separate accounts, documented owner pay).
    • A current, defensible valuation (or a method to set one) exists.
    • Your spouse’s role and any claim (employee, owner-on-paper, guarantor) is documented.
    • Operating cash and credit lines are structured so a personal dispute cannot freeze payroll.

    Mitigation. Talk to a business attorney about a postnuptial or a buy-sell clause that fixes ownership treatment now, while things are calm. Clean up commingling. Establish a valuation method in writing. Calm is the only time you can do it.

    3. Disease. If you were medically out for 30-90 days

    Not death. A heart attack, a serious diagnosis, a bad accident. You are alive but out. Does the company idle or run?

    • Someone can run daily production and dispatch without you for 30, 60, 90 days. Named, and they have actually done it (vacation test).
    • Estimates still get written and approved if you are the estimator. A backup exists.
    • Payroll, AP, and AR keep running without your hands on them.
    • Carrier / TPA relationships will not collapse if you are unreachable. Someone else has the relationships and portal access.
    • You carry disability income insurance so household income does not depend on you working.
    • Business overhead expense (BOE) insurance or a cash reserve can cover fixed costs while you recover.
    • A simple interim chain-of-command is written down, with dollar/decision thresholds.

    Mitigation. Run a real “two weeks off” test this quarter and watch what breaks. Cross-train a backup estimator. Look at disability and Business Overhead Expense coverage. Write a one-page interim chain-of-command with decision thresholds.

    4. Drugs / dependency. If you (or a key person) became unreliable

    The uncomfortable one. Substance issues, gambling, burnout, a mental-health crisis. Yours or a key person’s. The risk is a slow decline, not a clean exit.

    • No single person (including you) is a single point of failure whose impairment would quietly sink the company.
    • Financial controls exist (dual approval over a threshold, reconciliations, a second set of eyes on the books).
    • A trusted advisor or peer would tell you the truth if your performance was slipping, and has standing to.
    • Key roles have documented duties and cross-coverage.
    • There is an employee assistance path / clear policy for getting a valued person help without an instant, messy termination.
    • If a key person had to be removed fast, you could. Access and knowledge are not locked solely in their head.

    Mitigation. Dual approval over a dollar threshold, monthly reconciliations, a second set of eyes on the books. Document and cross-train so no one person can sink a function. Put a real advisor in your corner who is allowed to tell you the truth. Have a humane path to help and the access to act fast if you must.

    5. Departure / disaster. If a key person walked, or the building burned

    Two faces of the same risk: a critical person quits, or a fire/flood/storm/cyber event takes out your office, fleet, data, or a major account overnight.

    • Production runs if your best PM or lead tech quits Friday. Their knowledge is documented, not tribal.
    • Key customer and carrier relationships are not owned by one person who could walk and take the book with them.
    • A non-solicit / non-compete / confidentiality agreement is in place where appropriate and enforceable in your state.
    • Critical SOPs, pricing, and account knowledge are written down. Losing one person does not erase how the work gets done.
    • Data is backed up off-site (estimating files, photos, accounting, contacts) and you have actually tested a restore.
    • You have a business continuity / disaster plan for your own office or fleet. You restore others. Are you covered?
    • Business-interruption insurance would replace income if you could not operate for weeks.
    • A backup vendor/equipment plan exists so one lost truck, warehouse, or sub does not stall live jobs.

    Mitigation. Document tribal knowledge. Spread customer and carrier relationships across more than one person. Put reasonable non-solicit/confidentiality agreements in place (attorney confirms enforceability in your state). For disaster: off-site backups you have test-restored, a written continuity plan for your own shop, business-interruption coverage, and a backup equipment/vendor list.

    Overall exposure rating

    Four-phase board covering a 12-week owner freedom transition
    Overall exposure rating after all five Ds.

    Count your blank boxes across all 5 Ds. The packaged checklist scores 45 boxes. Find your band:

    • 0-6 Low / Resilient. The business could survive a major shock to you. Maintain it. Review annually and after any big change.
    • 7-15 Moderate. You would survive a short absence but a permanent loss would hurt. Close the highest-stakes gaps (Death + Disease) first.
    • 16-27 High. A 30-day absence would seriously disrupt the company. A permanent loss could end it. Treat this as a current-quarter priority.
    • 28+ Critical / You are the company. If something happened to you tomorrow, the business likely does not survive intact. Start the top-3 shore-ups this week.

    Write three lines: blank-box total, exposure band, and which D scored worst.

    Top 3 shore-ups

    Restoration SOP clipboard with checklist, moisture meter, and gloves on a jobsite table
    Top 3 shore-ups — write the next actions.

    Pick the three blank boxes that would hurt most if the D hit tomorrow. Be specific. Name an owner. Set a date.

    Most shore-ups need one of these professionals: a business / estate attorney (buy-sell, will, non-competes, postnup); an insurance agent (key-person life, disability, BOE, business-interruption); a CPA / financial advisor (valuation, financial controls, continuity reserve).

    This is an awareness and planning tool, not legal, financial, or insurance advice. Use it to find your gaps and to walk into the attorney, agent, and CPA prepared.

    If you want the packaged checklist

    You can run the five lists on a legal pad. Buy Now is the Notion page delivered by email after checkout. Duplicate it (··· → Duplicate) so the master stays clean. The boxes, the mitigation notes, the score table, and the top-3 shore-ups are already laid out. Same Square button at the top of this page.

    Pairs with the Owner Dependency Audit (what breaks if you vanish 30 days) and the Restoration Leadership Bench Builder (who can run production when a D hits). Matching Claude skill: succession-5ds-checklist.

    Related: Restoration Leadership Toolkit — Claude Edition. Also 90-Day Doer-to-Leader Transition Plan.

  • Claude Ambient Mode & Background Tasks: Setup Guide

    Claude Ambient Mode & Background Tasks: Setup Guide

    This is part of our Claude Tag field guide for agencies. Start with the overview: Claude Tag: A Builder’s Guide for Agencies.

    Ambient mode is Claude Tag’s headline feature and its single most consequential setting. Turn it on and Claude stops waiting to be asked — it starts watching the channels it’s in and speaking up when it thinks you’d want to know something. Whether you should enable it isn’t a yes-or-no question. It’s a where question, and getting the where right is the whole game.

    What ambient mode actually does

    Four-step loop: observe, remember, act, update for managed agents
    What ambient mode actually does.

    By default, Claude Tag is reactive: you @-mention it, it works, it replies. With ambient behavior enabled, it becomes proactive. Anthropic describes it as Claude keeping you updated about whatever it thinks you might need to know — flagging relevant information from across the channels it’s in and the tools it’s connected to, and following up on threads or tasks that have gone quiet.

    In practice that means three things: it surfaces context you didn’t ask for, it connects information across more than one channel, and it chases loose ends nobody assigned it. Those are exactly the behaviors that make it feel like a teammate instead of a tool.

    Where it’s a superpower

    Inside a single team, ambient mode is close to magic. Every channel belongs to the same company, so “learning across channels” only ever connects your own dots. A proactive teammate that remembers the forgotten follow-up, links the spec to the standup, and flags the blocker before it bites is pure upside. This is the version Anthropic runs internally, and it’s why they can say a large share of their product team’s code now comes from their own version of the tool.

    If your Slack workspace is one company’s data and one team’s work, turn ambient mode on and enjoy it.

    Where it’s a risk

    Five security domains: identity, data, code governance, audit, agents
    Where ambient mode is a risk.

    Ambient mode’s proactive, cross-channel nature is exactly what makes it dangerous in two situations:

    • Multiple clients in one operation. The moment a proactive teammate is “surfacing relevant information from across channels,” relevance becomes the judge of what crosses the line between Client A and Client B. That’s a context-bleed risk we’ve lived — the whole subject of The Multi-Client Isolation Trap.
    • Regulated or sensitive data. Anywhere an unprompted message pulling context from elsewhere could expose something it shouldn’t — health, financial, legal, HR — proactive surfacing is a liability, not a convenience.

    A simple decision framework

    Desk with laptop, checklist notebook, and billing card ready before creating an Anthropic API key
    A simple decision framework before you enable it.

    Don’t decide ambient mode globally. Decide it per surface, with one question: is everything this Claude can see owned by the same trust boundary?

    SurfaceAmbient modeWhy
    Internal team channels (one company)ONCross-channel proactivity only connects your own data
    Client-facing / multi-tenant channelsOFFProactive surfacing is where one client’s context leaks into another’s
    Regulated / sensitive-data channelsOFFUnprompted context-pulling is a compliance liability

    The rule of thumb: ambient mode should be on where the data is all yours, and off everywhere a human should still be pulling, not the AI pushing.

    If you do turn it on

    Enable it deliberately, not by default. Map which channels hold which trust boundary before you flip the switch, keep client and regulated channels out of cross-channel learning, and audit what the assistant can actually see. That sequencing — boundaries first, then ambient — is exactly how we walk through it in How to Set Up Claude Tag in Slack.

    The bottom line

    Ambient mode isn’t good or bad — it’s powerful, and power needs a boundary. For internal teams, it’s the best part of Claude Tag. For client work, it’s the part to leave off until isolation is airtight. For the full picture, start at the pillar: Claude Tag: A Builder’s Guide for Agencies.

  • Claude Enterprise Compliance: SOC 2, HIPAA & Security

    Claude Enterprise Compliance: SOC 2, HIPAA & Security

    Last verified: June 13, 2026

    Anthropic publishes a defined compliance posture for Claude: it holds SOC 2 Type I and Type II, ISO 27001:2022, and ISO/IEC 42001:2023 credentials; it will sign a Business Associate Agreement (BAA) covering HIPAA-ready services such as the first-party API and Enterprise plans; by default it does not train models on data sent under its commercial terms; and it offers a zero-data-retention (ZDR) arrangement on the Messages and Token Counting APIs. The hard part for buyers is the per-surface boundary — what the BAA covers, which features are blocked under ZDR or HIPAA, how long data is kept, and where it can be processed. Every figure below is drawn from Anthropic’s own trust, privacy, and developer documentation, with sources at the bottom. Eligibility, feature lists, and durations change; treat your signed contract and the live Trust Center as the controlling sources.

    Certifications and attestations

    Five security domains: identity, data, code governance, audit, agents
    Certifications and attestations overview.

    Anthropic’s help center lists the following compliance credentials for its commercial products (Claude for Work and the Anthropic API). It directs customers to the Trust Portal at trust.anthropic.com to request copies of the underlying reports and certificates.

    CredentialStatus as described by AnthropicScope
    SOC 2 Type I & Type IIListed as heldCommercial products (Claude for Work, Anthropic API)
    ISO 27001:2022CertifiedInformation Security Management
    ISO/IEC 42001:2023Certified (issued by Schellman Compliance, LLC, accredited by the ANSI National Accreditation Board)AI Management Systems
    HIPAA“HIPAA-ready configuration (BAA available)”See BAA section

    Anthropic describes itself as “one of the first frontier AI labs” to achieve ISO/IEC 42001:2023 certification, in an announcement dated January 13, 2025. The help-center certifications list does not mention ISO 27017, ISO 27018, FedRAMP, or CSA STAR; those are left out here rather than asserted. GDPR and CCPA are handled through Anthropic’s privacy program and customer agreements rather than as line-item “certifications” (see GDPR section).

    HIPAA and the BAA: covered by product surface

    Five-step path: account, API keys, billing, usage, workspaces
    HIPAA and the BAA by product surface.

    Anthropic states it “provides a Business Associate Agreement (BAA) covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans.” HIPAA readiness is enforced at the organization level: Anthropic provisions a dedicated HIPAA-enabled organization that automatically blocks non-eligible features. To process protected health information (PHI) on the API, an administrator must sign the BAA and contact sales to enable it; for Enterprise, an admin activates HIPAA compliance in the Claude Enterprise admin settings under “Data & Privacy” and signs the BAA there.

    SurfaceBAA / HIPAA-ready coverage
    First-party Claude API (Messages API)Covered as an Eligible Service (admin signs BAA, then contact sales)
    Claude EnterpriseCovered once an admin activates HIPAA compliance and signs the BAA
    Workbench and ConsoleNot covered
    Claude Free, Pro, Max, TeamNot covered
    CoworkNot covered
    Claude CodeNot covered under HIPAA readiness
    Amazon Bedrock / Vertex AINot covered (cloud provider is the data processor; see those platforms)
    Claude Platform on AWS / Microsoft FoundryHIPAA readiness not available
    Beta features (e.g., Claude in Office, Claude Design)Generally not covered unless explicitly listed as eligible

    Within the API, only a subset of features is HIPAA-eligible. Anthropic enforces this in code: a HIPAA-enabled organization that sends a non-eligible feature gets a 400 invalid_request_error naming the blocked feature. Anthropic states your signed BAA is the official source of truth for what is covered.

    API featureHIPAA-eligible
    Messages API (/v1/messages)Yes
    Token countingYes
    Web searchYes (dynamic filtering not eligible)
    Prompt caching, structured outputs, extended/adaptive thinking, citations, 1M context, PDF (inline), data residency, effort, fast mode, bash & text-editor tools, memory toolYes
    Web fetch, computer use, advisor tool, context management (compaction / editing), tool search, cache diagnosticsNo
    Code execution, programmatic tool callingNo
    Batch API, Files API, Agent Skills, MCP connector, Claude Managed Agents, MCP tunnelsNo

    PHI must appear only in message content, attached files, or related file names/metadata — never in JSON schema definitions (property names, enum/const values, or pattern regexes), because compiled schemas are cached separately and do not receive the same PHI protections. Anthropic notes workspace names, user contact details, billing data, and support tickets are not expected to contain PHI under the BAA.

    Data retention (commercial default)

    Under Anthropic’s commercial data retention policy, conversation content is not retained by default for the API, and API inputs and outputs are automatically deleted on the backend within 30 days of receipt or generation. For interface products such as Claude for Work, data persists until you delete it, after which it is removed from backend storage within 30 days. Two exceptions extend retention regardless of arrangement.

    Data type / eventRetention
    API inputs and outputs (default)Auto-deleted within 30 days
    Deleted conversation content (Claude for Work)Removed from backend within 30 days
    Inputs/outputs for a chat flagged as a Usage Policy violationUp to 2 years
    Trust & safety classification scores (flagged chat)Up to 7 years
    Data tied to feedback you submit (thumbs up/down, bug report)5 years

    Zero data retention (ZDR)

    Desk with laptop, checklist notebook, and billing card ready before creating an Anthropic API key
    Zero data retention (ZDR).

    With a ZDR arrangement, customer data is not stored at rest after the API response is returned, except where needed to comply with law or combat misuse. ZDR is requested through Anthropic sales and enabled per organization — it does not carry over automatically to new organizations under the same account. Even under ZDR, Anthropic retains User Safety classifier results, and may retain inputs and outputs for up to 2 years if a chat or session is flagged for a Usage Policy violation. CORS is not supported for ZDR organizations, so browser apps must call through a backend proxy.

    SurfaceZDR coverage
    Claude Messages API & Token Counting APIEligible
    Claude Code (Commercial org API keys, or via Claude Enterprise with ZDR enabled)Eligible
    Console and WorkbenchNot eligible
    Claude Teams & Claude Enterprise interfacesNot eligible (except Claude Code via Enterprise with ZDR on)
    Claude Free, Pro, MaxNot eligible
    Claude Managed AgentsNot eligible (stateful; delete transcripts manually)
    Batch API, Files API, code execution, Agent Skills, MCP connectorNot eligible
    Third-party integrationsNot eligible

    A handful of ZDR-eligible features are marked “Yes (qualified)” — structured outputs and cache diagnostics — meaning Anthropic retains a narrow, documented set of technical data (for example, a cached JSON schema for up to 24 hours since last use) rather than your prompts or Claude’s outputs.

    Model-training policy and Covered Models

    Anthropic’s Privacy Policy states it does not apply to content processed on behalf of business customers; that data is governed by the customer agreement. For the API specifically, Anthropic states retained data is never used for model training without your express permission. Anthropic’s consumer-terms update confirms the data-use changes “do not apply to services under our Commercial Terms,” including Claude for Work, Claude for Government, Claude for Education, and API use (including via Amazon Bedrock and Google Cloud’s Vertex AI). Training on commercial data happens only if a customer explicitly opts in (for example, the Development Partner Program).

    One model-specific exception affects retention, not training: Claude Fable 5 and Claude Mythos 5 are designated Covered Models and require 30-day data retention. ZDR is not available for these two models; a request to either from an organization whose retention configuration doesn’t meet the requirement returns a 400 invalid_request_error. Organizations with ZDR can turn on 30-day retention for a single workspace (Console > Settings > Workspaces > Privacy controls) to use those models there while keeping ZDR elsewhere. On Bedrock, Vertex AI, and Microsoft Foundry, retention requirements for these models are set by each platform.

    GDPR, data residency, and international transfers

    For users in the EEA, UK, or Switzerland, the data controller is Anthropic Ireland, Limited; elsewhere it is Anthropic PBC. Where the EU or UK GDPR applies, Anthropic responds to verifiable data-subject requests within one calendar month. For transfers to countries without an adequacy decision, Anthropic relies on standard contractual clauses, and publishes its subprocessors at anthropic.com/subprocessors.

    On data residency, the Claude API exposes two independent controls. inference_geo sets where inference runs per request — values are "global" (default) or "us" — and is supported on Claude Opus 4.6, Sonnet 4.6, and later (older models return a 400). Workspace geo controls where data is stored at rest and where endpoint processing happens; it is set at workspace creation and cannot be changed afterward. Per Anthropic’s documentation, "us" is currently the only available workspace geo, and only "us" and "global" inference geos are available — so there is currently no EU-resident storage option at the workspace level. US-only inference is priced at 1.1x the standard rate on supported models. Data residency is available on the Claude API (first-party) and Claude Platform on AWS; on Bedrock and Vertex AI the region is set by the endpoint or inference profile.

    Does Anthropic train its models on my API or commercial data?

    No, not by default. Anthropic’s Privacy Policy excludes business-customer content (governed by your customer agreement), and for the API it states retained data is never used for training without your express permission. The consumer data-use changes explicitly do not apply to Commercial Terms services. Training on commercial data requires an explicit opt-in.

    Will Anthropic sign a BAA, and for what?

    Yes. Anthropic signs a BAA covering HIPAA-ready services such as the first-party API and Enterprise plans. The Messages API is covered as an Eligible Service. It does not cover Workbench/Console, Free/Pro/Max/Team, Cowork, Claude Code, or beta features unless explicitly listed. An admin must sign the BAA and enable HIPAA readiness; the organization then auto-blocks non-eligible features.

    What’s the difference between ZDR and HIPAA readiness?

    Per Anthropic, ZDR prevents customer data from being stored at rest after the API response. HIPAA readiness is a broader set of safeguards (encryption, access controls, audit logging) that protect PHI throughout its lifecycle and lets data be retained with safeguards rather than deleted immediately. Anthropic states you do not also need ZDR if you have HIPAA readiness.

    How long does Anthropic keep my data?

    By default, API inputs and outputs are auto-deleted within 30 days. If a chat is flagged as a Usage Policy violation, inputs/outputs may be retained up to 2 years and trust & safety classification scores up to 7 years. Data tied to feedback you submit is kept 5 years. ZDR removes the default at-rest storage but does not remove the law/misuse exceptions.

    Can I keep Claude inference and data in the EU?

    Not at rest currently. The API’s inference_geo can pin inference to "us" or run "global", but Anthropic’s documentation lists "us" as the only available workspace geo (storage region). EU/UK data-subject rights and standard contractual clauses apply regardless, but an EU storage-residency option is not currently offered at the workspace level per the docs verified here.

    Related on Tygart Media: is Claude safe · Anthropic safety.

  • How Buyers Price a Restoration Company: 2026 Deal Killers

    How Buyers Price a Restoration Company: 2026 Deal Killers

    Most restoration buyers in 2026 are paying for the wrong things. They look at top-line revenue, the truck count, the trailing-twelve EBITDA — and miss the structural details that decide whether the company they just bought is a $4M business or a slow-motion writedown. Private equity has deployed over $6 billion across 50-plus platforms since 2018, and the buyers who keep winning at these multiples are the ones with a checklist that goes deeper than the broker’s pitch deck.

    Here is what the disciplined buyers — strategic acquirers, PE platforms, and operator-buyers — actually look at when they price a restoration company in 2026, and the five line items that quietly kill more deals than anything in the financials.

    What buyers are actually paying for in 2026

    Six cards: repeatable jobs, clean books, bench depth, channel mix, owner optional, risk controls
    What buyers pay for in 2026 — transferability over heroics.

    Median sale prices in restoration have risen to roughly $2.2M. Shops under $2M in revenue tend to clear at 2.5x to 3.0x SDE. The $2M to $5M EBITDA band — what the industry calls the PE feeder zone — trades at 4x to 6x EBITDA. Platforms above $10M EBITDA push 6x to 8x with strategic buyers willing to stretch further for the right geography or carrier panel. The spread between bottom and top of that range is not random. It is a function of five drivers that a thorough buyer will price line by line.

    Carrier preferred-vendor status is the first thing on every diligence sheet. A company on the preferred panel of two or more Tier 1 carriers — State Farm, Allstate, USAA, Liberty Mutual — gets a multiple premium because that revenue is durable, repeatable, and very hard for a new entrant to replicate. A company that depends on one TPA program for half its work gets discounted because that revenue is one phone call away from disappearing.

    Revenue mix matters almost as much. Mitigation-heavy companies — fast-turn water and emergency services — carry better margins and more predictable cash conversion than companies leaning on large-loss reconstruction. Reconstruction-heavy shops can still trade well, but buyers will model lower margins and longer working-capital cycles, which compresses the multiple.

    Management depth below the founder is the third lever. If the owner is the estimator, the rainmaker, and the operations lead, the buyer will assume a 12 to 24 month earnout structure and discount the price accordingly. A general manager, an estimating lead, and a production manager who are staying through transition can add an entire turn of EBITDA to the offer.

    CAT exposure is the fourth. Companies with more than 20-25% of revenue tied to catastrophic events get valued on a normalized basis — buyers strip the spike years out of the average. If you bought a restoration company on a peak hurricane year’s numbers, you overpaid. Sophisticated buyers know this and adjust before they sign the LOI.

    The fifth is books that survive a quality-of-earnings review. In about 85% of deals, the QoE adjusts down from the seller’s claimed EBITDA, and the average haircut runs 10 to 15%. Companies that have already run a sell-side QoE and addressed the easy adjustments hold their price better than companies that hand a buyer a QuickBooks export and a confident shrug.

    The five quiet deal-killers

    Red checklist of five quiet deal killers for restoration M&A
    Five quiet deal-killers — fix before the LOI.

    Most deals do not die on price. They die in the back half of due diligence, when something surfaces that the seller either did not disclose or did not realize mattered. These are the five issues that show up most often, and what a disciplined buyer does about each one.

    1. Customer or carrier concentration over 20%. If a single carrier, TPA program, or property manager drives more than a fifth of revenue, the company has a single point of failure. Buyers either re-price the deal, structure a larger earnout tied to retention, or walk. The honest fix on the seller side is to diversify the book 18 months before going to market, but most do not have that luxury once they have decided to sell.

    2. Licensing and certification gaps. Restoration is a regulated trade in most states. Buyers verify IICRC firm certification, individual technician WRT and ASD credentials, AMRT for mold work, state contractor licenses, and any specialty endorsements required locally. A lapsed firm certification or an expired mold license is not always a deal-killer, but it is always a price renegotiation and sometimes a regulatory exposure that gets baked into the purchase agreement as an indemnity.

    3. Aged accounts receivable. Restoration AR ages slowly because insurance carriers and TPAs pay slowly. Buyers will look at the receivables aging report and discount anything over 90 days, sometimes severely. If a meaningful portion of the company’s "earnings" is actually trapped in 180+ day AR that nobody is going to collect, the working capital adjustment at close will swallow a real chunk of the purchase price.

    4. Founder dependency in estimating and sales. This is the single most common reason restoration deals collapse or restructure into heavy earnouts. If the founder writes 60% of the estimates and personally manages the top carrier relationships, buyers know the business does not transfer. The seller who builds a real estimating department and pushes carrier relationships down to a sales lead two years before sale will capture meaningfully more value.

    5. Compliance and labor exposure. 1099 versus W-2 misclassification, prevailing wage issues on commercial jobs, OSHA history, and EMR trends all surface in diligence. Buyers will hire an HR specialist on any deal above a few million in revenue, and a clean compliance picture is worth 0.25x to 0.5x of EBITDA on its own.

    What a buyer should actually run before the LOI

    Six cards covering job margin, cycle time, AR days, utilization, CAC, close rate
    Run unit economics before the LOI — not after.

    The minimum diligence package on a serious restoration acquisition includes: a quality-of-earnings review by a firm that has seen at least a dozen restoration deals, an independent verification of carrier preferred-vendor status and any TPA contracts, a customer concentration analysis at the carrier and account level, an AR aging review by a buyer-side accountant, an IICRC and state licensing audit, and a sit-down with the operations and estimating leads with the founder out of the room. That last item is the most underused and the most predictive.

    Buyers who skip any of these line items end up renegotiating after close or eating a writedown a year in. Buyers who run all of them tend to pay slightly less and own businesses that transfer cleanly.

    Bottom line

    The 2026 restoration market is the best buyer’s window of the next five years, but only for buyers with discipline. The capital is there, the seller pipeline is there as the founder generation exits, and the platform playbook has been proven by HighGround, American Restoration, and a half-dozen others. The companies worth buying at top-of-range multiples are the ones with diversified carrier mix, real management depth, and books that survive a serious QoE. Everything else is a turnaround dressed up as an acquisition — and turnarounds in restoration take 18 to 36 months to fix and often cost more than the purchase premium ever saved. Pay for what transfers. Walk from what does not.

    Related on Tygart Media: Starlink on a water job · S500 in the van · local SEO for restoration.

    Frequently asked questions

    What multiple do restoration companies sell for in 2026?

    Sub-$2M revenue shops typically trade at 2.5x to 3.0x SDE. Companies in the $2M to $5M EBITDA range — the PE feeder zone — clear 4x to 6x EBITDA. Platforms above $10M EBITDA reach 6x to 8x, with strategic premiums pushing higher in the right geography or carrier panel.

    What kills restoration acquisition deals most often?

    Customer or carrier concentration above 20%, founder dependency in estimating and sales, aged accounts receivable that does not collect, licensing or IICRC certification gaps, and labor compliance exposure — in roughly that order of frequency.

    How long should a buyer-side diligence process take?

    For a sub-$5M revenue restoration acquisition, plan on 60 to 90 days from signed LOI to close. Quality of earnings runs three to five weeks, legal and licensing diligence runs parallel, and customer/carrier verification typically lands in the final two weeks before close.

    Is buying a restoration franchise better than buying an independent?

    Franchises like SERVPRO or ServiceMaster Restore deliver brand, training, and national-account access at the cost of royalties and territorial restrictions. Independents give you full margin upside and the freedom to build proprietary carrier relationships, but require self-built systems and certifications. For first-time operators, the franchise reduces execution risk. For experienced operators, an independent acquisition tends to compound faster.

  • Real Estate ESG Frameworks: Navigating GRESB, CDP & SB 253

    Real Estate ESG Frameworks: Navigating GRESB, CDP & SB 253

    Property owners and asset managers in institutional real estate operate in an increasingly layered ESG disclosure environment. GRESB drives investor-facing ESG scoring. CDP provides voluntary supply chain disclosure that is increasingly investor-requested. California SB 253 mandates Scope 3 disclosure for large entities. And the EU’s Corporate Sustainability Reporting Directive (CSRD) extends mandatory ESG reporting to European operations and, through supply chain due diligence requirements, reaches global real estate companies with EU exposure.

    For BOMA members — building owners, REITs, asset managers — understanding which framework governs which obligations, and where they overlap, is essential for building an ESG program that satisfies all of them without duplicating work. This article maps each framework against the specific Scope 3 obligations it creates for property owners, with particular focus on the contractor supply chain data gap that sits at the intersection of all three.

    GRESB: Investor-Driven, Asset-Level, Annual

    Bridge diagram between facility owners and restoration vendors for Scope 3 data
    GRESB — investor-driven, asset-level, annual.

    GRESB is the primary ESG accountability mechanism for institutional real estate globally. It is not a regulation — it is an investor-driven benchmark that most institutional property owners participate in voluntarily because their capital partners require it. GRESB assessments are annual, asset-level, and scored on a 0–100 scale that investors use to compare portfolio ESG performance.

    For Scope 3, GRESB evaluates both governance (do you have a Scope 3 target and supply chain policy?) and performance (do you have actual Scope 3 data?). Contractor emissions — Scope 3 Category 1 — factor into both components. Property owners without contractor data collection programs score lower on supply chain governance and leave Category 1 data fields blank in the Performance section.

    GRESB is the most immediate Scope 3 pressure for most BOMA members because it directly affects your capital relationships. A poor GRESB score can affect asset valuations, borrowing costs, and investor mandates in ways that regulatory compliance does not.

    CDP: Voluntary, Supply Chain Driven, Escalating

    CDP’s supply chain program allows large corporations — including real estate companies’ major tenants and capital partners — to request Scope 3 supply chain data from their vendors. For property owners, CDP requests typically arrive from two directions: from institutional tenants whose corporate ESG programs require supply chain data from their landlords, and from institutional investors whose own CDP commitments require portfolio-level Scope 3 supply chain data.

    CDP participation is voluntary, but declining a CDP request from a major tenant or capital partner has commercial consequences. As CDP participation expands — the program now covers thousands of companies — the probability that a significant counterparty will request Scope 3 data from your organization continues to increase.

    California SB 253: Mandatory, Regulated, Enforced

    Facility manager to restoration vendor Scope 3 data bridge
    California SB 253 — mandatory and enforced.

    SB 253 is the only mandatory framework in this set, at least for US-domiciled organizations. It applies to entities doing business in California with revenues above the threshold, requires Scope 1 and 2 disclosure starting with fiscal year 2025 data, and adds Scope 3 starting with fiscal year 2026 data. CARB administers the program and has authority to assess penalties for non-compliance and material misstatement.

    For real estate entities with California assets, SB 253 transforms the Scope 3 contractor data question from an investor relations consideration into a legal compliance obligation. The same contractor emissions data that improves your GRESB score and satisfies CDP supply chain requests now also needs to be accurate enough to withstand CARB review.

    Where Restoration Contractor Data Fits in Each Framework

    Bridge between facility owners and restoration vendors for Scope 3 data
    Where restoration contractor data fits.

    The Restoration Carbon Protocol addresses the same data gap across all three frameworks. An RCP-compliant restoration contractor provides project-level emissions data in a format aligned with GHG Protocol Category 1. That data feeds directly into your GRESB Performance section, satisfies CDP supply chain data requests for Category 1, and provides the documented, methodology-backed Scope 3 Category 1 data that SB 253 requires.

    The strategic efficiency argument for RCP adoption by property owners is that solving the restoration contractor data problem once solves it for all three frameworks simultaneously. You do not need different data for GRESB, CDP, and SB 253 — you need GHG Protocol Category 1 data, and RCP produces it in that format.

    Building a Unified Response

    For BOMA members navigating GRESB, CDP, and SB 253 simultaneously, the most efficient path is a unified Scope 3 data program rather than three separate compliance efforts. The foundation is a GHG Protocol-aligned inventory methodology that covers all fifteen Scope 3 categories. Contractor data — collected through RCP-compliant vendor agreements and green lease extensions — feeds into that inventory once and satisfies all three frameworks.

    The timeline pressure is real: SB 253 Scope 3 data collection for fiscal year 2026 should already be underway, GRESB 2026 assessments will open in the first quarter, and CDP supply chain requests arrive year-round. The property owners who have built the contractor data infrastructure now — preferred vendor panels with RCP adoption, ESG clauses in service agreements, documented methodology — will be the ones with defensible Scope 3 inventories when all three frameworks converge on the same data set in 2027.

    Related on Tygart Media: FM ESG frameworks · GRESB Scope 3 · Scope 3 for property owners.

    Frequently Asked Questions

    Does GRESB require the same data as SB 253?

    Both require Scope 3 GHG data aligned with the GHG Protocol Corporate Standard. GRESB collects it through an annual assessment submitted to the benchmark platform. SB 253 requires public disclosure filed with CARB. The underlying data set is the same — a GHG Protocol-compliant Scope 3 inventory by category — which is why building one unified inventory program satisfies both frameworks efficiently.

    How does CSRD affect US-based property owners?

    The EU’s Corporate Sustainability Reporting Directive (CSRD) applies directly to large EU-domiciled companies and EU subsidiaries of non-EU companies above defined thresholds. For US-based real estate companies with EU operations or EU-listed capital partners, CSRD may apply directly. Even for those it does not reach directly, CSRD’s supply chain due diligence requirements mean EU-based capital partners and tenants will increasingly request Scope 3 supply chain data from their US counterparties as part of their own CSRD compliance.

    What is the Restoration Carbon Protocol and why do BOMA members need it?

    The Restoration Carbon Protocol (RCP) is an industry self-standard that gives restoration contractors a structured GHG accounting methodology for project-level emissions reporting. For BOMA members, RCP-compliant contractors provide the Scope 3 Category 1 data needed for GRESB performance scores, CDP supply chain responses, and SB 253 mandatory disclosure — in a format directly compatible with GHG Protocol reporting requirements.

  • Contractor ESG Clauses: Driving Scope 3 Data Compliance

    Contractor ESG Clauses: Driving Scope 3 Data Compliance

    Green leases have been a standard tool in the institutional real estate ESG toolkit for over a decade. Originally designed to align landlord and tenant incentives around energy efficiency, green lease clauses have evolved to cover data sharing, sustainability reporting, and — in more sophisticated agreements — explicit GHG emissions obligations.

    The same contractual logic that makes green leases effective for tenant emissions management can be applied to the contractor supply chain. Property owners who have invested in green lease programs for tenant Scope 3 (Category 13) data now have a parallel opportunity: using vendor agreement language to systematically collect Scope 3 Category 1 data from the contractors who perform work on their assets.

    What Green Lease Language Has Achieved — and Where It Stops

    Seven cards naming common AI chatbot failure modes
    What green lease language has achieved — and where it stops.

    Modern green lease frameworks — developed by BOMA, the Institute for Market Transformation, the Urban Land Institute, and others — have established standard clauses for energy data sharing, sub-metering requirements, sustainable operations standards, and ENERGY STAR reporting. These clauses give property owners a contractual mechanism to collect the tenant data needed for GRESB Category 13 reporting and corporate GHG inventories.

    Green leases stop at the tenant boundary. They do not govern the contractors the property owner engages for capital projects, maintenance, and emergency response. Those contractor relationships are covered by master service agreements, purchase orders, and emergency vendor panel arrangements — none of which have traditionally included GHG data reporting requirements.

    Extending the Logic: Contractor ESG Clauses

    Three cards for field SOPs, owner prompts, and KPI rhythm in an operations kit
    Extending the logic — contractor ESG clauses.

    The Green Lease 2.0 framework extends the proven lease-language approach to contractor agreements. The principle is identical: establish a contractual data delivery obligation, specify the format and methodology, and make compliance a condition of the vendor relationship.

    For restoration contractors specifically, the relevant clause structure covers three elements. A methodology requirement — specifying that the contractor must use a recognized GHG accounting methodology (such as the Restoration Carbon Protocol) for calculating project emissions. A data delivery requirement — specifying that a project emissions report in a format compatible with GHG Protocol Category 1 reporting must be delivered within 30 days of project completion. And a pre-qualification requirement — specifying that participation in the property owner’s preferred restoration vendor panel requires demonstrated GHG reporting capability prior to emergency deployment.

    Why the Pre-Qualification Step Matters

    The most important element of the contractor ESG clause framework is pre-qualification — establishing GHG reporting capability before the loss event occurs. Property owners cannot negotiate data requirements at 2 AM when a pipe bursts. The contractual infrastructure needs to exist before the emergency.

    Pre-qualification creates a preferred vendor panel of restoration contractors who have adopted RCP or an equivalent methodology and are contractually committed to delivering project emissions data. When a loss event occurs, the property manager calls from that panel — and GHG data collection is already built into the engagement.

    What This Looks Like for GRESB and SB 253

    Three panels showing one problem, three options, one recommendation
    What this looks like for GRESB and SB 253.

    For GRESB participants, a documented contractor ESG clause program with demonstrated adoption across your preferred vendor panel satisfies the supply chain governance requirements in the Management component of the GRESB assessment. It shows that your organization has policies in place, that those policies have contractual teeth, and that you are actively collecting contractor emissions data — not estimating it.

    For SB 253, the contractor ESG clause approach provides the documented data collection methodology that CARB’s guidance suggests as the evidentiary standard for Scope 3 Category 1 reporting. Organizations that can demonstrate a systematic contractor data collection program — rather than spend-based estimation — are better positioned for both initial compliance and the audit scrutiny that mandatory disclosure programs inevitably generate over time.

    Green Lease 2.0 is not a dramatic reinvention. It is the application of a framework that already works — for tenants — to the contractor relationships where property owners have an equivalent data obligation and an equivalent contractual lever to close it.

    Related on Tygart Media: facility ESG frameworks (GRESB / CDP / SB 253) · RCP for property owners · Scope 3 contractor compliance checklist.