An IT department's structure is decided by three boundaries: where support ends and engineering begins, where infrastructure ends and applications begin, and where security stops being somebody's second job. Get those three right and the roles follow; get them wrong and the department is a queue with titles. This page is the roles in the order they are hired, what each owns, and the headcount that triggers each boundary. The underlying arithmetic is the company's own: at a span of seven, a group needs its own lead once it passes seven people, and the planner prints the manager count for any headcount you enter.
The first boundary: support and engineering
One person doing both means the tickets always win, because tickets have people waiting behind them. The first real structural decision an IT department makes is to protect engineering time by giving support its own owner, and it usually arrives at around four or five people. Until then the chart should at least name who is on the queue this week, so the protection is explicit rather than aspirational.
The second boundary: infrastructure and applications
Infrastructure keeps the network, the devices and the identity system running. Applications keeps the systems the business works in, which means it talks to finance, sales and people operations more than it talks to IT. Splitting them at around eight to ten people is what stops one lead from being asked about a firewall rule and an invoicing workflow in the same hour.
The third boundary: security as a seat
Security becomes a role rather than a hat somewhere around fifteen to twenty people, or earlier if the company sells to enterprises and answers questionnaires. Until then the chart must name whose hat it is. An IT chart with no name against security is the single most common gap, and it is the one an auditor finds first.
Questions people ask about it department structure and roles
How many people support how many staff?
It varies far too much by device estate and application count to be worth an average. Size it from ticket volume and response targets, then check the span on the planner.
Should applications report to IT or to finance?
IT, with a dotted line to whoever owns the system. Two solid lines into one applications lead is how a small team acquires two bosses.
What does modern mean here?
Mostly identity and endpoint management as owned seats rather than tasks. The boundaries above do not change.