Most companies do not leave a managed services provider because of a disaster. They leave because of a slow realization: the invoices arrive, the contract is being honored, tickets get closed — and yet the environment is no better than it was two years ago.
That is an uncomfortable position to be in, because nothing is obviously wrong. There is no breach to point to, no outage to escalate. The provider is meeting the letter of the agreement. The value simply is not showing up.
What follows is a diagnostic, not an accusation. Plenty of MSPs do excellent work. But the difference between one that is delivering and one that is merely present is visible if you know which signals to look at — and most of them are not in the monthly report.
Why this happens without anyone behaving badly
A managed agreement pays a fixed fee regardless of how much work is required. That structure is a feature: it gives the provider a direct financial reason to keep your systems stable, because every incident costs them margin.
But the same structure has a failure mode. Once an environment is stable enough to stop generating emergencies, the most profitable thing a provider can do is nothing at all. Not maliciously — just through drift. Attention migrates to the accounts that are on fire. Yours goes quiet. The fee keeps clearing.
A provider can be fully compliant with your contract and still not be delivering value. Contract compliance is the floor, not the goal.
Key indicators worth checking
Grouped by where they surface. None is damning on its own; the pattern is what matters.
In the ticket history
| Indicator | What it usually means |
|---|---|
| The same issues recur every few weeks and are closed each time | Symptoms are being cleared; root cause is never being addressed. Closing a ticket is cheaper than fixing the cause. |
| Response targets are met but resolution drags for days | The agreement is being satisfied on the metric that is measured, not the one you care about. |
| Your staff have built workarounds instead of opening tickets | The most telling signal on this list. People stop asking when asking stops helping. Your real ticket volume is higher than the report shows. |
| Ticket volume is flat year over year | A well-managed environment should generate measurably fewer incidents over time. Flat means nothing is being permanently fixed. |
In the relationship
| Indicator | What it usually means |
|---|---|
| You only hear from them when something is broken or being renewed | The account is in maintenance mode. Nobody is thinking about it between invoices. |
| The quarterly review keeps slipping, or never started | Planning was sold as part of the agreement and quietly dropped from delivery. |
| Nobody there can describe what your business actually does | They are managing servers, not supporting an operation. Advice given without that context is generic by definition. |
| The people on your account changed and no one told you | Continuity has been lost, and with it the accumulated knowledge you paid for. |
| You have stopped raising things because it is easier not to | Resignation. By this point the relationship has usually been over for a while. |
In the numbers
| Indicator | What it usually means |
|---|---|
| Reports show activity, not outcomes | Tickets closed and patches applied are inputs. Incidents prevented, downtime avoided and risks retired are outcomes. Most reporting stops at inputs. |
| Every improvement arrives as a separate quote | Worth examining honestly — some work genuinely is out of scope. But when everything is a change order, the base agreement has been hollowed out. |
| Renewal brings a price increase with no change in service | Escalators are normal. An escalator with nothing added to justify it is a signal about how the account is viewed. |
In what you cannot see
| Indicator | What it usually means |
|---|---|
| You cannot remember the last test restore | Backups are running. Whether they are recoverable is an open question until someone proves otherwise. |
| Nobody can produce current documentation on request | Either it does not exist or it is being held rather than shared. Both are problems, and you find out which at the worst possible moment. |
| You do not know what changed in your environment last quarter | Change is happening without a record. That is a security and continuity exposure, not just an admin gap. |
Reading your own results
Count what you recognized.
- One or two. Normal. Every relationship has friction. Raise them directly and watch what happens next — the response tells you more than the issues do.
- Three to five. Drift. The provider is probably capable but the account has gone quiet on their side. This is usually recoverable with a frank conversation and written commitments.
- Six or more. The agreement has become a subscription rather than a service. Worth a formal review, and worth getting a second opinion on what your environment actually needs.
One caveat before acting on any of this: check your own side first. Providers are frequently blamed for constraints their client imposed — a budget that was cut, a project that was deferred, an approval that never came. A fair review looks at both.
How XOR Services approaches it
Our tagline is Integrity by Comparison, and it means something specific and operational rather than aspirational: we deliver what the customer wanted, in the timeframe they expected. Here is what that requires in practice.
Scope is agreed before work begins
We collect and analyze what is actually in your environment, put the design and its boundaries in writing, and get your sign-off before delivery starts. That is the CADD process, and it exists so that "what you wanted" is a documented artifact rather than two parties' differing recollections. You cannot hold a provider to a standard that was never written down — including us.
Root cause over ticket closure
A recurring problem is a design problem. Because our scope is fixed and signed off, we carry the cost of every repeat incident, which means the incentive runs toward fixing causes rather than clearing symptoms. Good structure does more for a client than good intentions.
Your documentation is yours
Diagrams, inventories, configurations and credentials belong to you and are available on request, in a usable format, at any point in the relationship — not as a concession negotiated on the way out. A provider who is confident in their work has no reason to hold the record of it hostage.
We tell you when you do not need something
This is the part that costs us money, and it is the clearest test of the word integrity. If a proposed project will not return what it costs, if existing hardware has real life left, if a cheaper approach will serve you just as well — we say so. Recommending work we would profit from but you do not need is precisely the failure this article describes.
Above what was scoped
Working inside an environment surfaces things nobody hired us to look at: an expiring certificate, a licensing exposure, a single point of failure in a system adjacent to the one we were engaged on. We raise those, with a plain assessment of urgency, whether or not they fall inside the agreement.
Not every finding becomes a project — most do not, and some are simply worth knowing about. But a client should never learn about a risk we already saw. Noticing is free, and staying quiet about it would be a decision, not an oversight.
A reasonable next step
If several of the indicators above landed, the useful move is not necessarily to change providers. It is to find out what your environment actually needs, independently of whoever is currently managing it.
We are happy to walk through your current agreement and your environment with you and give you a straight read on where the gaps are — including the cases where the honest answer is that your provider is doing fine and the problem is somewhere else. Get in touch, or read more about how we scope managed IT engagements.