"Managed IT" is not a standardized product. Two proposals carrying the same monthly number can cover substantially different amounts of work, and the difference usually surfaces in month four, when an invoice arrives for something you assumed was covered.
This is a plain description of what sits inside a managed services agreement: the components, how the service is actually delivered day to day, what is normally excluded, how it gets priced, and the specific items worth confirming in writing before signing.
The seven components
Most agreements are assembled from the same seven pieces. Labels vary between providers; the substance shouldn't.
1. Monitoring and alerting
Agents installed on servers, workstations and network hardware report health continuously — disk capacity, failed services, backup failures, hardware warnings, unusual traffic. What matters is not the dashboard but the response commitment attached to it. Confirm which alert types generate action without you having to call, and which simply appear in a report.
2. Patch and update management
Operating systems, browsers and common third-party applications, on a defined schedule, with a rollback path when a patch breaks something. Ask for the maintenance window, the interval between a vendor releasing a patch and it reaching your machines, and how exceptions are handled for line-of-business software that can't be updated on the standard cycle.
3. Endpoint security
Typically endpoint detection and response software, plus someone triaging what it produces. Two things to establish: whether the license sits inside the monthly fee or is billed separately, and who investigates an alert at 2am — a person, an automated rule, or a queue that gets looked at in the morning.
4. Backup and recovery
Two numbers belong in the agreement rather than in the sales conversation: the recovery point objective (how much data you can lose) and the recovery time objective (how long you can be down). Both should be stated per system, since a file server and a production database rarely warrant the same treatment.
A backup that has never been restored is a hypothesis. Ask how often test restores are performed, and ask to see the results of the last one.
5. Helpdesk and end-user support
Where staff go when something breaks. Check the covered hours, the intake channels (phone, email, portal, chat), and whether volume is capped. Some agreements include unlimited remote support but meter on-site visits; some include a fixed number of tickets per user per month. Either arrangement is workable — not knowing which one you have is not.
6. Vendor management
When the phone system, the line-of-business application, the internet circuit and the printer fleet each carry their own support contract, someone spends their week on hold. A managed agreement can move that work to the provider. It is frequently implied and just as frequently left out of the written scope, so confirm which vendors are named and what the provider is authorized to do on your behalf.
7. Planning and reporting
A recurring review covering what is aging out, what is coming up for renewal, and what belongs in next year's capital budget. Establish the cadence (monthly, quarterly, annual), who attends, and what the written output looks like.
How the service actually runs
The component list describes what is covered. These are the mechanics of how it gets delivered — the part that determines what working with a provider feels like week to week.
Onboarding
The first 30 to 90 days are discovery and stabilization: inventorying hardware and software, documenting the network, deploying agents, standardizing configurations, and clearing the backlog that accumulated before you arrived. Establish whether onboarding is included in the monthly fee or billed as a one-time project, and what "complete" means.
Ticketing and escalation
Requests enter a ticketing system and are graded by severity. Most providers run tiered support — a first line resolving common issues, escalating to engineers as needed. Ask what percentage is resolved at first contact, and what triggers escalation: elapsed time, issue type, or someone asking.
Response targets
Service levels are usually defined by severity band. Note carefully that most agreements commit to a response time, not a resolution time. A one-hour response and a one-hour resolution are entirely different commitments, and the gap between them is where most disappointment lives.
| Severity | Typical definition | What to confirm |
|---|---|---|
| Critical | Business stopped — server down, site offline, no connectivity | Response target, and whether it holds outside business hours |
| High | A department or key system impaired | Who decides the severity — you or the provider |
| Normal | A single user blocked | The target, and whether it is measured in hours or business days |
| Low | Requests, changes, questions | Whether these count against any ticket cap |
Documentation and access
The provider will build and maintain network diagrams, asset inventories, configuration records and credentials. Confirm at the outset that this documentation is yours, that you can obtain a current copy on request, and in what format.
Co-managed arrangements
If you already have internal IT, a co-managed agreement splits the work rather than replacing anyone — the provider commonly takes monitoring, patching, after-hours coverage and escalation, while internal staff keep user support and business-specific systems. The boundary needs to be written down explicitly, because ambiguity here produces work that both parties assume the other is doing.
What is normally excluded
None of these exclusions is unreasonable. The only real problem is discovering one after the fact.
| Commonly excluded | What to clarify |
|---|---|
| Projects | Migrations, office moves, new deployments — where is the line between support and project? |
| Hardware | Quoted at cost or with a markup, and how much |
| Third-party licensing | Microsoft 365, security tooling, backup storage — inside the per-user fee or passed through |
| After-hours work | What counts as after-hours, and at what rate |
| Onboarding and offboarding users | Often capped per month; seasonal hiring can exceed the cap quickly |
| Physical infrastructure | Cabling, rack work and site surveys are usually scoped separately |
| Compliance work | Audit preparation and evidence collection are typically billed on their own |
How it gets priced
Three models dominate, and the choice determines how the cost behaves as the business changes.
| Model | How it scales | Watch for |
|---|---|---|
| Per user | Tracks headcount | Staff with several devices may be counted more than once — confirm the definition of "user" |
| Per device | Tracks the asset count | Cost climbs quietly as tablets, kiosks and spare laptops accumulate |
| Tiered / all-in | Flat until a threshold is crossed | Know exactly where the thresholds sit before signing |
Per-user pricing is the most common and generally the easiest to forecast, since headcount is already a planned number. Whichever model applies, ask for the price at your current size and at roughly 20% larger, so next year's figure isn't a surprise.
Before you sign
- Response or resolution? Confirm which the stated times refer to, per severity band.
- Exclusions in writing. A list, not an assurance that everything is handled.
- Data and documentation ownership. If you leave, what comes back to you, in what format, and how quickly.
- The offboarding process. Ask at the start, while everyone is friendly.
- Price escalators. Annual increases are normal; unannounced ones are not.
- Named vendors. Which third parties the provider will deal with directly, and with what authority.
Any provider worth engaging can answer all six in a single conversation, and will put the answers in the agreement rather than in an email.
If you are reviewing a managed services proposal and want a second read on what it actually covers, get in touch — or take a look at how we scope managed IT engagements.