What a Managed IT Agreement Actually Covers

"Managed IT" is not a standardized product. Two proposals carrying the same monthly number can cover substantially different amounts of work, and the difference usually surfaces in month four, when an invoice arrives for something you assumed was covered.

This is a plain description of what sits inside a managed services agreement: the components, how the service is actually delivered day to day, what is normally excluded, how it gets priced, and the specific items worth confirming in writing before signing.

The seven components

Most agreements are assembled from the same seven pieces. Labels vary between providers; the substance shouldn't.

1. Monitoring and alerting

Agents installed on servers, workstations and network hardware report health continuously — disk capacity, failed services, backup failures, hardware warnings, unusual traffic. What matters is not the dashboard but the response commitment attached to it. Confirm which alert types generate action without you having to call, and which simply appear in a report.

2. Patch and update management

Operating systems, browsers and common third-party applications, on a defined schedule, with a rollback path when a patch breaks something. Ask for the maintenance window, the interval between a vendor releasing a patch and it reaching your machines, and how exceptions are handled for line-of-business software that can't be updated on the standard cycle.

3. Endpoint security

Typically endpoint detection and response software, plus someone triaging what it produces. Two things to establish: whether the license sits inside the monthly fee or is billed separately, and who investigates an alert at 2am — a person, an automated rule, or a queue that gets looked at in the morning.

4. Backup and recovery

Two numbers belong in the agreement rather than in the sales conversation: the recovery point objective (how much data you can lose) and the recovery time objective (how long you can be down). Both should be stated per system, since a file server and a production database rarely warrant the same treatment.

A backup that has never been restored is a hypothesis. Ask how often test restores are performed, and ask to see the results of the last one.

5. Helpdesk and end-user support

Where staff go when something breaks. Check the covered hours, the intake channels (phone, email, portal, chat), and whether volume is capped. Some agreements include unlimited remote support but meter on-site visits; some include a fixed number of tickets per user per month. Either arrangement is workable — not knowing which one you have is not.

6. Vendor management

When the phone system, the line-of-business application, the internet circuit and the printer fleet each carry their own support contract, someone spends their week on hold. A managed agreement can move that work to the provider. It is frequently implied and just as frequently left out of the written scope, so confirm which vendors are named and what the provider is authorized to do on your behalf.

7. Planning and reporting

A recurring review covering what is aging out, what is coming up for renewal, and what belongs in next year's capital budget. Establish the cadence (monthly, quarterly, annual), who attends, and what the written output looks like.

How the service actually runs

The component list describes what is covered. These are the mechanics of how it gets delivered — the part that determines what working with a provider feels like week to week.

Onboarding

The first 30 to 90 days are discovery and stabilization: inventorying hardware and software, documenting the network, deploying agents, standardizing configurations, and clearing the backlog that accumulated before you arrived. Establish whether onboarding is included in the monthly fee or billed as a one-time project, and what "complete" means.

Ticketing and escalation

Requests enter a ticketing system and are graded by severity. Most providers run tiered support — a first line resolving common issues, escalating to engineers as needed. Ask what percentage is resolved at first contact, and what triggers escalation: elapsed time, issue type, or someone asking.

Response targets

Service levels are usually defined by severity band. Note carefully that most agreements commit to a response time, not a resolution time. A one-hour response and a one-hour resolution are entirely different commitments, and the gap between them is where most disappointment lives.

SeverityTypical definitionWhat to confirm
CriticalBusiness stopped — server down, site offline, no connectivityResponse target, and whether it holds outside business hours
HighA department or key system impairedWho decides the severity — you or the provider
NormalA single user blockedThe target, and whether it is measured in hours or business days
LowRequests, changes, questionsWhether these count against any ticket cap

Documentation and access

The provider will build and maintain network diagrams, asset inventories, configuration records and credentials. Confirm at the outset that this documentation is yours, that you can obtain a current copy on request, and in what format.

Co-managed arrangements

If you already have internal IT, a co-managed agreement splits the work rather than replacing anyone — the provider commonly takes monitoring, patching, after-hours coverage and escalation, while internal staff keep user support and business-specific systems. The boundary needs to be written down explicitly, because ambiguity here produces work that both parties assume the other is doing.

What is normally excluded

None of these exclusions is unreasonable. The only real problem is discovering one after the fact.

Commonly excludedWhat to clarify
ProjectsMigrations, office moves, new deployments — where is the line between support and project?
HardwareQuoted at cost or with a markup, and how much
Third-party licensingMicrosoft 365, security tooling, backup storage — inside the per-user fee or passed through
After-hours workWhat counts as after-hours, and at what rate
Onboarding and offboarding usersOften capped per month; seasonal hiring can exceed the cap quickly
Physical infrastructureCabling, rack work and site surveys are usually scoped separately
Compliance workAudit preparation and evidence collection are typically billed on their own

How it gets priced

Three models dominate, and the choice determines how the cost behaves as the business changes.

ModelHow it scalesWatch for
Per userTracks headcountStaff with several devices may be counted more than once — confirm the definition of "user"
Per deviceTracks the asset countCost climbs quietly as tablets, kiosks and spare laptops accumulate
Tiered / all-inFlat until a threshold is crossedKnow exactly where the thresholds sit before signing

Per-user pricing is the most common and generally the easiest to forecast, since headcount is already a planned number. Whichever model applies, ask for the price at your current size and at roughly 20% larger, so next year's figure isn't a surprise.

Before you sign

  • Response or resolution? Confirm which the stated times refer to, per severity band.
  • Exclusions in writing. A list, not an assurance that everything is handled.
  • Data and documentation ownership. If you leave, what comes back to you, in what format, and how quickly.
  • The offboarding process. Ask at the start, while everyone is friendly.
  • Price escalators. Annual increases are normal; unannounced ones are not.
  • Named vendors. Which third parties the provider will deal with directly, and with what authority.

Any provider worth engaging can answer all six in a single conversation, and will put the answers in the agreement rather than in an email.

If you are reviewing a managed services proposal and want a second read on what it actually covers, get in touch — or take a look at how we scope managed IT engagements.

Want to talk through something like this?

Tell us what you're working on and we'll show you what a signed-off, fixed-cost engagement looks like.