Skip to content
Remote help Let's Talk

Co-Managed IT: What You Keep, What We Cover

Co-managed IT keeps your internal team and fills in the gaps around them. What it covers, who holds admin, where the bills come from, and who it's wrong for.

An IT person's empty desk in low evening light, dark monitor with a sticky note reading Back Mon 8/17, a wall calendar behind it with a week crossed off in red, a coiled blue network cable, badge lanyard, handwritten notebook, and a full coffee mug in the foreground
In this article

Most companies that ask us about co-managed services have one IT person. They know every wiring closet and every password, and they haven’t taken a full week off in two years. Sometimes the problem is just time. Sometimes it’s a specific skill. Nobody can know all of it, and a strong generalist who runs your network, servers, and user support well might have never set up a firewall at the edge, or might not want to be the only person answerable for whether you’re secure.

That’s what co-managed is for. You keep your internal team and we fill in around them. Two questions, however, need to be answered first: how does administrative control get split, and who handles tier-one support for your end users?

The Co-Managed Baseline

Every agreement includes:

  • Monitoring and alerting on covered servers, workstations, network gear, and software. This watches whether things are running, not whether somebody is inside your network.
  • Patch management, applying patches the vendor has already tested, on a schedule.
  • Backup coverage, which for us means Datto: hourly server backups, replication to two data centers, and a tested restore of every server every night.
  • All eight security layers. Multi-factor authentication, endpoint protection, email filtering, security awareness training, 24/7 monitoring by a security operations center, firewall management, SaaS monitoring, and ransomware protection.

Those layers are not optional and there is no tier that leaves one out. What’s negotiable is whose products fill them. If you already run Okta, or Proofpoint, or SentinelOne, we work with what you have instead of making you rip it out and re-standardize on ours. Fully managed is the opposite: we pick that stack.

What Else We Can Cover

Depending on your team’s skill set, we can also take on:

  • Microsoft 365. Hardening past Microsoft’s defaults, tenant backup, and migrations.
  • Phone systems, if your team would rather not own voice. That’s a separate agreement through ThinkVoIP, our dedicated voice division.
  • Project work. Roadmap, budget forecasting, and execution on the projects your team has no bandwidth for.
  • Workflow automation, so your people stop being the integration layer between systems that don’t talk.

Who Holds Admin Access

Both of us.

Your internal team keeps their administrative accounts. We get our own on the core systems we cover because we can’t patch a server we can’t access or manage a firewall we don’t have rights to.

Some providers require sole administrative access as a condition of the agreement. There’s a defensible reason for it: when two teams can both edit an MX record on a Saturday night, eventually one of them will and forget to tell the other. Mail stops, and two teams start troubleshooting the same outage from opposite ends.

But if a provider takes sole access, your internal team ends up with fewer rights than they had before. Is that really co-managed? We don’t do that. We’d rather agree on who touches what and tell each other when we do. When a software vendor wants domain credentials, or a developer needs rights for a weekend cutover, or you’ve got a subcontractor working on your CCTV system, we decide together what rights they get.

Next up, if anything breaks because of something done by anyone outside our team, fixing it is billable outside the plan. That includes your own IT staff, not just outside vendors. Nobody is assigning blame. It’s the tradeoff for shared access. Whether it’s fair comes down to two things: did the provider tell you about it up front, and are they reasonable about using it.

Who Handles Tier One

Some companies have a strong systems person who knows firewalls, security, and routing cold and would rather not spend the day on end-user tickets. Others have an IT manager who knows every line-of-business app and is great with people, but gets nervous the moment somebody says firewall. Those two want the line drawn in opposite places.

We usually start with tier-one end-user support staying with your internal staff while we cover the infrastructure. Then we adjust the line during scoping to fit what you actually need covered.

Escalation matters more than where the line ends up. When you can’t resolve something, how does it get to us, who decides it has crossed over, and how fast is that supposed to happen? This should be written down with names and time expectations attached, not just a shared understanding that we’re around to help.

Before an agreement is finalized, we will have gone through the environment piece by piece and decided who does what work, who approves it, and who needs to be told when things change. We started doing this because we learned the hard way what happens without it: two competent teams both assuming the other one owned something, and nobody noticing until a user has been waiting four days.

You can also buy help for the overflow. Block time attached to the agreement is how most of our clients handle vacations, a bad flu week, or a gap between hires. Without it, escalations from your users to our service desk bill at our hourly rate.

Strategy and Planning

You get a dedicated consultant and a quarterly review. If your internal lead is effectively your CIO, the three-year roadmap and the budgeting cycle stay with them and we support that rather than duplicate it. If nobody on your side is doing it, we do.

Either way somebody has to, because that’s where the expensive surprises get caught early. Windows Server 2016 reaches end of support in January 2027.1 Our clients have had that migration funded and scheduled since 2023, and most of them are already through it.

Requirements

  • Coverage is close to all-or-nothing. Every Windows server in the domain has to be covered, and every workstation in a covered office. You can’t cover half the machines in one office. Leaving out a separate location is sometimes possible, depending on how your network is put together. Ask about your locations rather than assuming.
  • Our monitoring agent has to be on every covered device. Anything without it isn’t covered.
  • Workstations stay on overnight. Patching and maintenance run after hours, so a machine that gets shut off at the end of the day falls behind.
  • We keep no spare parts. Keep critical hardware under warranty or stock your own spares. Equipment that is out of warranty and unsupported falls outside coverage.
  • Documentation is shared. You get access to our Confluence space, and we ask your team to use it and keep it current.

How You’re Billed

The monthly fee covers the baseline. Engineering time beyond it is billable whether the work is remote or onsite, and we don’t absorb any of it.

Block time is a bank of engineering hours attached to your agreement. You buy the hours in advance and we draw them down. You can see the balance at any time. It covers anything outside the baseline. Work outside Monday through Friday, 8:00 to 5:00 Eastern bills at time and a half.

Size that block honestly when you sign. Guess low and you’ll be approving hourly work in the middle of a busy week.

On top of that, these bill separately:

Formal disaster recovery planning. Building and testing a real DR or business continuity plan is professional services work.

Hard costs. Parts, shipping, third-party licenses and renewals, vendor support incidents, and the work to bring an environment up to the minimum standard we can support.

The exclusion list. On printers and copiers we cover the network connection and the drivers, not the hardware. Fax and copy functions aren’t supported. Locally attached peripherals are best effort. Phones and phone systems are excluded, and we stay out of other providers’ phone systems. We can’t put our monitoring agent on another provider’s phone system anyway. If you want voice off your plate, that’s a separate agreement. Training isn’t included, and neither is moving equipment between locations.

Your monthly fee moves with your device and license counts, but it never drops below a floor you commit to for the term.

Who Co-Managed Is Wrong For

If your internal team is drowning in tickets, handing us the infrastructure doesn’t fix that. You want enough block time to absorb the overflow, or another hire. We can take tier one instead, but that’s basically fully managed.

Companies without real internal IT shouldn’t read co-managed as a discount on fully managed. By real internal IT we mean somebody whose actual job includes handling day-to-day user problems, with enough hours in the week to do it. One full-time person usually clears that bar. A contractor who comes in two days a week doesn’t, and neither does the office manager who happens to be good with computers. If that’s your setup, fully managed is the better fit.

If your internal staff and current provider can’t work together, a new provider might not fix it. Co-managed depends on two teams cooperating daily. When the relationship is the actual problem, changing only one party is a coin flip.

And some companies have a capable internal team that genuinely doesn’t need help with the infrastructure. Keep your money. We would just be watching work that’s already going well.

We’re a fit when you have good internal IT and more ground than they can cover on their own, or ground that sits outside what they do best. We’re also a fit when the environment needs to survive somebody quitting or taking a vacation, and when somebody should be planning a year ahead instead of reacting.

Frequently Asked Questions

Q·01 Is co-managed IT cheaper than fully managed?
Q·02 Do we keep our own admin credentials?
Q·03 We have one IT person who is buried in tickets. Will Co-Managed fix that?
Q·04 What happens if our IT person quits?

How to Get Started

Start a conversation and we’ll figure out what you actually need covered and put it in writing: what we cover, what your team keeps, and what falls outside the fee.


Sources

  1. Windows Server 2016 lifecycle. Microsoft. Windows Server 2016 follows the Fixed Lifecycle Policy, with a mainstream end date of January 11, 2022 and an extended end date of January 12, 2027. Paid Extended Security Updates are offered for some Microsoft products past end of support, so confirm your own options with your licensing channel rather than assuming a hard cutoff. learn.microsoft.com