The right model depends on the leadership, skills, capacity, and coverage you already have—not simply company size.

Fully outsourced IT

One provider owns most day-to-day support, administration, monitoring, security operations, and planning. This works when the business wants a single accountable operating team.

Co-managed IT

Internal IT retains leadership or selected systems while the provider supplies a service desk, security operations, infrastructure, projects, or coverage. Success depends on explicit responsibility boundaries.

Where co-management fails

Shared tools without shared process, unclear escalation, competing standards, and invisible ownership create friction. Put the responsibility matrix and decision rights in the agreement.

Choose based on outcomes

Decide who should own user support, endpoints, identity, cloud, networks, security, applications, vendors, projects, budget, and executive reporting. Then buy only the external capability required.

Write a responsibility matrix before choosing tools

List the recurring decisions as well as the tasks: who approves access, prioritizes tickets, approves a firewall change, accepts risk, and authorizes spending? Assign one accountable business owner per outcome and a named operational role. Define how the two teams hand off work and where the authoritative record lives. Shared access without shared process creates more coordination work.

Work through a concrete incident

Suppose an employee reports a suspicious sign-in during the evening. Identify who receives the report, who investigates, who can revoke access, when leadership is contacted, and who tells the employee what happened. Repeat the exercise for a failed backup and a new-hire request. If the answer is “either team,” make the routing rule explicit before launch.

Review capacity and boundaries after launch

Measure whether the arrangement is releasing internal time for the intended priorities. Track repeated handoffs, duplicated changes, and tickets that stall between queues. A monthly boundary review can expose a missing responsibility before it becomes a dispute. If internal staffing changes, amend the service schedule rather than relying on informal favors from the provider.

About this guidance

Published by Bay Area Managed IT. Examples are illustrative; they are not provider quotes, audited results, or local market survey findings. Read our editorial approach →

Continue the research

PRICING GUIDEManaged IT pricing in the Bay Area: what drives the monthly costBUYER TOOLA practical MSP RFP checklist for small and midsize businessesTRANSITION GUIDEHow to switch managed service providers without losing control

Bring these questions to your next provider conversation.

Use a common scope and keep the evidence beside each answer.

Prepare your RFP →