All field notes

Managed IT · Buyer guidance

Managed IT should define ownership—not hide it inside a tool list.

Monitoring, patching, antivirus, and a help desk are useful. They do not answer the most important question: who is responsible when the problem crosses systems, vendors, security, and business operations?

The stack is not the service

Most managed IT proposals contain recognizable categories: endpoint management, security software, backup, email, remote support, and reporting. Those tools matter, but several providers can buy nearly the same stack.

The real service is the operating model around those tools. Someone must interpret alerts, connect repeated incidents, maintain standards, direct vendors, explain risk, plan lifecycle, and take responsibility when the failure no longer fits cleanly inside a ticket.

Separate routine support from senior ownership

Routine requests should be handled efficiently. Password resets and ordinary workstation issues do not require a principal engineer. Network architecture, identity design, ransomware containment, cloud migrations, business continuity, and major cutovers often do.

A defensible managed relationship identifies the escalation path before a high-impact event. The buyer should know who can make difficult technical decisions, how that person becomes involved, and whether the same person understands the business context.

  • Named responsibility for infrastructure and security decisions
  • Defined boundaries between included support and project work
  • A documented escalation path for difficult incidents
  • Regular priorities tied to risk, lifecycle, and business plans

Documentation is evidence of control

A provider cannot reliably protect or recover an environment it does not understand. Current diagrams, systems, circuits, vendors, licensing, credentials, configurations, and recovery information are operational controls—not administrative decoration.

Good documentation reduces diagnosis time, improves change safety, makes vendors accountable, and protects the business from depending on one person’s memory. It should remain usable during an outage or identity compromise.

The proposal should explain the exit too

A healthy provider relationship does not depend on trapping the client. The agreement should establish who owns credentials, configurations, documentation, tenant data, domains, licensing, and the records needed for transition.

If the provider cannot explain how the relationship ends, the business does not yet understand the relationship it is entering.

Direct access. Senior judgment.

The difficult part is rarely identifying another product.

It is understanding the dependencies, choosing the right sequence, and assigning one person to own the outcome.