Managed services agreements are frequently written so that the provider cannot fail. Response targets are vague, the scope of what is covered is not enumerated, and the monthly report is a chart of ticket counts that tells the customer nothing about whether their environment is getting better or worse. Ours states response and resolution targets in hours, lists what is covered and what is not, and reports against them.
Onboarding is a defined process rather than a gradual absorption. Before support begins we complete an asset inventory, review identity and access, confirm backups by testing a restore, apply the agreed security baseline, and document the environment. Where the starting position falls below the baseline and remediation is out of scope, it is recorded as an accepted risk and signed rather than quietly inherited.
You retain ownership of everything. Tenancies, domains, licences and backups are held in your name with your billing, and you keep administrative access to your own environment throughout. Providers who hold the keys make themselves difficult to leave, which is a commercial strategy rather than a technical necessity.
What is included
Service desk
A single channel for issues, with response and resolution targets stated in hours by priority and reported against monthly.
Monitoring and alerting
Availability and health monitoring on agreed systems, with alerts that are acted on rather than merely generated.
Patch management
Operating system and application patching on a defined cycle, with reporting on what is current and what is not.
Identity administration
Joiner, mover and leaver processing, access reviews, and multi-factor authentication coverage maintained.
Backup oversight
Backup success monitored and restores tested periodically, with the test results shared rather than filed.
Monthly reporting and review
Performance against targets, changes made, risks outstanding, and what we recommend next — written to be read by an owner.
How it is delivered
- Everything in your environment is inventoried before support begins. Supporting an estate nobody has documented means guessing, and guessing is what causes outages.
- Response targets are contractual and reported against every month, including the months we miss them.
- Anything outside the agreed scope is quoted before it is done. Scope creep that is absorbed silently ends either in a bad month for us or an unexpected invoice for you.
What you receive
- Documented environment: assets, architecture, and escalation contacts
- Signed service level agreement with stated response and resolution targets
- Security baseline report and signed risk register
- Tested restore evidence
- Monthly service report against targets
- Quarterly review of risks, spend and recommendations
What is not included
Stated plainly, because unstated exclusions are where disputes begin.
- Project work such as migrations and rollouts, which is quoted separately as a statement of work
- Hardware and licence purchases, which are billed to you at cost by the vendor
- On-site attendance outside greater Melbourne, unless separately agreed
- Support for systems excluded from the inventory at onboarding
Common questions
What are the response targets?
They are set in the service level agreement by priority, and they are the ones we can actually meet rather than the ones that win the tender. We would rather commit to four hours and meet it than commit to one and miss it.
Do you lock us in?
No. Tenancies, domains, licences and backups are held in your name and you retain administrative access throughout. If you leave, you already have everything and we will assist the transition.
What if our environment is in poor condition?
That is common and it is not a reason to refuse the work. It is assessed at onboarding, the gaps are quantified, and you decide what to remediate now, what to schedule, and what to accept. What we will not do is take on support while pretending the environment is sound.