Co-managed IT means your IT person stays and gets a team behind them. You keep the internal hire who knows your business, your people, and your applications, and you buy the parts that one person cannot cover: nights and weekends, the security stack, backup and disaster recovery, patching at scale, and senior planning. It is not a staged replacement, and we will put the division of labor in writing before you sign anything.
Los Angeles-based since 2007 · Channel Futures MSP 501 Ranked
Is this a polite way to replace our IT person?
No, and it is the first question almost every business asks, so it deserves a direct answer rather than reassurance.
Your internal IT person is usually the most valuable technical asset you have, because they know things no provider can learn from documentation: which application the accounting team refuses to give up, which partner never reboots, which vendor actually answers the phone. Losing that costs you more than the salary.
What they cannot do is be awake at 3 am, be a security specialist, a network engineer, and a cloud architect at the same time, and take a vacation. Co-managed IT buys those. If your goal is to reduce headcount, say so at the scoping call and we will scope a fully managed engagement instead. Do not buy co-managed as a quiet transition plan; it makes a bad handover worse, because nobody knows who owns what while it happens.
Who owns which tickets?
This is the part that decides whether a co-managed engagement works. The split below is our default starting point. It is written into the engagement and reviewed at every quarterly business review, not left to whoever picks up the phone.
| Work | Your IT person | Be Structured |
| Day-to-day desk-side support | Primary | Overflow and backup |
| Application knowledge and user training | Primary | Support on request |
| After-hours and weekend escalation | Optional, by agreement | Primary, on call |
| Monitoring, alerting and patching | Visibility | Primary, tooling included |
| Security stack and 24/7 SOC monitoring | Visibility | Primary |
| Backup, restore testing and disaster recovery | Visibility | Primary |
| Projects and migrations | Joint, by capacity | Joint, with a project manager |
| Vendor management and procurement | Joint | Joint |
| Roadmap, budget and compliance documentation | Input | Primary, through the vCIO |
| Coverage during PTO, illness and turnover | Not possible | Primary |
Every row is negotiable. A firm with a strong internal network engineer usually moves patching and projects to the left. A firm whose IT person is really an operations manager with technical instincts tends to move most rows to the right. What matters is that the row is assigned before an incident, not during one.
What happens when a ticket has to be escalated?
One queue, one ticket number, and a named path. Your IT person can hand a ticket to our engineers without having to re-explain it, because we are looking at the same monitoring data and the same documentation. There is no second service desk for your staff to learn.
Escalation criteria are agreed in advance, by severity, and so is the containment authority: what we are pre-authorized to do without calling anyone, such as isolating a host, disabling an account, or blocking an address. Monitoring anomalies generates a prioritized ticket within 60 seconds. Our Network Operations Center triages after-hours issues in about 10 minutes, and when an incident needs hands-on a device rather than a console, our team reaches most of the Los Angeles area in roughly 30 minutes.
The escalation that matters most is the one at 11 pm on a Friday, when your IT person is at dinner and should stay there.
Who gets access to which tools?
Both sides, deliberately. Your IT person keeps administrative rights in your own environment; we do not take them away as a condition of the engagement, and a provider who insists on that is buying leverage rather than delivering a service.
What we bring is our tooling: remote monitoring and management agents, the security stack, backup and recovery, and documentation. Your IT person gets a login to the monitoring and ticketing platforms, so they can see the same alerts and the same history we can. Documentation is written for your environment and handed over, so if you ever leave, you leave with a documented network rather than a mystery.
Ask any provider two questions here: does my internal person get read and write access to the tools you deploy, and what leaves with me if we part ways.
If your IT person quits
Nothing stops. That is most of the reason to do this.
Because monitoring, patching, security, backup, and documentation already sit with us, a resignation becomes a hiring problem rather than an outage. We can cover the desk-side gap while you recruit, and hand back to the new hire with documentation they can actually read. Firms that have been through this once rarely go back to a single unsupported internal hire.
The same applies to the smaller version of the problem: a two-week vacation, jury duty, or a bad flu during your busiest month.
What does a co-managed cost compare with a second hire?
The comparison is not co-managed against fully managed. It is co-managed against hiring a second IT person.
A second internal hire in Los Angeles costs a salary plus benefits, plus recruiting, plus onboarding time, and gives you one more person’s skill set with the same coverage ceiling: they also sleep. Co-managed pricing is scoped around the division of labor you agree on. Managed security stays per device, commonly $50 per device per month for the full stack, and the managed layer is scoped down from the fully managed rate of $125 to $300 per user per month, depending on which rows your internal team keeps. Project work outside the recurring scope is quoted in advance. Our managed IT services cost page has the full pricing model, including onboarding fees and contract terms.
Agreements generally run one to three years, with a discount on multi-year terms. Ask about the termination clause and what happens to your documentation on exit before a discount persuades you.
When co-managed is the wrong answer
Three cases, honestly:
- You have no internal IT at all. Then this is just managed IT with extra steps. Look at all-inclusive managed services instead.
- Your internal person does not want it. Co-managed fails when it is imposed. Bring them to the scoping call; the good ones usually ask better questions than the executives do.
- You want the headcount reduction. Then scope a fully managed engagement with a proper handover, and be straight with your team member about it.
How to evaluate a co-managed provider
- Ask for the division of labor in writing before you sign. A provider who will not commit to a row-by-row split will improvise during your first incident.
- Ask whether your internal person keeps admin rights. The answer should be yes.
- Ask what tooling access they get. Read-only dashboards are a warning sign.
- Ask about the escalation path and containment authority by severity. Get target response times in the service level agreement.
- Ask what happens during PTO and turnover. That is the scenario you are buying for.
- Ask what leaves with you. Documentation, log history, and licensing should not be hostage to a renewal.
- Ask them to talk to your IT person alone. How that conversation goes tells you more than the proposal does.
Co-managed IT in Los Angeles
Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA. Co-managed engagements draw on the same practice as our fully managed work: 24/7 support and monitoring, the managed security services stack, backup and data protection, disaster recovery and business continuity planning, and vCIO planning. If you are still weighing internal versus outsourced IT, our page on MSP versus in-house IT is the place to start, and outsourced IT support services cover the fully managed option.
➤ Get Your Free IT Assessment: contact Be Structured to scope a co-managed engagement, and bring your IT person to the call. Or call (323) 331-9452.
