Co-managed IT means your IT person stays and gets a team behind them. You keep the internal hire who knows your business, your people, and your applications, and you buy the parts that one person cannot cover: nights and weekends, the security stack, backup and disaster recovery, patching at scale, and senior planning. It is not a staged replacement, and we will put the division of labor in writing before you sign anything.

Los Angeles-based since 2007 · Channel Futures MSP 501 Ranked

Is this a polite way to replace our IT person?

No, and it is the first question almost every business asks, so it deserves a direct answer rather than reassurance.

Your internal IT person is usually the most valuable technical asset you have, because they know things no provider can learn from documentation: which application the accounting team refuses to give up, which partner never reboots, which vendor actually answers the phone. Losing that costs you more than the salary.

What they cannot do is be awake at 3 am, be a security specialist, a network engineer, and a cloud architect at the same time, and take a vacation. Co-managed IT buys those. If your goal is to reduce headcount, say so at the scoping call and we will scope a fully managed engagement instead. Do not buy co-managed as a quiet transition plan; it makes a bad handover worse, because nobody knows who owns what while it happens.

Who owns which tickets?

This is the part that decides whether a co-managed engagement works. The split below is our default starting point. It is written into the engagement and reviewed at every quarterly business review, not left to whoever picks up the phone.

Work Your IT person Be Structured
Day-to-day desk-side support Primary Overflow and backup
Application knowledge and user training Primary Support on request
After-hours and weekend escalation Optional, by agreement Primary, on call
Monitoring, alerting and patching Visibility Primary, tooling included
Security stack and 24/7 SOC monitoring Visibility Primary
Backup, restore testing and disaster recovery Visibility Primary
Projects and migrations Joint, by capacity Joint, with a project manager
Vendor management and procurement Joint Joint
Roadmap, budget and compliance documentation Input Primary, through the vCIO
Coverage during PTO, illness and turnover Not possible Primary

Every row is negotiable. A firm with a strong internal network engineer usually moves patching and projects to the left. A firm whose IT person is really an operations manager with technical instincts tends to move most rows to the right. What matters is that the row is assigned before an incident, not during one.

What happens when a ticket has to be escalated?

One queue, one ticket number, and a named path. Your IT person can hand a ticket to our engineers without having to re-explain it, because we are looking at the same monitoring data and the same documentation. There is no second service desk for your staff to learn.

Escalation criteria are agreed in advance, by severity, and so is the containment authority: what we are pre-authorized to do without calling anyone, such as isolating a host, disabling an account, or blocking an address. Monitoring anomalies generates a prioritized ticket within 60 seconds. Our Network Operations Center triages after-hours issues in about 10 minutes, and when an incident needs hands-on a device rather than a console, our team reaches most of the Los Angeles area in roughly 30 minutes.

The escalation that matters most is the one at 11 pm on a Friday, when your IT person is at dinner and should stay there.

Who gets access to which tools?

Both sides, deliberately. Your IT person keeps administrative rights in your own environment; we do not take them away as a condition of the engagement, and a provider who insists on that is buying leverage rather than delivering a service.

What we bring is our tooling: remote monitoring and management agents, the security stack, backup and recovery, and documentation. Your IT person gets a login to the monitoring and ticketing platforms, so they can see the same alerts and the same history we can. Documentation is written for your environment and handed over, so if you ever leave, you leave with a documented network rather than a mystery.

Ask any provider two questions here: does my internal person get read and write access to the tools you deploy, and what leaves with me if we part ways.

If your IT person quits

Nothing stops. That is most of the reason to do this.

Because monitoring, patching, security, backup, and documentation already sit with us, a resignation becomes a hiring problem rather than an outage. We can cover the desk-side gap while you recruit, and hand back to the new hire with documentation they can actually read. Firms that have been through this once rarely go back to a single unsupported internal hire.

The same applies to the smaller version of the problem: a two-week vacation, jury duty, or a bad flu during your busiest month.

What does a co-managed cost compare with a second hire?

The comparison is not co-managed against fully managed. It is co-managed against hiring a second IT person.

A second internal hire in Los Angeles costs a salary plus benefits, plus recruiting, plus onboarding time, and gives you one more person’s skill set with the same coverage ceiling: they also sleep. Co-managed pricing is scoped around the division of labor you agree on. Managed security stays per device, commonly $50 per device per month for the full stack, and the managed layer is scoped down from the fully managed rate of $125 to $300 per user per month, depending on which rows your internal team keeps. Project work outside the recurring scope is quoted in advance. Our managed IT services cost page has the full pricing model, including onboarding fees and contract terms.

Agreements generally run one to three years, with a discount on multi-year terms. Ask about the termination clause and what happens to your documentation on exit before a discount persuades you.

When co-managed is the wrong answer

Three cases, honestly:

  • You have no internal IT at all. Then this is just managed IT with extra steps. Look at all-inclusive managed services instead.
  • Your internal person does not want it. Co-managed fails when it is imposed. Bring them to the scoping call; the good ones usually ask better questions than the executives do.
  • You want the headcount reduction. Then scope a fully managed engagement with a proper handover, and be straight with your team member about it.

How to evaluate a co-managed provider

  1. Ask for the division of labor in writing before you sign. A provider who will not commit to a row-by-row split will improvise during your first incident.
  2. Ask whether your internal person keeps admin rights. The answer should be yes.
  3. Ask what tooling access they get. Read-only dashboards are a warning sign.
  4. Ask about the escalation path and containment authority by severity. Get target response times in the service level agreement.
  5. Ask what happens during PTO and turnover. That is the scenario you are buying for.
  6. Ask what leaves with you. Documentation, log history, and licensing should not be hostage to a renewal.
  7. Ask them to talk to your IT person alone. How that conversation goes tells you more than the proposal does.

Co-managed IT in Los Angeles

Be Structured has supported Los Angeles businesses since 2007 from 500 S. Grand Avenue, 22nd Floor, in Downtown LA. Co-managed engagements draw on the same practice as our fully managed work: 24/7 support and monitoring, the managed security services stack, backup and data protection, disaster recovery and business continuity planning, and vCIO planning. If you are still weighing internal versus outsourced IT, our page on MSP versus in-house IT is the place to start, and outsourced IT support services cover the fully managed option.

➤ Get Your Free IT Assessment: contact Be Structured to scope a co-managed engagement, and bring your IT person to the call. Or call (323) 331-9452.

Frequently Asked Questions About Co-Managed IT

What is co-managed IT?

Co-managed IT is an arrangement where your internal IT person or team stays in place and a provider covers the parts one person cannot: after-hours and weekend escalation, the security stack, backup and disaster recovery, monitoring and patching at scale, and senior planning. The division of labor is written into the engagement row by row, not left to whoever picks up the phone.

Are you going to replace our IT person?

No. Your internal person knows things a provider cannot learn from documentation, and losing that costs more than the salary. What they cannot do is be awake at 3 am, be a security specialist and a network engineer at the same time, and take a vacation. If your actual goal is to reduce headcount, say so at the scoping call, and we will scope a fully managed engagement with a proper handover instead. Co-managing is used as a quiet transition plan, making a bad handover worse.

Who handles which tickets?

Our default split gives day-to-day desk-side support, application knowledge, and user training to your IT person, and gives after-hours escalation, monitoring, and patching, the security stack, backup and disaster recovery, and roadmap and compliance documentation to us. Projects, vendor management, and procurement are joint. Every row is negotiable, and the split is reviewed at each quarterly business review. What matters is that the row is assigned before an incident, not during one.

Does our IT person lose administrative access?

No. Your internal person retains administrative rights within your environment and gets a login to the monitoring and ticketing platforms, so they see the same alerts and history we do. A provider who requires you to give up admin rights as a condition of the engagement is buying leverage rather than delivering a service. Ask any provider whether your internal person gets read and write access to the tools they deploy.

What happens when a ticket needs to be escalated to you?

One queue and one ticket number. Your IT person hands the ticket over without re-explaining it, because we are looking at the same monitoring data and the same documentation, and your staff never learns a second service desk. Escalation criteria and containment authority are agreed in advance by severity. Monitoring generates a prioritized ticket within 60 seconds of an anomaly, after-hours issues are triaged in about 10 minutes, and when hands are needed on a device, we reach most of the Los Angeles area in roughly 30 minutes.

What if our IT person quits?

Nothing stops, which is most of the reason to do this. Monitoring, patching, security, backup, and documentation already sit with us, so a resignation becomes a hiring problem rather than an outage. We can cover the desk-side gap while you recruit and hand back to the new hire with documentation they can read. The same protection applies to a two-week vacation, jury duty, or a bad flu during your busiest month.

How much does co-managed IT cost compared with hiring a second IT person?

The comparison that matters is co-managed against a second hire, not against fully managed. A second internal hire in Los Angeles costs salary, benefits, and recruiting and onboarding, and gives you one more person’s skill set with the same coverage ceiling. Co-managed pricing is scoped around the division of labor you agree on: managed security stays per device, commonly $50 per device per month for the full stack, and the managed layer is scoped down from the fully managed rate of $125 to $300 per user per month, depending on which rows your team keeps.

What should we ask a co-managed provider before signing?

Get the division of labor in writing, row by row, before you sign. Confirm that your internal person retains admin rights and has write access to the deployed tooling. Get the escalation path, containment authority, and target response times by severity into the service level agreement. Ask what happens during PTO and turnover, since that is the scenario you are buying for. Ask what leaves with you on exit: documentation, log history, and licensing. And ask them to talk to your IT person alone, because how that conversation goes tells you more than the proposal does.