What co-managed IT actually is (and what it is not)
Co-managed IT is a shared-responsibility model where your internal IT person or team stays in place, and a managed service provider (MSP) fills defined gaps: overflow tickets, after-hours coverage, escalations, specialized engineering, and the tools that make proactive operations possible. Think of it as expanding your IT department without expanding your payroll. Co-managed IT is not a vague “we help when you need us” arrangement. The whole value comes from clarity: who owns what, how issues are routed, what response times look like, and how decisions are made. It also is not a downgrade to your internal staff. In a healthy co-managed setup, your internal IT lead becomes more strategic because they can finally get out of reactive work and into planning, standardization, and business alignment.When Orlando SMBs should consider co-managed IT
Co-managed is usually a fit when you already have some internal IT capability, but the business has outgrown what that small team can cover. In real life, the triggers often look like this:- Coverage gaps: projects stall when the IT lead is buried in tickets, and vacations feel impossible because there is no backup.
- Security depth is thin: you can do the basics, but you do not have time for hardening, log review, identity governance, or consistent remediation.
- Too many vendors: internet, phones, SaaS apps, security tools, printers, and line-of-business systems are all “someone else’s problem,” but you are the one stuck coordinating.
- Growth without standardization: onboarding is manual, device setups vary, and support requests bounce around because there is no consistent workflow.
Define the division of labor with a simple RACI
Co-managed IT works when the division of labor is written down. The easiest way to do that is a lightweight RACI (Responsible, Accountable, Consulted, Informed) for your most important operational categories. Start with six buckets that cover most environments:- Service desk intake and triage (where tickets come in, who routes them, and what gets escalated)
- Microsoft 365 and identity (Entra ID, MFA, conditional access, email security, admin changes)
- Endpoint management (Intune policies, patching, EDR alerts, device lifecycle)
- Network and infrastructure (firewalls, Wi‑Fi, switches, backups, monitoring)
- Projects and change management (who plans, who executes, and how downtime risk is controlled)
- Vendors and procurement (quoting, renewals, asset tracking, warranty coordination)
Adopt “lightweight ITSM” so operations scale without bureaucracy
Many SMBs hear “IT service management” and imagine enterprise red tape. In practice, a lightweight ITSM approach is exactly how you keep co-managed relationships clean. It prevents finger-pointing because it turns “who should do this?” into a defined workflow. You do not need a giant toolset to get value. You need three things:- One intake path: a single way to request help (portal, email-to-ticket, or Teams channel that creates tickets).
- Three ticket types: incidents (something broke), requests (standard asks like new user setup), and changes (anything that could create downtime).
- A small set of KPIs: first response time, time to resolution, backlog, and user satisfaction.
Pick the right success metrics (not vanity metrics)
Co-managed IT should make the business feel calmer and more predictable. To know whether it is working, avoid metrics that look good but do not change outcomes. Instead, track a few operational indicators that connect directly to business impact:- Ticket backlog trend: is the queue shrinking or growing month over month?
- Repeat-issue rate: are the same problems showing up every week (a sign of missing root-cause work)?
- Patch and configuration compliance: what percentage of devices are actually current and aligned to policy?
- After-hours incident frequency: are you reducing emergencies, or just responding faster?
A 30-day co-managed IT kickoff plan
The first month sets the tone. A practical kickoff is not about rewriting everything. It is about establishing control points and making sure both teams can operate together. Week 1: Discovery and access- Confirm admin access, documentation, and an inventory baseline.
- Define the intake path and ticket routing rules.
- Agree on the RACI for the six buckets above.
- Stand up monitoring, backup verification, and endpoint visibility.
- Baseline identity settings (MFA coverage, privileged access, alerting).
- Identify the top recurring issues and decide which will be eliminated first.
- Publish a simple onboarding/offboarding checklist.
- Standardize device setup and patch policies.
- Create a small service catalog of “standard requests” with clear turnaround times.
- Build a 90-day roadmap: quick wins, security hygiene, and one or two business projects.
- Set a monthly operations review that includes KPIs and risk items.
- Confirm escalation paths and after-hours procedures.
Common pitfalls (and how to avoid them)
Co-managed IT fails when the scope is ambiguous. The most common pitfalls are predictable:- Duplicate work: both teams patch devices, both teams manage M365 settings, and no one knows which configuration is current.
- Unclear accountability: the MSP is “responsible” but your internal team is still “accountable,” or vice versa, which slows decisions.
- No documentation discipline: passwords, diagrams, and procedures live in someone’s head instead of a shared system.
- Tool sprawl: too many overlapping tools with unclear ownership creates noise and cost.