Co-managed IT services means an outside provider and the person or people who handle IT inside your business share the work under a written split. If someone already looks after IT but is stretched, is the only one who knows your systems, or can’t cover every area, that arrangement can fit. It may fit less well when nobody owns IT inside the business, or when you want one party accountable for all of it. Either way, the split is what makes sharing work: who does what, who holds which access, and who answers when something breaks.
The consequence is worth naming. When IT rests on one person, support and upkeep can stall while that person is away or overloaded, and work nobody owns may simply go undone. Handing tasks to an outside team without a written split can leave some of them falling between the two sides. So put the split on paper.
What does co-managed IT mean in practice?
It means your business keeps someone handling IT inside and brings in an outside provider to cover part of the work. The two sides divide tasks, access and responsibility. A written agreement sets the line. Arrangements differ by provider and by business, so the words only mean what your agreement says.
How it differs from fully managed IT
In a fully managed arrangement, an outside provider takes the day-to-day IT work. Where the work is shared, the person inside stays and the provider covers some of it. Labels matter less than detail. Two providers can use the same term and mean different things, so read what’s written rather than the name on the proposal.
How it differs from hiring another person
Hiring is a third route. It means one more role to find and manage, with the same questions about who covers which area and who steps in during an absence. If that choice is still open for you, hiring in-house versus outsourcing works through it separately. This article starts after that decision, with a person who stays.
Which signs point toward co-managed IT?
Look at where IT work waits. Signs can include one person carrying every area with nobody covering their absence, upkeep that sits behind the day’s requests, and projects that keep slipping. Another sign: the person inside asks for help in an area they don’t cover. None of these settles the decision on its own.
- One person covers every area, and nobody picks it up while they’re out.
- Monitoring, backup checks or security upkeep wait behind daily requests.
- A project keeps slipping because nobody has an uninterrupted stretch for it.
- A problem outside working hours waits until the person is back.
- The person inside asks for help in an area they don’t cover.
- The “IT person” is an office manager who handles IT alongside another job.
Sharing may not suit every business. If nobody owns IT inside, a fully managed arrangement may be simpler to run, because there’s no internal line to draw. If the person inside and a provider can’t agree on who holds administrator access, that question is worth settling before anything else. And if you want a single party accountable for everything, a split works against that.
Who does what when the work is shared?
There’s no standard division. As a general rule, the person inside keeps work that depends on knowing your business, and an outside team can take on work that needs breadth or coverage. You choose the line, write it down, and keep the final say on priorities. The agreement decides it, not the labels.
What the person inside might keep
Some work is hard to hand to anyone who doesn’t sit in the building. A business might keep these inside:
- How the office runs day to day, including the quirks nobody wrote down.
- The line-of-business software your team lives in.
- The people, and who needs what to do their job.
- The physical building and hands-on help at the desk.
- The final say on what gets worked on first.
What an outside team could take on
The other side of the line might be work that needs breadth or hours one person can’t supply: coverage outside working hours, monitoring, backups and the checks that prove they ran, routine upkeep, a documented request queue, specialist areas, project work and longer-range planning. Which of those you hand over is your choice, not a given.
O&O Systems’ Managed IT and Help Desk page says its team is available around the clock for technical issues and that issues are logged, tracked and resolved, with reports on issue trends, resolution times and system health. That describes what the page says that service includes. How any outside team and a person inside divide the work is something the business and the provider agree in writing. And no provider can promise nothing will go wrong.
Where the gap is planning rather than daily work, O&O Systems’ virtual CIO page describes executive-level IT leadership, with O&O working as a trusted advisor on technology decisions.
How do you put the split in writing?
Write a short document that lists tasks and names one owner for each. Say who holds which access, how a request reaches the outside team, and what happens when either side is unreachable. Name who approves a change. Say where the shared notes live. Keep it short enough that both sides read it.
A workable version can cover:
- Every task with one named owner: inside, outside or shared, plus who backs that owner up.
- Who holds administrator access to what, and confirmation that the business itself can reach it, not only one person or one provider.
- How a request reaches the outside team, and who the first contact is on each side.
- What happens while the person inside is away, and what happens if the provider can’t be reached.
- Who approves a change before it’s made.
- Where the shared notes and documentation live, and who may read them.
- How security incidents get reported, and by whom.
On that last line, the FTC’s business guidance on protecting personal information speaks to working with service providers. It says to put your security expectations in writing in contracts with service providers. It also advises looking into a company’s data security practices before you outsource a business function, verifying compliance instead of taking their word for it, and insisting that service providers notify you of any security incidents they experience. That’s general guidance for businesses that handle personal information and outsource functions. It isn’t a statement of any law or of any contract term, and the written split stays your own document.
What should you ask an outside provider before you agree?
Ask how they’d work with the person you already have, and which tasks they’d take on while others stay inside. Ask who answers outside working hours. Ask who holds administrator access and how you’d get it back. Then ask for the answers in writing, because a conversation isn’t an agreement.
- How would you work with the person who handles IT here?
- Which tasks would you take on, and which would stay with us?
- Who answers a problem outside working hours?
- How does a request get logged, and who can see it?
- What reports would we receive, and what do they show?
- Who holds administrator access, and how would we get it back?
- What documentation do you share with us?
- How would a disagreement between your team and ours get settled?
- How does this arrangement change or end?
None of those questions assumes an answer, which is the point of asking them. Record what you hear beside the tasks it covers, and keep the recorded version with the split.
How do you keep two teams from pointing at each other?
Give both sides one list. A shared request queue means the same open items are visible to everyone, so less depends on who remembers it. Name one contact on each side. Review the written split and the open tasks on a regular rhythm. Shared notes that both sides update help with the rest.
If request handling is informal right now, what a working support system looks like covers that ground separately. Keep the person inside in every decision about their own area, since they’ll be living with it. And when that person leaves or you change providers, update the written split, then the access list and the named contacts.
Frequently Asked Questions About Co-Managed IT
Is co-managed IT the same thing as fully managed IT?
No. In a fully managed arrangement, an outside provider takes the day-to-day work. Where the work is shared, your own person stays and the provider covers part of it. Providers use these terms differently, though, so the written agreement is what tells you which one you’re buying.
Will an outside provider replace our IT person?
Not by default. A shared arrangement is built around keeping that person, and a business might add outside help so the areas nobody can reach get covered. What happens to the role is your decision. It belongs in the written split before the work starts, rather than being left to work itself out.
Can an office manager who handles IT be our internal contact?
That can work. Someone who covers IT alongside another job may be the right internal contact, as long as the split is honest about the hours and the areas they can’t cover. Name a backup as well, so a request doesn’t stall while they’re busy with their other work.
Who is responsible when something breaks?
Day to day, whoever the written split names as the owner of that task. The split decides who acts first, not who is liable. Liability depends on your agreements and the rules that apply to you, which is a question for your own attorney or other advisers. No label settles ownership. That’s why the document should name an owner and a backup for each task, plus who the first contact is on each side, before anything breaks.
Does co-managed IT make a business compliant?
No arrangement and no provider can promise compliance, and nothing here is legal or compliance advice. What a business must do can depend on factors such as its industry, the data it holds and its own agreements, which is a question for its own attorney or other advisers. Sharing IT work changes who does which task; it does not remove what applies to you.
How do we change or end the arrangement?
Through the terms you agreed to, which is why they belong in writing from the start. Before you sign, ask how work moves back inside or to someone else, who returns administrator access, and what documentation you keep. Knowing the exit terms early keeps the arrangement adjustable later.
Want to talk through where outside IT support could sit beside your team?
If you already have someone handling IT and you’re weighing outside support beside them, you can contact O&O Systems to talk through what you need. It helps to have two lists ready: what’s covered inside now, and what keeps waiting.