Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

WEBIT Learning Hub

Co-Managed IT: How Internal IT and an MSP Share the Load

Most internal IT teams are not failing. They are simply outnumbered by the work. Co-managed IT gives that team a partner for the load it cannot carry alone, but only if both sides agree on who owns what before the first ticket arrives.

What co-managed IT actually means

In a fully managed arrangement, the provider runs everything. In a co-managed arrangement, your internal staff keep real ownership, and the provider fills specific gaps. Those gaps might be tickets, projects, security monitoring, or after-hours coverage.

That means co-managed IT is not a product. Instead, it is a division of labor. The division is different at every organization, so the contract and the daily routine should reflect your team, not a template.

Also, it is not a polite first step toward replacing your IT staff. A good provider should make your people more effective, not nervous.

Why internal teams get stretched thin

A one or two person IT department at a 100-person company is doing several jobs at once. For example, they handle password resets, vendor calls, laptop setups, and the occasional server emergency. Then leadership asks for a new phone system or a security review.

As a result, strategic work slides. Patching gets done late, documentation goes stale, and the person who knows everything cannot take a real vacation.

In my experience running service delivery, the warning sign is not a missed ticket. Instead, it is when your IT lead stops saying no because there is no time to explain why.

Signs you are ready for co-managed IT

Not every internal team needs outside help. However, a few patterns suggest the time has come.

First, projects keep slipping to next quarter, then to next year. Second, your IT lead is the only person who can fix certain systems. Third, security alerts go unread overnight and on weekends.

Another sign is burnout. If your best technical person is quietly updating their resume, the cost of doing nothing is much higher than the cost of a partner. Losing that person also means losing years of undocumented knowledge.

Finally, look at growth plans. If you plan to add locations or staff, the workload will rise faster than your IT headcount. A co-managed arrangement lets you scale support without a long hiring cycle.

Common ways to split the work

There is no single right model. However, most arrangements land in one of three shapes, and many combine them.

Help desk overflow

The provider takes first-line tickets, so your internal staff can focus on systems and projects. Your team still handles escalations that need deep business knowledge, such as your line-of-business application.

Projects and specialty skills

Your team runs daily support, and the provider brings engineers for migrations, network redesigns, or cloud work. This model works well when you need a skill only a few times a year.

Security and after-hours monitoring

Many internal teams cannot watch alerts at 2 a.m. So the provider covers monitoring, endpoint protection, and incident response, while your staff own users and applications.

Most organizations start with one model and adjust over time. For example, a team might begin with security monitoring, then add help desk overflow once trust builds.

Where co-managed IT arrangements break down

The failure pattern is predictable.

First, a problem lands in a gray area between the two teams. Next, each side assumes the other is handling it. Finally, a user waits three days while two groups debate ownership.

Other common problems include:

  • Two sets of admin credentials, with no one sure which accounts are still active.
  • Changes made by one team that the other team never hears about.
  • Duplicate tools, such as two remote access agents on the same laptop.
  • A provider that treats internal staff as customers to be managed instead of peers.

To be candid, providers cause many of these problems. Some are simply built for fully managed clients and bolt on co-managed work as an afterthought.

Build a responsibility matrix before day one

The fix is boring, and it works. Write down every recurring task and assign an owner. Then review it together every quarter, because it will drift.

Use this checklist to build yours:

  1. List every system you run, from Microsoft 365 to the badge reader.
  2. For each system, name who handles tickets, changes, patching, and backups.
  3. Define the escalation path in both directions, including phone numbers.
  4. Agree on one ticketing system that both teams can see.
  5. Set a change notification rule, for example a same-day note for any production change.
  6. Decide who approves new software, new vendors, and admin access.
  7. Schedule a monthly working session and a quarterly review with leadership.

If you are still sizing the arrangement, our co-managed pricing calculator can help you frame the budget conversation.

Tools, access, and who holds the keys

Access is where shared responsibility gets real. Your organization should own the root accounts, the domain registrar, and the Microsoft 365 global admin credentials. The provider should get named accounts with only the rights it needs.

CISA makes the same point in its Risk Considerations for Managed Service Provider Customers. The guidance recommends defining roles with a shared responsibility model and granting minimum rights for the shortest necessary time.

Also, agree on a single documentation platform. If your team keeps notes in one place and the provider keeps them somewhere else, you have two partial truths instead of one complete one.

Next, standardize the tool stack. One remote access tool, one monitoring platform, and one endpoint protection product is the goal. Duplicate agents slow devices down, and they also create more places for an attacker to hide.

Finally, plan for the day the arrangement ends. Your team should be able to remove the provider’s access in an afternoon, without breaking anything. If that sounds hard, the access model needs work now.

How WEBIT approaches this

We treat internal IT staff as colleagues. Every co-managed client gets a named Client Success Manager and a dedicated Field Engineer, so your team always knows who to call. We also use our Assess, Align, Automate, Advance process to map responsibilities during a 30-day onboarding.

Security Essentials runs on every managed device, and we baseline each client to the CIS Controls. Agreements are month-to-month with 90 days’ written notice, so the arrangement has to keep earning its place. You can see how the model works on our managed IT services page.

Key takeaways

  • Co-managed IT is a division of labor, so design it around your team.
  • Most failures come from gray areas, not from bad technicians.
  • A written responsibility matrix prevents finger-pointing.
  • Your organization should always own the master credentials.
  • Review the split every quarter, because needs change.

Wondering whether your internal team needs a partner or just a plan? Talk to an owner.

Talk to an owner

Want help applying this to your business? A 30-minute discovery call gets you honest advice.

Schedule a discovery call

Industry whitepapers

In-depth guides for 13 industries, from medical to manufacturing.

Browse whitepapers →

Estimate your IT cost

Real per-unit pricing, updated as you go.

Open the calculator →

Keep reading

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.