A managed IT agreement is where sales promises either become commitments or disappear. Most owners read the price and the term, then skim the rest. The questions below focus on the clauses that decide what happens when something goes wrong.
What exactly is in scope?
Scope is where most disputes start. Ask for a written list of what the monthly fee covers. That list should address help desk support, onsite visits, patching, backups, security tools, vendor coordination, and new user setup.
Then ask for the exclusion list, which is often more revealing. Pay close attention to vague phrases like “reasonable use” or “standard support.” Ask the provider to define them with examples, because vague terms get interpreted by the party that wrote them.
Watch for documents outside the contract
Many agreements refer to separate schedules, policies, or online terms pages. Those documents are part of the deal, even if nobody attached them. In some cases, the provider can change them without asking you, so request copies and ask how changes are handled.
How are response and resolution defined?
Service level agreements often promise a response time. However, “response” may mean an automated email, not a technician. Ask what counts as a response, and whether the provider also tracks time to resolution.
Next, ask what happens if they miss the targets. An SLA with no consequence is a goal, not a commitment.
CISA’s Risk Considerations for Managed Service Provider Customers recommends specific performance-related SLAs. It also calls for incident management guidelines that address compensation for service outages.
Who is responsible for which security controls?
Many agreements say the provider “manages security” without defining it. Ask which controls they operate, which they only recommend, and which stay with you. For example, will they enforce multifactor authentication, or just advise it?
Also ask which framework they measure you against, such as the CIS Controls or the NIST Cybersecurity Framework. A named baseline turns “we handle security” into something you can check.
Finally, ask how the provider will report on those controls. A short quarterly summary of patch status, backup tests, and open risks tells you whether the work is actually happening.
This matters for cyber insurance, too. If your managed IT agreement does not match what you told your insurer, you may have a gap nobody notices until a claim.
Who owns the accounts, data, and documentation?
This question matters most on the day you leave. Admin credentials for Microsoft 365, domain registrations, firewall configurations, and software licenses should belong to your organization. Some providers register them in their own name, which makes switching painful.
The same goes for vendor relationships. If the provider buys licenses or hardware warranties on your behalf, the agreement should say whose name they sit under and how they transfer.
So ask for written confirmation that you own your data and documentation. The agreement should also say the provider will hand them over at the end without charging more than reasonable labor.
What happens when the agreement ends?
Every agreement ends eventually, and the exit terms show how a provider really thinks about you. Ask what transition help they provide, how long it lasts, and what it costs. Also ask how quickly they will hand over documentation, passwords, and admin access after you give notice.
Next, confirm what happens to your data held in their tools. Backups, ticket history, and monitoring records may live in systems the provider owns. The agreement should state how you get that data back and when the provider deletes its copies.
Limitation of liability
Most agreements cap what the provider owes if something goes wrong. That is normal, but you should know how the cap is calculated. Then ask what insurance the provider carries, since a cap means little if the provider cannot pay it.
How do price changes and projects work?
Ask how often the provider can raise rates, by how much, and with how much notice. Then ask how projects are quoted: fixed price, hourly, or a blend. Finally, find out who on your side approves work outside scope, so surprise invoices do not appear.
In my experience, most billing disputes trace back to one unanswered question here. Settling it before you sign is far easier than arguing about it later.
Also ask whether the monthly fee covers routine changes, such as adding a new hire or moving a printer. Small requests like these add up quickly when each one becomes a separate charge.
A managed IT agreement review checklist
Before anyone signs, walk through the full document with these steps. It takes a few hours and can save years of friction.
- Get the complete agreement, including every schedule, policy, and online terms page it references.
- Highlight every exclusion, and ask for a price on the ones you expect to need.
- Confirm SLA definitions and remedies in writing.
- List the security controls the provider will operate versus only recommend.
- Confirm that your organization owns admin accounts, domains, and licenses.
- Read the limitation of liability clause, and ask what insurance the provider carries.
- Check the termination, notice, and offboarding terms.
- Have your attorney review the final version before signing.
How WEBIT approaches this
Our agreements are month-to-month with 90 days’ written notice, and a 90-day money-back guarantee backs the start. Every client gets a named Client Success Manager and a dedicated Field Engineer. We also baseline every client to the CIS Controls, so security responsibilities are documented from onboarding.
We are glad to walk through our managed IT agreement line by line before you sign. Because we take no vendor commissions or kickbacks, our recommendations are not driven by what a vendor pays us. You can also read how our strategic IT services and pricing fit together.
Key takeaways
- Scope and exclusions cause more disputes than price.
- An SLA needs clear definitions and a consequence to mean anything.
- Get security responsibilities, and the baseline behind them, in writing.
- Your organization should own its accounts, domains, licenses, and documentation.
- Read every document the managed IT agreement references, not just the main contract.
Related from WEBIT: should I switch MSPs self-assessment, MSP vs. break-fix comparison, and managed IT pricing calculator.
Want a second set of eyes on an agreement before you sign? Talk to an owner.





