Article

Fully managed vs co-managed IT: which model fits your team?

Fully managed IT suits organizations without internal IT staff; co-managed IT suits organizations with an IT person or team who need capacity, cover and specialist skills. The deciding factor is who you want owning day-to-day decisions, and whether you can write that split down.

The short answer

Fully managed IT means one provider takes responsibility for monitoring, supporting, maintaining and securing your systems and users. It fits organizations with no internal IT staff, or one person who is overloaded and not an IT specialist.

Co-managed IT means your internal IT person or team stays in charge, and a provider works as an extension of that team: monitoring, patching, routine tasks, after-hours cover, specialist escalation and projects. It fits organizations that value in-house knowledge but lack capacity or depth.

Both can work well. Both fail when nobody writes down who owns what.

Side by side

Fully managedCo-managed
Who leads day to dayThe providerYour internal IT lead
Users callThe provider's help deskUsually your IT team first, with the provider behind them
Tools (monitoring, patching, ticketing)Provider'sShared, or provider's with access for your team
After-hours coverProvider, for managed-service clients under the agreementProvider, for agreed systems and alerts
Strategy and budgetProvider's vCIO with your leadershipYour IT lead, supported by the provider's vCIO
Best whenNo IT staff, or IT is a side job for someoneOne or more IT staff who need backup
Main riskLosing internal knowledge of how the business worksUnclear boundaries between two teams

How to decide

Ask four questions:

  1. Do you have someone whose actual job is IT? If not, fully managed is usually simpler and safer.
  2. Do you want to keep that knowledge in-house? Organizations with specialist systems (clinical software, manufacturing controls, custom databases) often benefit from an insider who knows them deeply.
  3. What is falling through the cracks today? If it is after-hours cover, patching and security monitoring, co-managed fills exactly those gaps. If it is everything, fully managed is the honest answer.
  4. Will your internal team share access and agree a process? Co-managed IT only works if both sides use one ticket system, one set of documentation and named accounts.

The responsibility matrix

A co-managed agreement stands or falls on a clear split. Here is a starting point you can adapt:

TaskYour IT teamProviderShared
First-line user support during business hoursYes
After-hours alerts and triageYes
Operating system and third-party patchingYes
Line-of-business application supportYes
New user setup and offboardingYes
Firewall and network changesYes (approval by your IT lead)
Backup monitoring and restore testingYes
Security alert investigationYes
Vendor relationships for core business systemsYes
Roadmap and budgetYes (owner)vCIO support

The exact rows matter less than the fact that every row has an owner.

Demonstration, not a client project

A regional distributor with two internal IT staff chooses co-managed IT. The internal team keeps the warehouse scanners, the ERP and user support. The provider takes 24/7 monitoring, patching, backup testing, endpoint security alerts and a Windows server upgrade the team never had time for. A monthly review between the IT lead and the provider's vCIO keeps the list current.

What usually goes wrong

Two sources of truth. Tickets in one system, documentation in another, passwords in a spreadsheet. Pick one ticketing system and one documentation platform and agree that anything not recorded there did not happen.

Shared administrator logins. If everyone uses the same admin account, you cannot tell who changed what. The Canadian Centre for Cyber Security recommends that individuals have only the privileges they need, and that service providers have only the access required to manage their services (Cyber Centre ITSM.50.030). Give provider staff named, least-privilege accounts with multi-factor authentication.

Changes made around the process. An internal change made on a Friday evening without telling the provider becomes a 2 a.m. alert. Use an agreed change process, even a light one.

The internal team feels displaced. Involve your IT staff in choosing the provider and writing the matrix. Co-managed IT should make their job more manageable and more interesting.

Fully managed without a business contact. Even in a fully managed model, someone on your side must approve changes, purchases and priorities. Name that person.

Rather talk it through? We can run a short responsibility-mapping session with your IT lead and show which model closes your gaps. Talk to a Promatics specialist

Switching between models later

The models are not permanent. A common path is co-managed while an internal IT person is in place, then fully managed if they leave, or the reverse when an organization grows enough to hire internally. Keep documentation, credentials and domain registrations in your organization's name so either move is straightforward.

When to bring in help

If you have a stable internal team, documented systems, a tested backup and holiday cover, you may not need either model yet. Bring in a provider when your IT staff cannot take leave without risk, when patching and security monitoring are behind, or when projects wait months for time. If you have no internal IT at all, look at managed IT services.

How Promatics approaches co-managed IT

We start with a responsibility-mapping workshop with your IT lead, then onboard tools and access using separate named accounts so every action is traceable. Your team keeps what it knows best; we take monitoring, patching, repetitive tasks, after-hours cover and escalation. Regular reviews with your IT lead and our vCIO keep the split honest as things change. Our co-managed IT page sets out the full scope.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Cyber security considerations for consumers of managed services (ITSM.50.030), Canadian Centre for Cyber Security

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Find the support model that fits the team you have

Choosing between models is easier with someone who has seen both work. We will map who should own what and show you where the gaps are.

  • A written responsibility matrix, not vague promises
  • Your IT staff keep control of what they know best
  • After-hours cover and specialist escalation included