The short answer
Fully managed IT means one provider takes responsibility for monitoring, supporting, maintaining and securing your systems and users. It fits organizations with no internal IT staff, or one person who is overloaded and not an IT specialist.
Co-managed IT means your internal IT person or team stays in charge, and a provider works as an extension of that team: monitoring, patching, routine tasks, after-hours cover, specialist escalation and projects. It fits organizations that value in-house knowledge but lack capacity or depth.
Both can work well. Both fail when nobody writes down who owns what.
Side by side
| Fully managed | Co-managed | |
|---|---|---|
| Who leads day to day | The provider | Your internal IT lead |
| Users call | The provider's help desk | Usually your IT team first, with the provider behind them |
| Tools (monitoring, patching, ticketing) | Provider's | Shared, or provider's with access for your team |
| After-hours cover | Provider, for managed-service clients under the agreement | Provider, for agreed systems and alerts |
| Strategy and budget | Provider's vCIO with your leadership | Your IT lead, supported by the provider's vCIO |
| Best when | No IT staff, or IT is a side job for someone | One or more IT staff who need backup |
| Main risk | Losing internal knowledge of how the business works | Unclear boundaries between two teams |
How to decide
Ask four questions:
- Do you have someone whose actual job is IT? If not, fully managed is usually simpler and safer.
- Do you want to keep that knowledge in-house? Organizations with specialist systems (clinical software, manufacturing controls, custom databases) often benefit from an insider who knows them deeply.
- What is falling through the cracks today? If it is after-hours cover, patching and security monitoring, co-managed fills exactly those gaps. If it is everything, fully managed is the honest answer.
- Will your internal team share access and agree a process? Co-managed IT only works if both sides use one ticket system, one set of documentation and named accounts.
The responsibility matrix
A co-managed agreement stands or falls on a clear split. Here is a starting point you can adapt:
| Task | Your IT team | Provider | Shared |
|---|---|---|---|
| First-line user support during business hours | Yes | ||
| After-hours alerts and triage | Yes | ||
| Operating system and third-party patching | Yes | ||
| Line-of-business application support | Yes | ||
| New user setup and offboarding | Yes | ||
| Firewall and network changes | Yes (approval by your IT lead) | ||
| Backup monitoring and restore testing | Yes | ||
| Security alert investigation | Yes | ||
| Vendor relationships for core business systems | Yes | ||
| Roadmap and budget | Yes (owner) | vCIO support |
The exact rows matter less than the fact that every row has an owner.
A regional distributor with two internal IT staff chooses co-managed IT. The internal team keeps the warehouse scanners, the ERP and user support. The provider takes 24/7 monitoring, patching, backup testing, endpoint security alerts and a Windows server upgrade the team never had time for. A monthly review between the IT lead and the provider's vCIO keeps the list current.
What usually goes wrong
Two sources of truth. Tickets in one system, documentation in another, passwords in a spreadsheet. Pick one ticketing system and one documentation platform and agree that anything not recorded there did not happen.
Shared administrator logins. If everyone uses the same admin account, you cannot tell who changed what. The Canadian Centre for Cyber Security recommends that individuals have only the privileges they need, and that service providers have only the access required to manage their services (Cyber Centre ITSM.50.030). Give provider staff named, least-privilege accounts with multi-factor authentication.
Changes made around the process. An internal change made on a Friday evening without telling the provider becomes a 2 a.m. alert. Use an agreed change process, even a light one.
The internal team feels displaced. Involve your IT staff in choosing the provider and writing the matrix. Co-managed IT should make their job more manageable and more interesting.
Fully managed without a business contact. Even in a fully managed model, someone on your side must approve changes, purchases and priorities. Name that person.
Rather talk it through? We can run a short responsibility-mapping session with your IT lead and show which model closes your gaps. Talk to a Promatics specialist
Switching between models later
The models are not permanent. A common path is co-managed while an internal IT person is in place, then fully managed if they leave, or the reverse when an organization grows enough to hire internally. Keep documentation, credentials and domain registrations in your organization's name so either move is straightforward.
When to bring in help
If you have a stable internal team, documented systems, a tested backup and holiday cover, you may not need either model yet. Bring in a provider when your IT staff cannot take leave without risk, when patching and security monitoring are behind, or when projects wait months for time. If you have no internal IT at all, look at managed IT services.
How Promatics approaches co-managed IT
We start with a responsibility-mapping workshop with your IT lead, then onboard tools and access using separate named accounts so every action is traceable. Your team keeps what it knows best; we take monitoring, patching, repetitive tasks, after-hours cover and escalation. Regular reviews with your IT lead and our vCIO keep the split honest as things change. Our co-managed IT page sets out the full scope.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Cyber security considerations for consumers of managed services (ITSM.50.030), Canadian Centre for Cyber Security
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.