An internal IT staff member and an outside technician working together at an open network rack
Articles

Co-Managed IT Services: How the Split Actually Works

If you have an IT team and a provider keeps calling, you already know the subtext. Somewhere in the proposal is a slide about efficiency, and you can see where it goes.

So here is the part most co-managed content skips: the mechanics. Not whether your team is valued — of course a vendor will say that — but who holds the domain admin credentials, who owns the ticket queue, who gets called at 2am, and who decides when a change goes in. Those answers are checkable. Reassurance isn't.

What co-managed actually means

Co-managed IT is a division of labor between your internal staff and an outside provider, where you keep the work that requires knowing your business and they take the work that scales badly for a small team.

It differs from the two things it gets confused with:

Fully outsourced means the provider owns the environment end to end. That's the right answer when there's no internal IT, and the wrong one when there is — you'd be paying someone to re-learn what your people already know.

Staff augmentation means renting a body. You direct the work, you carry the management overhead, and you get a person rather than a system. Co-managed is buying a function with tooling, escalation paths, and after-hours coverage behind it, not a contractor.

For what managed IT covers in general — the model, what's included, what isn't — start with the full guide. This article assumes you already know that and is about the split.

The arithmetic that actually justifies it

Forget talent shortages. The honest case for co-managed is a coverage calculation you can run on your own org chart.

Round-the-clock coverage means 168 hours a week, or roughly 8,700 a year. A full-time person, after vacation, holidays, sick time and training, delivers somewhere in the range of 1,750 to 1,800 working hours annually. Continuous coverage — someone awake, reachable, and competent at 3am on a Sunday in February — therefore takes close to five full-time people before you've hired a single specialist.

A three-person team can cover a business day well. It cannot cover 168 hours, and pretending otherwise just means the coverage is actually one person's cell phone.

For a plant running second shift, a distribution center working through peak, or a food processing operation with sanitation running overnight, that gap isn't theoretical. It's the hours when something breaks and nobody is staffed to answer.

Manufacturing floor at night, mostly dark, with one production line running under work lights

The second half of the arithmetic is specialization, and it's a price problem rather than an availability one. Per the Bureau of Labor Statistics, information security analysts carried a 2025 median wage of $129,180 — and demand is rising, which keeps that number moving in one direction.

A three-person IT team is not adding a $129,000 salary for a function it needs intermittently, and shouldn't have to. Co-managed buys fractional access to a skill you need occasionally and can't justify permanently. The same logic applies to anyone who can run a wireless survey properly or terminate a cable run to spec.

That's the whole argument: hours you can't staff, and skills you can't justify full-time. It doesn't require anyone to be underperforming.

Who does what

The specifics vary, but a workable split looks like this:

Your team keeps:

  • Business applications — the ERP, the MES, the WMS, and everything wired into them
  • User and departmental relationships, and knowing whose request is actually urgent
  • Vendor management for line-of-business systems
  • Project decisions and priorities
  • Institutional knowledge: why that server exists, which machine can't reboot mid-run, what happened last time
  • Final say on changes to production systems

The provider takes:

Shared, with your team leading:

  • Architecture and roadmap
  • Budget planning and lifecycle forecasting
  • Incident response, with defined roles agreed before an incident

The test of whether a split is real: your IT manager should be able to say what happens to a specific ticket at 6pm on a Friday without checking.

Who holds the keys

Wall-mounted network cabinet with a perforated steel door secured by a keyed lock

This is the question that decides whether the arrangement is a partnership or an acquisition, and it deserves a direct answer.

Your organization should own the tenant and the domain. Not the provider. Administrative accounts issued to provider staff should be named individual accounts, not a shared login, and they should be revocable by you, unilaterally, without a support ticket.

Ask for these commitments in writing:

  • You hold the top-level administrative credentials
  • Provider access is per-person, logged, and auditable
  • You can revoke any provider account immediately, on your own
  • Documentation — diagrams, inventories, credentials, runbooks — is yours outright and leaves with you
  • Changes to production systems require your approval, with the approver named

A provider who hesitates at any of these is describing a different relationship than the one on the proposal. A provider who has already written them down has done this before.

Three splits that come up repeatedly

The one-person IT department. One capable generalist, no backup, no vacation that isn't interrupted. Here co-managed is mostly about redundancy and hours: the provider covers nights, weekends, and the two weeks in July, and takes tier-1 volume so the internal person can do the work only they can do. The documentation deliverable matters most in this scenario, because right now there isn't any.

The small team without a security specialist. Three or four people who run the environment well but have no one whose job is security. The provider brings the security operations function — monitoring, detection, response, the insurance questionnaire — and the internal team keeps everything else. This one tends to be the easiest to scope and price, because the boundary is a discipline rather than a clock.

The team with no after-hours coverage. Competent, adequately staffed for business hours, and completely exposed from 6pm Friday. The split here is almost purely temporal, and it's the simplest version to negotiate because nothing about the daytime arrangement changes.

Most environments are some combination. The useful exercise is naming which one you actually are before taking a meeting, because it determines what you're buying.

What co-managed doesn't fix

Worth saying plainly, because the category oversells:

  • It doesn't fix an understaffed team by half a person. If you're two people short, co-managed covers hours and specialties, not headcount.
  • It doesn't resolve unclear internal ownership. If nobody internally owns IT decisions, adding a provider adds a party to an unresolved argument.
  • It doesn't make undocumented environments documented for free. That's a real project with real hours, and it should be scoped and priced as one.
  • It doesn't remove the need for someone on-site. Physical problems still need hands in the building — it just changes whose hands. We work through that tradeoff here.

How it gets priced

Co-managed is not reliably cheaper than fully managed, and a provider who leads with that claim is describing a narrower scope rather than a better deal.

What actually drives the number is the same thing that drives it in any managed agreement: security scope and coverage hours. A co-managed arrangement that includes 24/7 security operations can cost more than a fully managed one that doesn't. Model is close to irrelevant next to those two variables.

Three structures come up:

  • Per-device or per-user, with a defined scope. The easiest to compare between providers — provided you compare the scope lists rather than the monthly totals.
  • Functional blocks. You buy the specific pieces: after-hours coverage, security operations, patching. Cleanest when your gaps are well understood and you don't want to re-paper the whole environment.
  • A base agreement plus project work. Steady-state coverage priced monthly, with discovery, remediation and infrastructure work quoted separately. Worth insisting the remediation backlog gets scoped honestly rather than absorbed into the monthly rate, where it tends to quietly not happen.

Whichever shape it takes, ask what happens when your internal team shrinks or grows, because that's where a co-managed agreement gets renegotiated. For benchmark data on what managed agreements actually cost, we break that down separately.

What the first ninety days look like

A useful engagement is front-loaded, and you should be able to see progress on a calendar.

Weeks 1–4 — discovery. Asset inventory, network diagrams, a list of what's unsupported or past end of life, and identification of systems that can't take a standard patch cycle. You should end this phase with documents you own, whatever happens next.

Two people reviewing printed network diagrams and floor plans spread across a conference table

Weeks 5–8 — tooling and boundaries. Monitoring deployed, the ticket split turned on, escalation paths defined and tested, change windows agreed against your production schedule. This is where the division of labor stops being a slide and becomes a runbook.

Weeks 9–12 — steady state and measurement. A first review against agreed measures: what share of tickets the provider absorbed, what your internal team got back, what got documented that wasn't before, what's still open.

That last one is the honest test of the arrangement. Ninety days in, your IT manager should have measurably more time on work that requires knowing your business, and a shorter list of things only they can answer. If neither is true, the split is wrong and it's worth fixing early.

In a plant, a warehouse, or a processing facility

Two boundary questions matter more here than in an office.

Where does IT stop and OT begin? The production network — PLCs, HMIs, historians, machine-attached PCs — needs a named owner and a named boundary. In most co-managed arrangements the provider handles the business network and the segmentation between the two, while OT stays with the people who own the equipment and its vendor relationships. What matters is that it's written down, not that it's split any particular way. More on what changes by industry here.

Whose change window is it? Maintenance schedules in a plant belong to operations, not IT. A co-managed agreement that doesn't account for that will produce its first serious conflict in month two. The provider should be asking about your production schedule during discovery — and if they don't ask, that's the answer.

Frequently Asked Questions

What is co-managed IT?

A division of labor where an outside provider handles what scales badly for a small internal team — after-hours coverage, security operations, patching, tier-1 tickets — while your staff keep the applications, relationships, and decisions that depend on knowing your business.

Is co-managed IT a first step toward replacing our team?

It can be, and it's fair to ask. The signals worth watching: whether the scope is defined by function or by headcount, whether your team keeps administrative control and final say on changes, and whether the provider's proposal talks about what your people will do more of rather than what they'll stop doing. An arrangement that starts by taking your credentials is a different arrangement than one that starts by taking your after-hours pager.

How is co-managed different from fully managed IT?

Fully managed means the provider owns the environment end to end, which fits organizations with no internal IT. Co-managed keeps your team in place and in control, with the provider filling specific gaps. Most organizations with any internal IT are better served by the second.

Does co-managed cost less than fully managed?

Not reliably. Scope drives price far more than model does — a co-managed agreement with 24/7 security operations can cost more than a fully managed one without it. The benchmark data is here.

Who holds admin credentials in a co-managed arrangement?

You should. Your organization owns the tenant and the domain; provider access should be per-person, logged, and revocable by you without going through them. Get it in writing.

How many IT staff do you need before co-managed makes sense?

One is enough, and one is often the strongest case — a single-person department has no redundancy at all. The question isn't headcount, it's which hours and which specialties you can't cover.

An Arrangement Your IT Manager Would Agree To

CTC Technologies supports Michigan businesses from an Ann Arbor headquarters. We work alongside internal IT teams as often as we work without them, and we handle the physical layer ourselves — cabling, wireless surveys, network refresh — so the on-site work doesn't get subcontracted out from under you.

If you want to see what the split would look like, start with the discovery phase on its own: inventory, diagrams, what's past end of support, and where the coverage gaps actually are. You keep those documents regardless of what you decide.

Request an IT assessment or call 734-408-0200. Managed IT across Michigan, including Detroit, Warren, Novi, Canton, Lansing, and Ann Arbor.

We Have The Proof

We Solve Complex IT and Networking Problems.

Contact Us Today