Home / Resources / Managed IT
Managed IT

Co-Managed IT Responsibility Matrix: What to Agree Before Signing

DR
Dan Rosedahl
Sep 24, 2026
Two people at a table pointing at printed forms, with a pen, phone and tablet beside them

A co-managed IT proposal can list the included services without explaining who approves changes, handles exceptions or takes over when an issue crosses teams. Those details matter when you compare offers and when the service starts.

Use a responsibility matrix to record those decisions. The example below separates the person doing the work from the approver and escalation contact, then adds questions to resolve before an agreement is signed.

Record the work, approval and escalation roles

An organization can delegate a task without delegating every decision around it. For example, a provider might perform routine administration while your IT lead approves changes to production systems. A separate contact may be needed for an issue outside the provider’s authority.

So use three columns for every row:

Here, “owner” means the role performing the work, not a transfer of all organizational accountability. Specify the work and authority even when one role appears in several columns.

An illustrative matrix

The assignments below are illustrative, not a description of Virteva’s commitments or a recommendation for every organization. Adapt the rows with your IT and security leads and the provider. Some activities will need separate rows when the work, approval or escalation differs.

AreaOwner (day to day)ApproverEscalation contactWhat to pin down before signing
Identity and access (accounts, groups, MFA, conditional access)Provider for routine requests; internal for policyInternal IT leadInternal IT lead, then provider security contactWho can grant admin rights? Who handles a suspected compromised account overnight?
Endpoints (imaging, patching, compliance, device replacement)ProviderInternal IT lead for standards and exceptionsProvider desk leadWhich devices are excluded (shop floor, clinical, executive)? Who orders hardware?
Microsoft 365 (Exchange, Teams, SharePoint, licensing)Provider for administration; internal for information architectureInternal for licensing spend and tenant-wide settingsProvider Microsoft specialistWho owns license true-ups? Who approves tenant-wide changes such as retention or sharing policies?
Infrastructure (servers, network, cloud resources, monitoring)Provider for monitoring and maintenanceInternal for architecture changesProvider infrastructure contact, then internalWhich systems are monitored? What is the response to an alert versus a failure?
Security alerts and incidentsProvider or SOC for triageInternal for containment decisions with business impactInternal security or IT leadIs triage the same as response? Who can isolate a device or disable an account without asking?
Backups and recoveryProvider for jobs and verificationInternal for recovery prioritiesProvider, then internalWho tests restores, how often, and who sees the results? Who declares a recovery event?
Vendors (ISP, phone system, line-of-business applications, hardware)Internal vendor owner; provider coordination if agreedInternal vendor ownerNamed vendor support contact, then internal vendor ownerWhich vendors can the provider contact directly? Who follows vendor tickets to closure?
Changes (standard, normal, emergency)Assigned implementer for each change typeInternal change authority or an agreed pre-authorized processInternal IT leadWhich changes are pre-authorized? Who approves other changes and handles emergency decisions?
After-hours escalationProvider deskInternal on-call role for decisions above the provider’s authorityNamed internal role, then executive sponsorWho is on the internal on-call rota? What is the provider allowed to do at 3 a.m. without a call?

Add rows for anything specific to your organization: clinical systems, manufacturing equipment, a warehouse management platform, a subsidiary with its own tenant. If you cannot name an owner for a row, that is a finding, not a gap in the template.

How to use the matrix against a proposal

Take the proposal and try to place every service it describes into a row and a column. Then look for three patterns.

Unresolved scope and exclusions. If a proposal covers endpoints but says nothing about backups, mark backups as unresolved. Ask whether the work is included, excluded or assigned to another party, and record the answer. A blank row remains an open question until the parties explicitly agree what it means. List confirmed exclusions in the agreement.

Shared work without defined responsibilities. “Shared” needs an explanation. For example, the provider might triage specified security alerts, take pre-authorized actions and escalate defined events to your security lead. Record the event types, authority and handoff rather than relying on “we work together on security.”

Unclear handoffs. Where work moves between organizations, specify the system, contact channel, information accompanying the ticket and how receipt is acknowledged. Include what happens if the intended contact is unavailable.

Compare proposals against the same completed rows. Consider the suitability of the coverage, evidence behind the answers, retained internal workload and price, rather than counting how many responsibilities a provider offers to take.

Questions to ask the provider

The answers tell you as much about how the provider operates as they do about the scope.

Put it in the agreement

Once the matrix is agreed, ask the people responsible for the service agreement how it will be incorporated or referenced. Set a review cadence and a process for updating named contacts, exclusions and responsibilities as the environment changes.

Check that ticket routing and notifications reflect the agreed responsibilities. Test a handoff before relying on it for an urgent incident.

Discuss co-managed support with Virteva

Virteva provides co-managed IT alongside internal teams, with services including user support, endpoint management, Microsoft 365 administration, security operations and project work. The services available for your engagement and the responsibilities retained internally need to be confirmed in the proposed scope.

Read about the co-managed model or fully managed IT to consider which arrangement fits your team.

Frequently asked questions

Can we use our existing responsibility framework? Yes. This table is a simplified planning tool, not a replacement for your organization’s governance framework. Keep any additional roles your framework requires, and make sure the people doing the work can identify the approval and escalation arrangements.

How detailed should the rows be? Detailed enough that a new person on either side could read the row and know what to do. “Endpoints” is too broad if patching, imaging, and hardware ordering have different owners. Split rows when the three answers differ.

What if the provider will not commit to the matrix in writing? Ask how the provider documents the same responsibilities in its proposal or agreement. If the responsibilities remain unclear, leave the relevant rows unresolved and seek clarification before committing to the scope.

Next step

If you are considering co-managed support, contact Virteva with your current division of responsibilities and the areas where your team needs help. The matrix can help you prepare for that conversation.

co-managed ITresponsibility matrixIT vendor evaluation

More from the blog

Ready to optimize your Microsoft environment?
Talk to our team about what a managed services partnership looks like for your organization.
Schedule a conversation