A co-managed IT proposal can list the included services without explaining who approves changes, handles exceptions or takes over when an issue crosses teams. Those details matter when you compare offers and when the service starts.
Use a responsibility matrix to record those decisions. The example below separates the person doing the work from the approver and escalation contact, then adds questions to resolve before an agreement is signed.
Record the work, approval and escalation roles
An organization can delegate a task without delegating every decision around it. For example, a provider might perform routine administration while your IT lead approves changes to production systems. A separate contact may be needed for an issue outside the provider’s authority.
So use three columns for every row:
- Owner: who does the day-to-day work.
- Approver: who has to say yes before a change, a purchase, or an exception happens.
- Escalation contact: who gets called when the owner is stuck, when the issue exceeds their authority, or when the clock runs out.
Here, “owner” means the role performing the work, not a transfer of all organizational accountability. Specify the work and authority even when one role appears in several columns.
An illustrative matrix
The assignments below are illustrative, not a description of Virteva’s commitments or a recommendation for every organization. Adapt the rows with your IT and security leads and the provider. Some activities will need separate rows when the work, approval or escalation differs.
| Area | Owner (day to day) | Approver | Escalation contact | What to pin down before signing |
|---|---|---|---|---|
| Identity and access (accounts, groups, MFA, conditional access) | Provider for routine requests; internal for policy | Internal IT lead | Internal IT lead, then provider security contact | Who can grant admin rights? Who handles a suspected compromised account overnight? |
| Endpoints (imaging, patching, compliance, device replacement) | Provider | Internal IT lead for standards and exceptions | Provider desk lead | Which devices are excluded (shop floor, clinical, executive)? Who orders hardware? |
| Microsoft 365 (Exchange, Teams, SharePoint, licensing) | Provider for administration; internal for information architecture | Internal for licensing spend and tenant-wide settings | Provider Microsoft specialist | Who owns license true-ups? Who approves tenant-wide changes such as retention or sharing policies? |
| Infrastructure (servers, network, cloud resources, monitoring) | Provider for monitoring and maintenance | Internal for architecture changes | Provider infrastructure contact, then internal | Which systems are monitored? What is the response to an alert versus a failure? |
| Security alerts and incidents | Provider or SOC for triage | Internal for containment decisions with business impact | Internal security or IT lead | Is triage the same as response? Who can isolate a device or disable an account without asking? |
| Backups and recovery | Provider for jobs and verification | Internal for recovery priorities | Provider, then internal | Who tests restores, how often, and who sees the results? Who declares a recovery event? |
| Vendors (ISP, phone system, line-of-business applications, hardware) | Internal vendor owner; provider coordination if agreed | Internal vendor owner | Named vendor support contact, then internal vendor owner | Which vendors can the provider contact directly? Who follows vendor tickets to closure? |
| Changes (standard, normal, emergency) | Assigned implementer for each change type | Internal change authority or an agreed pre-authorized process | Internal IT lead | Which changes are pre-authorized? Who approves other changes and handles emergency decisions? |
| After-hours escalation | Provider desk | Internal on-call role for decisions above the provider’s authority | Named internal role, then executive sponsor | Who is on the internal on-call rota? What is the provider allowed to do at 3 a.m. without a call? |
Add rows for anything specific to your organization: clinical systems, manufacturing equipment, a warehouse management platform, a subsidiary with its own tenant. If you cannot name an owner for a row, that is a finding, not a gap in the template.
How to use the matrix against a proposal
Take the proposal and try to place every service it describes into a row and a column. Then look for three patterns.
Unresolved scope and exclusions. If a proposal covers endpoints but says nothing about backups, mark backups as unresolved. Ask whether the work is included, excluded or assigned to another party, and record the answer. A blank row remains an open question until the parties explicitly agree what it means. List confirmed exclusions in the agreement.
Shared work without defined responsibilities. “Shared” needs an explanation. For example, the provider might triage specified security alerts, take pre-authorized actions and escalate defined events to your security lead. Record the event types, authority and handoff rather than relying on “we work together on security.”
Unclear handoffs. Where work moves between organizations, specify the system, contact channel, information accompanying the ticket and how receipt is acknowledged. Include what happens if the intended contact is unavailable.
Compare proposals against the same completed rows. Consider the suitability of the coverage, evidence behind the answers, retained internal workload and price, rather than counting how many responsibilities a provider offers to take.
Questions to ask the provider
- Which rows in this matrix would you decline to own, and why?
- For each row you own, what are you authorized to do without asking us, and where does that authority stop?
- How does our team see your work? Can we look at every ticket, change, and alert in your system, or do we get reports?
- When one of your people escalates to one of ours after hours, how does that happen, and how do we know it happened?
- What is a standard change in your practice, and who defines the list for our environment?
- If we take a row back from you in year two, what changes in the contract?
- Who on your side is accountable for this matrix staying accurate as our environment changes?
The answers tell you as much about how the provider operates as they do about the scope.
Put it in the agreement
Once the matrix is agreed, ask the people responsible for the service agreement how it will be incorporated or referenced. Set a review cadence and a process for updating named contacts, exclusions and responsibilities as the environment changes.
Check that ticket routing and notifications reflect the agreed responsibilities. Test a handoff before relying on it for an urgent incident.
Discuss co-managed support with Virteva
Virteva provides co-managed IT alongside internal teams, with services including user support, endpoint management, Microsoft 365 administration, security operations and project work. The services available for your engagement and the responsibilities retained internally need to be confirmed in the proposed scope.
Read about the co-managed model or fully managed IT to consider which arrangement fits your team.
Frequently asked questions
Can we use our existing responsibility framework? Yes. This table is a simplified planning tool, not a replacement for your organization’s governance framework. Keep any additional roles your framework requires, and make sure the people doing the work can identify the approval and escalation arrangements.
How detailed should the rows be? Detailed enough that a new person on either side could read the row and know what to do. “Endpoints” is too broad if patching, imaging, and hardware ordering have different owners. Split rows when the three answers differ.
What if the provider will not commit to the matrix in writing? Ask how the provider documents the same responsibilities in its proposal or agreement. If the responsibilities remain unclear, leave the relevant rows unresolved and seek clarification before committing to the scope.
Next step
If you are considering co-managed support, contact Virteva with your current division of responsibilities and the areas where your team needs help. The matrix can help you prepare for that conversation.