What Should a Managed IT Services Agreement Include? A 12-Point Checklist
A managed IT services agreement defines far more than the monthly fee. It establishes which users and systems are covered, when support is available, how requests are prioritized, which security and backup responsibilities belong to each party and what happens when the relationship changes or ends.
Two proposals can appear similar while providing very different levels of coverage. One may include on-site support, backup monitoring and strategic reviews; another may price those services separately. Terms such as “unlimited support,” “24/7 service” and “proactive management” can also mean different things unless the agreement defines them.
This checklist helps Ontario businesses identify the operational questions that should be answered before signing or renewing an IT support agreement. It provides general business information, not legal advice. Have qualified legal counsel review contractual rights, obligations, liability and compliance requirements.
What Is a Managed IT Services Agreement?
A managed IT services agreement documents an ongoing relationship between a business and an IT provider. Depending on the provider, the complete arrangement may use several connected documents:
- A master services agreement governing the overall commercial relationship
- A service schedule describing recurring managed services
- A statement of work for a specific project or onboarding activity
- A service-level agreement defining priorities and performance expectations
- A pricing schedule
- Security, privacy or data-processing terms
There is no single document structure that fits every relationship. The practical question is whether the complete set of documents clearly defines scope, responsibilities, performance, costs, change procedures and exit requirements.
1. Covered Users, Devices, Locations and Systems
The agreement should identify what the provider is responsible for supporting.
Ask whether coverage includes:
- Employees, contractors and shared accounts
- Workstations and laptops
- Mobile devices
- Servers and virtual machines
- Network equipment and internet connections
- Offices and remote locations
- Microsoft 365 or other cloud tenants
- Business applications
- Printers and specialized equipment
- Supported operating systems and versions
The agreement should also explain how new employees, devices and locations are added and when billing changes.
Unsupported or end-of-life technology deserves particular attention. A provider may monitor it temporarily while recommending replacement, exclude it completely or support it only on a best-effort basis. The treatment should be documented rather than assumed.
2. Included Services and Explicit Exclusions
The service description should identify what the recurring fee includes.
Potential services include:
- Help desk and remote support
- On-site assistance
- Remote monitoring and management
- Patch management
- Endpoint protection
- Email security
- Microsoft 365 administration
- Backup monitoring
- Vendor coordination
- Hardware and software procurement
- Technology reporting
- Strategic planning
Ask for exclusions in writing. Common separately priced work may include major migrations, office moves, new server deployments, cabling, security-incident recovery, after-hours projects, application consulting and remediation of pre-existing problems.
If a proposal promises “unlimited support,” confirm the covered users, devices, hours and request types. Unlimited remote assistance for routine incidents does not necessarily include projects, on-site work or support for every application.
3. Support Hours and Communication Channels
The agreement should explain when and how users can request help.
Review:
- Standard service hours
- Telephone, email and portal access
- After-hours procedures
- Emergency coverage
- Holiday coverage
- On-site availability
- Authorized contacts
- Support for remote employees
The phrase “24/7” requires a definition. It may refer to automated monitoring, ticket intake, an answering service or direct access to technical staff. These are not equivalent.
Ask which issues qualify for after-hours response and what additional charges apply.
4. Priority Levels, Escalation and Service Levels
An SLA should explain how support requests are classified and what timing commitments apply to each priority.
Important terms include:
- Acknowledgement: confirmation that the request was received
- Response: engagement by an appropriate support resource
- Work commencement: when troubleshooting begins
- Target resolution: an objective based on the issue type
- Escalation: when the request moves to a more specialized or senior resource
Priority should consider business impact and urgency. A problem affecting an entire location or critical system should not be handled like a routine request from one user.
Ask whether timing commitments pause while the provider waits for client information, third-party vendors, replacement hardware or access to the affected system.
Most importantly, do not confuse a fast response target with a guaranteed resolution time. Some problems depend on vendors, replacement parts, software developers or complex investigation outside the provider’s direct control.
5. Cybersecurity Responsibilities
Managed IT and cybersecurity often overlap, but the agreement should identify the actual controls and responsibilities included.
Review responsibility for:
- Identity and access management
- Administrative privileges
- Multi-factor authentication
- Endpoint protection
- Email protection
- Patch and vulnerability management
- Firewall and network security
- Security monitoring
- Incident notification
- Incident response
- Security awareness training
- Third-party and subcontractor access
- Cyber-insurance requirements
The Canadian Centre for Cyber Security advises organizations to identify the sensitivity and criticality of their information and establish appropriate security expectations when contracting managed service providers.
Security is a shared responsibility. The client may still be responsible for approving changes, following security policies, reporting employee departures, maintaining insurance and making business decisions during an incident.
Avoid an agreement that simply says “security included” without identifying the controls, coverage and limitations.
6. Backup, Restore Testing and Business Continuity
Backup terms should describe more than whether a backup product is installed.
Confirm:
- Which systems and data are protected
- Backup frequency
- Retention periods
- Local, off-site and cloud copies
- Encryption and access controls
- Monitoring of failed jobs
- Restore-testing frequency
- Recovery priorities
- Recovery-time objectives
- Recovery-point objectives
- Responsibilities during a disruption
A completed backup job does not automatically confirm that a business can recover. Restore testing helps verify that data and systems can be accessed when needed.
The agreement should also distinguish routine file restoration from a larger disaster-recovery or ransomware response. Significant recovery work may require separate planning, specialist services or project fees.
7. Third-Party Vendors, Cloud Services and Licensing
IT providers often coordinate with software companies, internet providers, telecom carriers, hardware manufacturers and cloud platforms.
Clarify whether the provider acts as:
- Reseller
- Licence administrator
- Technical administrator
- Support liaison
- Procurement partner
- Billing intermediary
Ask who owns each account and what happens to licences if the agreement ends. The business should understand which subscriptions are held directly and which are supplied through the provider.
The agreement should also explain how vendor price changes, licence increases and product retirement are communicated and approved.
8. Onboarding and Initial Remediation
Onboarding establishes the information, access and tools the provider needs to deliver service.
A documented process may include:
- Asset and software inventory
- Network and cloud discovery
- Credential transfer
- Documentation review
- Deployment of monitoring and security tools
- Backup review
- Security assessment
- Identification of unsupported systems
- Initial remediation plan
- Employee communication
- Service launch meeting
Ask which onboarding activities are included in the recurring fee and which are separately billed.
Existing security gaps, undocumented systems and overdue upgrades may require remediation before the standard service can begin. The agreement should explain how that work is identified, quoted and approved.
9. Reporting and Strategic Review
Regular reporting should help the business understand service performance, technical risk and upcoming decisions.
Useful reporting can cover:
- Ticket volume and recurring issues
- Response performance
- Patch status
- Backup results and restore tests
- Security alerts and incidents
- Device age and warranty status
- Software and licence changes
- Capacity or performance concerns
- Open projects
- Recommended priorities
Confirm how often reports and review meetings occur, who attends and whether strategic planning is included.
Ticket counts alone do not show whether the environment is becoming more reliable or secure. Good reporting connects technical activity to business risk and priorities.
10. Pricing, Projects and Change Control
The pricing schedule should explain how recurring and non-recurring charges work.
Review:
- Per-user, per-device, per-location or flat pricing
- Minimum monthly charges
- Included labour
- On-site charges
- Travel
- After-hours work
- Hardware and software
- Cloud usage
- Project work
- Onboarding
- Emergency response
- Annual adjustments
- New-user and new-location changes
- Taxes
Ask how changes are approved. A written quote or statement of work should normally define significant project scope, deliverables, timing and fees before work begins.
Compare total service scope rather than monthly price alone. A lower fee may exclude activities another provider includes.
11. Client Responsibilities
A successful managed-service relationship requires participation from the client.
The agreement may require the client to:
- Provide timely access and accurate information
- Identify authorized contacts
- Notify the provider of employee changes
- Maintain supported technology
- Follow agreed security practices
- Approve recommendations and projects
- Protect credentials
- Identify critical systems and acceptable downtime
- Maintain appropriate insurance
- Participate in incident and recovery decisions
These obligations should be reasonable and clear. The client should understand how delays or unapproved risks may affect service commitments.
12. Term, Renewal, Termination and Offboarding
Review the end of the relationship before signing the beginning.
Confirm:
- Initial contract term
- Automatic renewal
- Notice periods
- Early-termination charges
- Final billing
- Data export
- Credential transfer
- Documentation handover
- Licence transfer
- Removal of management tools
- Transition assistance
- Data retention and deletion after termination
The agreement should protect security during transition without preventing the business from accessing its own systems and information.
Ask how long offboarding normally takes, which assistance is included and what may be billed separately.
Red Flags Before You Sign
- The service scope is described only in sales language.
- Exclusions are not documented.
- “Unlimited” and “24/7” are not defined.
- SLA priority levels are unclear.
- Security responsibilities are reduced to product names.
- Backup is included without restore testing.
- The provider retains exclusive control of client accounts.
- Project and after-hours charges are unclear.
- Onboarding has no documented process.
- Reporting is limited to ticket counts.
- Price-adjustment language is vague.
- There is no offboarding or data-transfer process.
Ten Questions to Ask During Agreement Review
- Which users, devices, locations and systems are covered?
- Which work is billed separately?
- How are priority levels assigned?
- Does the SLA measure acknowledgement, response or resolution?
- Who owns our accounts, credentials and documentation?
- Which data is backed up, and how is restoration tested?
- What happens outside standard service hours?
- How are security incidents reported and managed?
- Which reports and strategic reviews will we receive?
- What happens to data, licences, tools and credentials when the agreement ends?
Match the Agreement to Your Business Risk
There is no universal managed IT package. Appropriate coverage depends on:
- Organization size
- Number of locations
- Working hours
- Critical applications
- Data sensitivity
- Privacy and contractual obligations
- Internal IT capability
- Remote-work requirements
- Acceptable downtime
- Growth and project plans
A small office using cloud applications may need a different service model from a multi-location organization with servers, specialized systems and strict recovery requirements.
The agreement should reflect the actual environment rather than force every client into the same checklist of tools.
Review Your IT Support Requirements with Access Group
Access Group provides managed IT, help desk, on-site support, remote monitoring, infrastructure, cloud, procurement and cybersecurity services for small and mid-sized businesses across Toronto and the GTA.
The appropriate service scope depends on your users, systems, locations, operating hours, risks and internal capabilities. Speak with Access about your current environment and the responsibilities that should be clearly defined in an IT support relationship.
Review Your IT Support Requirements
Frequently Asked Questions
What is the difference between an MSA and an SLA?
A master services agreement commonly governs the overall commercial relationship. A service-level agreement defines service priorities and performance expectations. Providers may structure their documents differently, so review the complete set with qualified legal counsel.
Does managed IT automatically include cybersecurity?
No universal package exists. The agreement should identify the specific security controls, systems, users, monitoring and incident responsibilities included.
Is backup normally included in managed IT?
It may be included, optional or supplied through a separate service. Confirm protected systems, frequency, retention, monitoring, restore testing, recovery responsibilities and costs.
What does unlimited IT support mean?
There is no standard definition. Confirm the covered users, devices, hours, request types, labour, on-site work, projects and exclusions.
Can a business leave a managed IT agreement early?
That depends on the contract. Review the term, notice period, early-termination charges, data transfer, documentation, licences and transition assistance with legal counsel.