This is for you if
- You are an MSP, software vendor, reseller or consultancy that has won work needing a skill you do not have in-house
- Your team has the skill but is at capacity, and a delivery date is not moving
- You need one piece of expert judgement, under NDA, delivered in your name
- You need to show your own procurement team, or your client's, who sits behind the delivery
The work usually goes back to the client with an apology, or to a contractor found in a hurry whose quality you cannot vouch for. The first costs you the account eventually. The second costs you it faster, because it is your name on the delivery either way.
This pack is for MSPs, software vendors, resellers and consultancies deciding whether to put Systech behind their brand. It covers what we deliver, how the engagement is structured, the terms that protect your client relationship, and how a job runs from first call to handover. It is deliberately specific, because a partner choosing a subcontractor needs terms, not adjectives.
1. Three situations, and they are not the same purchase
You are short of a skill
A contract landed that needs Azure Virtual Desktop design, an MSIX packaging backlog cleared, a Windows 365 rollout sized properly, a security hardening piece, or a migration off something end-of-life. Hiring for it makes no sense when it may not recur, and turning it down hands the client a reason to look elsewhere.
You are short of hands
The skill is not the problem; the calendar is. Two projects landed in the same month, somebody is on long-term leave, or a cutover date will not move. Overflow is our least complicated engagement: your process, your tooling, your standards, our people, for as long as the pinch lasts.
You need one answer, not a delivery bench
A tender needs a credentialed specialist to answer the technical section, a client proposal needs reading by somebody with no stake in it, or a design decision needs a second opinion before you commit. That is a bounded piece of consulting, and it is priced as one.
2. What we deliver under your brand
Broadly, the service lines we already run for our own clients, delivered by the same engineers with your name on the output.
Hands-on delivery
- Managed IT, with service desk cover by arrangement, depending on the partner
- Microsoft 365 and Azure project work: tenant builds, migrations, SharePoint and Teams structure, security hardening
- Security delivery: managed firewall, EDR and XDR rollout, Conditional Access design, Cyber Essentials preparation
- Backup and recovery design, and restore testing
- Application packaging and MSIX, including App Attach image builds
- Azure Virtual Desktop and Windows 365 design, build and cost optimisation
- Legacy Windows and Windows Server migrations
- Legacy application capture and repackaging where the original install media has gone
Advisory, delivered as material you can put your own cover on
- A second opinion on an approach before you commit to it
- A design review of something a client's previous supplier built
- A technical response to a tender question, including named, credentialed answers where a tender asks for evidenced expertise
- Sizing and cost modelling behind a proposal you are about to submit
- An independent technical assessment of an estate's licensing position, security posture and technical debt, for example before acquiring a book of business
For software vendors specifically: the deployment and integration layer around your product. That means getting it packaged, delivered and supported cleanly in a customer's Microsoft estate, answering the identity, device and virtual desktop questions your support team is not staffed for, or standing behind a proof of concept in an enterprise environment.
What this bench is not for: volume first-line service desk work, general body-shopping, and anything outside the Microsoft cloud, security, virtual desktop and application space. Service desk cover is available by arrangement on a white-label engagement, depending on the partner, but if you need volume rather than depth, a provider built for scale will serve you better and cost you less.
3. Engagement models compared
| Fully white-label | Co-branded | Overflow capacity | |
|---|---|---|---|
| Who the end client sees | Your brand only; we never appear | Your brand, with us introduced as your named specialist partner | Your brand; we work inside your existing processes |
| Who owns the client relationship | You, entirely, including all client communication | You, entirely; we are introduced, not handed the account | You, entirely; we never leave your queue |
| What the gap is | A skill you do not hold in-house | A skill the client wants to see evidenced by name | Capacity, not capability |
| Where our engineers work | Behind your delivery team, in your tooling and templates | Alongside your team, including client sessions where you want us | In your ticket queue, project board and change process |
| Typical trigger | A won contract that needs one thing you cannot staff | A governance or procurement process that asks who is doing the work | A peak, a holiday period, a backlog or a project running hot |
| Handover at the end | Documentation in your templates, issued as yours | Documentation in your templates, with our input attributed if you want it | Tickets and changes closed in your system, so nothing needs migrating |
| Best for | Vendors and MSPs protecting a single supplier relationship | Engagements where the specialism is part of what was bought | Established teams absorbing short-term demand without hiring |
4. Confidentiality, non-solicitation and ownership
NDA first
A mutual non-disclosure agreement is signed before any detail about your client, their estate or your commercial position is discussed. That applies to every engagement, including ones that stop at scoping. If you have your own NDA template, we work to yours.
No contact with your client
Unless you have introduced us and agreed it in advance. On a client call we attend as part of your team and follow whatever description you have set with them.
No marketing to your client
During the engagement or after it ends.
Non-solicitation
We are happy for a non-solicitation clause covering the end clients we are introduced to to be part of the engagement, drafted into your paperwork rather than ours, and made mutual. Insist on one from any partner, including us.
Your client's identity
For delivery work we usually need to know whose estate it is, after the NDA. For advisory, design review or scoping work we can often be useful with the environment described and the client anonymised, which is a reasonable way to test the arrangement.
Ownership
You own the deliverables produced for your engagement: designs, run books, handover documentation, scripts and configuration written for that client's estate. Our pre-existing methods, templates and internal tooling stay ours. That split is written into the scope at the start.
5. How a job runs
- NDA. Mutual, before any detail is shared.
- Scoping conversation. Within a day or two of you getting in touch. It establishes what the client actually needs, what you have already committed to in writing, and what your own team is keeping.
- Written scope. Deliverables, exclusions, the assumptions the estimate depends on, who owns each part, and how the work will be handed back. The quote is itemised, so you can price your own margin on top and compare it line by line with anyone else's. We give you a date we believe; if we cannot hold your date, we say so at this point rather than in week three.
- Access. Granted only after the scope is agreed, limited to what the work requires, and documented so both sides know exactly what we hold.
- Delivery. Through one agreed channel with a named owner on each side, usually a shared Teams channel or your own ticketing system, in your tooling and following your naming and change conventions where you want us there.
- Handover. Documentation as a defined deliverable, in your templates: reports, run books, design documents, handover notes and diagrams.
- Access removal. A defined step at the end, with confirmation back to you, so you have the record.
A scoped piece of work usually starts within a fortnight, sooner where the work is well defined and the discovery has already been done.
6. Incidents and escalation
Through you, always. You own the client relationship and therefore the client communication, so our job in an incident is to give you an accurate technical picture fast enough that you can be the one telling them something useful.
The mechanics are agreed per engagement and belong in the contract:
- What counts as an incident, as against a routine request
- Who is called, and on what number
- What our engineers may do without waiting for your approval, and what always needs your sign-off
- What happens when the named contact on either side is unavailable
We do not publish response targets for partner work. They depend on what is covered, during what hours, and what you have promised your client. Tell us your commitment and we will tell you plainly, in writing, what we can stand behind and what we cannot.
7. Commercial structure
No minimum commitment
And no retainer to sign before a first engagement. Most partner work is a single piece: one migration, one packaging backlog, one design, one second opinion.
Fixed-scope project work
Suits a defined deliverable with a clear end, such as a migration, a build or a packaging batch. It is the easier one to sell on, because the risk is bounded.
A retained bench
Suits partners with recurring or unpredictable demand. Plenty of partners start with the first and move to the second once the demand proves not to be one-off.
Priced per engagement
Against a written scope, because the same nominal task varies with the estate it lands in. A number quoted before anyone has looked at the environment is a number that will change.
8. What sits behind the delivery
The team. Senior engineers rather than a rota of first-line staff, which matters on partner work: you are putting your name on what we deliver, and you do not get to supervise it. Support is 100% UK-based.
Independently audited process.
- ISO 27001 for information security, certified by NDC Certification Services
- ISO 9001 for quality management, certified by NDC Certification Services
- Cyber Essentials, with a certificate you can verify online
- Microsoft partner status, with team certifications kept current
Over the last 12 months, across Systech client engagements, from our own service reporting.
Named expertise. Where a bid needs a named credential, the team includes Ryan Mangan, Systech's founder: a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS, and the author of Packt's Mastering Azure Virtual Desktop. That is what the co-branded model is for.
No logos, by design. We do not quote a partner count or show other partners' names. White-label work is confidential by definition, and a firm willing to show you its other partners is showing you how it would treat yours.
9. Where our scope ends
- We do not hold your client contract, and we do not carry your obligations under it. Your client's commercial terms, service commitments and regulatory accountability stay with you. We can build to a standard you have committed to, and give you the evidence that it was built that way.
- Our certifications are ours and do not transfer. ISO 27001, ISO 9001 and Cyber Essentials cover how Systech operates, so they are a fair statement about the processes your delivery runs through, not a certificate you can present as your own.
- Systech holds Cyber Essentials and helps clients prepare for it. We are not a certification body.
- Independent penetration testing is delivered with our CREST-approved partner, Punk Security. That approval is theirs, so it is disclosed rather than absorbed into anyone's brand.
- If a scope has been sold that cannot be delivered as described, we will tell you during scoping, not after you have taken the money.
- If the same skill gap keeps appearing, hire for it. We will tell you when the pattern suggests that, rather than quietly taking the work each time.
10. Questions to ask any subcontractor, including us
- Will you sign a mutual NDA before we share anything, and work to our template?
- Will you put a mutual non-solicitation clause covering our clients into our paperwork?
- Who is our named owner on your side, and what happens when they are away?
- What goes in the written scope, and is there an assumptions list?
- What access will you hold, where is it documented, and how and when is it removed?
- Is handover documentation a defined deliverable, in our templates?
- Who owns the deliverables, and what stays yours?
- What response and escalation commitments will you put in writing against our scope?
- Which of your certifications cover the work, and which belong to your own partners?
Where this leaves you
Specialist work, unlikely to recur often enough to hire for
Subcontract it and keep the client relationship entirely your own. That is what this is built for.
The same skill gap keeps appearing
Hire for it. We will tell you when the pattern suggests that, rather than quietly taking the work each time.
You need volume rather than depth
A provider built for scale will serve you better and cost you less. Service desk cover is by arrangement, depending on the partner, and we will say so on the first call.
A scope has been sold that cannot be delivered as described
We will tell you during scoping, not after you have taken the money.
If the work is specialist and unlikely to recur often enough to hire for, subcontract it and keep the client relationship entirely your own. That is what this is built for. Tell us what you have won, what is missing and when it has to land, and we will come back within a working day with whether we can help, and say so plainly if we cannot.
What does white-label delivery mean in practice?
We deliver the technical work and the advice behind it fully under your brand, so your client only ever sees you. You stay the single point of contact and the contracting party. We work as an invisible extension of your team, scoped to what you need: a one-off project, a specific skill gap, or an ongoing bench you can call on when the next contract demands it.
It is built for the specialist work that sits just outside a capable generalist team and comes up too rarely to justify a hire: an Azure Virtual Desktop or Windows 365 design, an MSIX packaging backlog, a security hardening piece, a migration off something end-of-life. Service desk cover is available by arrangement, depending on the partner. If the work is squarely what your team does every week, subcontracting it costs you margin and teaches your people nothing, and we will say so.
How do we protect your client relationship?
In writing, before anything else. A mutual NDA comes first on every engagement, including ones that never get past scoping, and we are happy to work to your template. We do not contact your client, appear in front of them or issue anything carrying our name unless you have introduced us and agreed it in advance. We do not market to your client during the engagement or after it ends.
We are happy for a non-solicitation clause covering the end clients we are introduced to to be part of the engagement, drafted into your paperwork rather than ours, and made mutual. Our own business is Microsoft cloud, security and IT support for end customers across Yorkshire and the UK; a reputation for taking partners' clients would close the partner side of it within a year. The incentive runs the same way as the contract.
Which engagement model fits?
Fully white-label is the default: your brand is the only one the client sees, and everything is written in your templates for you to issue as your own. Co-branded suits engagements where the client is buying the specialism as well as the relationship, often Azure Virtual Desktop, Windows 365 or security work where a named credential carries weight; you stay the contracting party and we are introduced as your named specialist partner.
Overflow is a capacity gap rather than a skill gap: our engineers work inside your ticket queue, project tooling and processes to absorb a peak, a holiday period, a backlog or a project running hot. The right model is usually obvious within one scoping call, and it can change between engagements.
How does a job run, from first call to handover?
NDA, then a scoping call, then a written scope naming the deliverables, the exclusions, the assumptions the estimate depends on, who owns each part and how the work will be handed back. Access is granted only after the scope is agreed, limited to what the work requires, and documented so both sides know what we hold. The assumptions list is the step most often skipped elsewhere, and it decides whether a change in the environment becomes a conversation or an argument.
Delivery runs through one agreed channel with a named owner on each side, in your tooling where you want us there. Handover documentation is a defined deliverable, produced in your templates, and access is removed as a defined step at the end, with confirmation back to you.
What sits behind the bench?
A certified, entirely UK-based team. Systech holds ISO 27001 for information security and ISO 9001 for quality management, both certified by NDC Certification Services, and Cyber Essentials, with a certificate you can verify online. Over the last 12 months, 98% of tickets met SLA with an average response time under 15 minutes, from our own service reporting.
Independent penetration testing is delivered with our CREST-approved partner Punk Security, and that approval is theirs, so it is disclosed rather than absorbed into anyone's brand. Where a bid needs a named credential, the team includes Systech's founder, Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, which is what the co-branded model is for.
Frequently asked
Will you approach our client?
No, and it is written into the agreement rather than offered as a promise. We work under NDA on every engagement, we do not contact your client directly unless you put us in the room, and we do not market to them during or after the work. We are also happy for a mutual non-solicitation clause covering the end clients we are introduced to to be drafted into your paperwork.
Can you provide service desk cover under our brand?
By arrangement, depending on the partner. Service desk cover can be part of a white-label engagement, but volume first-line work is not what this bench is built for. If what you need is volume rather than depth, a provider built for scale will serve you better and cost you less, and we will say so on the first call.
Can we use you for one piece of expert advice rather than a delivery bench?
Yes. A tender response section, a design review, a technical due-diligence assessment ahead of an acquisition, or a second opinion before you commit to a client all scope as a single bounded piece of consulting with a defined output. Say what you need on the first call and we will scope to that, not to a bigger engagement than the problem requires.
Is there a minimum commitment?
No. Most partner work is a single engagement. A retained bench is available where the flow of work justifies it, but it is something you can grow into rather than a condition of starting.
How quickly can you start?
A scoping conversation happens within a day or two of you getting in touch, and a scoped piece of work usually starts within a fortnight, sooner where the work is well defined. Tell us your date and we will tell you honestly whether we can hold it. We will not agree to a date we do not believe.
Who owns the documentation and intellectual property?
You do, for the deliverables produced for your engagement: designs, run books, handover documentation, scripts and configuration written for that client's estate. Our own pre-existing methods, templates and internal tooling stay ours. That split is written into the scope at the start, so nobody discovers it at the end.
Can we present your ISO certificates to our client?
Not as your own. Systech's ISO 27001, ISO 9001 and Cyber Essentials certificates cover how Systech operates. They are a fair statement about the processes your delivery runs through, and they give your client's procurement team evidence about your supply chain, but they do not transfer to your organisation.












