Co-Managed IT Support for In-House IT Teams
Your team keeps the day-to-day and the projects. We take the run-and-maintain load behind them.
Depth behind your team, not instead of it
In short: Co-managed IT splits one estate between your internal IT team and us, in writing, at onboarding. Your people keep day-to-day support, priorities and projects; we take monitoring, patching, backup checks, out-of-hours cover and specialist depth. Right for organisations of 15 to 250+ people with IT staff worth keeping.
Your IT person was hired to move the business forward. Most weeks the time goes on patching, chasing backup warnings and taking the evening call nobody else can, and the projects slide to next quarter again.
The problem
One or two people cannot be awake at 3am, on holiday and current across security, cloud, identity and networking all at once. The run-and-maintain work never stops, so it eats the week, the improvement work gets deferred, and the quiet failures (a backup warning nobody read, a patch that never landed) are found on the day they matter.
What we would do
If you have internal IT worth keeping and the run-and-maintain work is crowding out everything else, co-managed is the right model and usually the best value. Your team keeps the knowledge of your business, and we take the work that benefits from tooling, scale and cover outside working hours.
- If you have no internal IT, or one person whose role was never really IT, a fully managed contract is the simpler answer.
- If your team covers the working day well and the only gap is the hours it cannot cover, buy out-of-hours cover on its own.
- If patching runs on a schedule, backups are restore-tested, security tooling is current and nothing has sat on the 'when we get time' list for months, you may not need a provider yet.
When we are not the answer: If what you need is another pair of hands physically in your building most days, picking up desk-side requests as they arise, another internal hire will serve you better than we will. We are strong on Microsoft cloud, identity, security and well-run remote support behind your team; we are not a body on site.
Your team keeps the day-to-day and the project work. We take the run-and-maintain load (patching, monitoring, backup checks, firewall management and out-of-hours cover) so your people can move the business forward instead of patching firewalls at night.
More on how we deliver co-managed IT support
What we take on varies by customer, and that is deliberate: the scope is built around what your team already does well and what keeps getting pushed to next week. It is written down at onboarding as a split of who owns what, and your team stays in control of change, because updates and changes are agreed with you before they are scheduled.
Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.
If you are still deciding whether to replace, supplement or leave your current arrangement alone, our MSP vs internal IT guide sets out all three options, including when the honest answer is to wait.
How a scoped engagement runs, from the first conversation to an itemised quote, is set out on our pricing page.
Everything you need, managed for you
What is co-managed IT support?
Co-managed IT is one estate looked after by two teams on purpose: your internal IT person or team, and us. It is not a provider covering for your team's absence, and it is not a first step towards replacing them.
The split that usually works: your team keeps what benefits from presence and context, which is day-to-day user support, business priorities, vendor relationships and project ownership. We take what benefits from tooling, scale and continuity: monitoring, patching, backup checks, security, out-of-hours cover, and the specialist work that comes up a few times a year and has to be right.
Done well, the internal role gets better rather than smaller. The week stops going on patching and backup warnings, and starts including the projects that were always deferred because there was never a clear fortnight.
Which services can we take on?
Scope varies by customer, so this is a menu rather than a bundle. What we can take on alongside your team:
- Microsoft 365 administration, and Copilot readiness and governance
- Azure infrastructure support and monitoring
- Managed firewall: monitoring, configuration backup, patching and change control
- Patching for operating systems and third-party software, on staged rings
- Backup that is monitored, with restores tested rather than assumed
- Infrastructure support and monitoring for servers, storage and the network
- Out-of-hours cover for evenings, weekends, leave and sickness
- Proactive support: daily checks, and fixes before they become tickets
- Virtual desktops on Azure Virtual Desktop and Windows 365
Some customers hand us one piece, often the firewall estate or out-of-hours cover. Others hand us most of the run-and-maintain work and keep the projects. Both are co-managed; the only difference is where the line sits.
Who owns what, and how is that agreed?
In writing, at onboarding. Co-managed arrangements fail in one specific way: both sides assume the other is watching something, and the answer turns out to be nobody. The backup warning goes unread because each team thought the other had it.
So the first thing we agree with you is a written split covering:
- Which systems belong to which team
- Who holds which administrative roles, including the privileged accounts in your Microsoft tenant
- Who responds first to each type of alert, in hours and out of hours
- Where tickets are raised, and how they pass between the two teams
- Who approves changes, and who can authorise an urgent one out of hours
The split moves as your estate does, because a new system or a new starter in your team changes where the line sits. If a provider will not write this down, that tells you something.
How does your team stay in control?
Through change control that happens before work is scheduled, not a report after it. Updates and changes are raised as change requests and agreed with your team before they go into a window, so nothing lands on your estate that your people did not know was coming.
Your team also works directly with senior engineers. There is no tiered first-line queue to get through before somebody who knows the estate picks it up, which matters when the person raising the ticket is technical and has already done the first-line checks.
What do the daily checks cover?
Our daily checks confirm that backups ran, that security has been reviewed, and that systems are running as expected. When we find something in our half of the split, we fix it and tell you what we found and what we did, so your team hears about it from us rather than from a user.
That rhythm is a large part of what frees your team. The checks happen whether or not anybody internal had time that morning, and the problems they catch are the quiet ones that otherwise surface on the worst possible day.
How is co-managed IT priced?
Against the split of responsibilities rather than per user, because two organisations of the same size can need very different things from us. A team that hands us the firewall estate and out-of-hours cover is a different engagement from one that hands us monitoring, patching, backup and Azure.
So we scope first and then quote, and the quote is itemised so you can see what each part covers and compare it line by line with anyone else's. The published per-user rate on our pricing page is for a fully managed estate, which is a different purchase.
Questions we hear a lot
Who owns what in a co-managed arrangement?
Whatever the written split agreed at onboarding says, and nothing is assumed. Typically your team keeps user-facing support, priorities, vendors and projects, and we take monitoring, patching, backup checks, security and out-of-hours cover. The written version names the systems, the administrative roles, the first responder for each alert type and how tickets pass between the teams, so nothing falls between them.
What happens when our IT person is on holiday or off sick?
The work in our half of the split carries on as normal, because it never depended on them. For their half, what we pick up while they are away, and how your users reach us, can be agreed at onboarding as part of the split, so leave and sickness stop being the weeks when IT waits. If the gap is evenings and weekends as well, out-of-hours cover can be part of the scope.
Are you trying to replace our IT team?
No. Co-managed is the most common shape of our work with organisations that already have internal IT, and we usually recommend it because it keeps the knowledge of your business in your business. Your team's role tends to change shape rather than shrink: less patching and backup chasing, more of the project work they were hired for. If a fully managed contract would genuinely suit you better, we will say so, and the decision stays yours.
Will you make changes to our systems without asking?
No. Updates and changes are raised as change requests and agreed with your team before they are scheduled. Who can approve a change, and who can authorise an urgent one out of hours, is agreed at onboarding, so it is settled before it is needed rather than in the middle of an incident.
Is there a minimum scope?
There is no standard bundle you have to buy. Some customers start with one piece, such as the managed firewall or out-of-hours cover, and add to it once they have seen how the split works in practice. The scope and the quote follow what you hand us, so a small scope is a smaller engagement rather than a reason for us to turn you away.
Co-managed IT support is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in York, Sheffield, Barnsley, Halifax, Doncaster and Wakefield and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
Tell us what you need
A short call to talk through how your IT works today, what your team handles, and what you need from a provider. We will tell you plainly how we would approach it.
