Most of the conversations we have start the same way. Someone runs IT for a 15-to-70-person organization — sometimes it's their whole job, sometimes it's half of it — and they're not failing. They're just the only one. Every patch, every onboarding, every "hey, quick question" routes through one person. It works right up until it doesn't: a vacation, a server migration, a security questionnaire from a funder, and suddenly the whole thing is stuck behind one calendar.
The instinct is to call a managed services provider. The fear is that calling one means handing over the keys and watching your internal person get managed out of a job.
That's not the only option. Co-managed IT is the middle path, and for organizations your size it's frequently the right one.
What co-managed IT actually means
Co-managed IT means your internal person or team keeps owning IT, and an outside team covers the parts that don't fit inside one person's week.
It is not a trial run for a full takeover. It's not a staffing agency placing a warm body. It's a division of labor that plays to what each side is actually good at.
Your internal person knows things an outside provider never will. They know which director always needs the same thing twice, which line-of-business application breaks if you look at it wrong, which workflow the executive director will not give up regardless of what a best-practice document says. That institutional knowledge is the most valuable IT asset you have, and it isn't transferable.
What an outside team brings is different: coverage that doesn't take vacation, tooling that's too expensive to justify for one company, and depth in the areas nobody can stay current in part-time.
Both halves are real. The mistake is assuming you have to pick one.
Three situations where it fits
You have one IT person and no backup. This is the most common. Your person is competent and overloaded, and there's no second set of hands when they're out or when something big lands. Co-managed gives them a bench. It also means they can take a real vacation.
Your team is strong on applications and thin on infrastructure. A lot of internal IT grew up around the business systems — the ERP, the case management platform, the production floor software. That's exactly where you want internal ownership. But the same person is now also expected to own endpoint security, Microsoft 365 hardening, and a backup strategy that would survive an actual test. Those are different disciplines.
Growth is outrunning the team. You added a location, doubled headcount, picked up a compliance obligation. Hiring a second IT person is a real cost and a long search. Co-managed lets you add capacity now and decide about hiring from a calmer position.
When it doesn't fit
Two situations where we'll tell you so.
When there's nobody internal at all. Co-managed needs a counterpart. If IT currently belongs to the operations manager as a fourth job, you don't need co-managed — you need fully managed IT, and calling it co-managed just leaves ambiguity about who owns what.
When nobody will write the split down. This is the one that quietly kills co-managed arrangements. If the division of labor lives in a shared understanding rather than a document, both sides assume the other has it. The gap doesn't show up on a normal Tuesday. It shows up during an incident.
A split that isn't written down isn't a split. It's an assumption held by two parties.
Dividing the six areas
When we assess an environment we score it across six areas. They're also the cleanest way to divide a co-managed relationship, because every one of them has a natural owner once you say it out loud. Here's how the split usually lands — and where it usually goes wrong.
- Identity & Access. Almost always shared. The provider owns the platform and the policy — multi-factor enforcement, conditional access, admin account separation, the quarterly access review actually happening. Internal owns the people decisions: who should have what, and who just changed roles. This area is worth getting right first. The 2025 Verizon Data Breach Investigations Report found stolen credentials involved in 88% of attacks against basic web applications. It's the front door.
- Devices & Endpoints. Usually the provider, at scale. Patching, endpoint protection, encryption, the standard build. Internal keeps the exceptions — the machine on the production floor that can't reboot during a shift, the workstation running the software the vendor stopped supporting in 2019. Exceptions are fine. Undocumented exceptions are not.
- Email Security. Usually the provider outright. This is specialist work, it changes constantly, and it's where the money actually gets stolen. Internal stays in the loop on one thing: the finance process. No technical control substitutes for a policy that a change to payment details always gets a phone call.
- Backup & Recovery. This is the area that most often ends up owned by nobody. Both sides assume backups are running because backups are always running. The question that matters isn't whether they run — it's who is on the hook for restoring something on purpose, on a schedule, and writing down how long it took.
- Support & Response. The real decision, and the one most worth arguing about. The usual shape: internal handles what they're fastest at — the line-of-business applications, the requests that need context — and the provider takes overflow, after-hours, and anything requiring specialist depth. What breaks this is leaving the routing rule vague. Your staff need to know where to send a request without having to make a judgment call first.
- Network & Infrastructure. Usually the provider, with internal keeping the vendor relationships — the ISP, the phone system, the landlord's building access. Firewall, switching, wireless and server infrastructure benefit from someone who does it every day.
Worth being specific here, because a lot of organizations get it wrong: your Microsoft 365 data is probably not backed up the way you think. Under the shared responsibility model you're the data owner, and Microsoft's Services Agreement says plainly, "We recommend that you regularly back up your content and data that you store on the services." Retention policies and the recycle bin are not backups. Someone has to own that, by name.
If you can't name the owner for all six, you don't have a co-managed arrangement. You have two teams hoping.
The structure question — and the trap in it
Most co-managed IT gets sold as a block of hours. Twenty hours a month, forty, whatever. It feels safe because it's bounded and you can see what you're buying.
It's worth understanding what that structure does over time.
If you're buying hours, then every hour the provider saves you is revenue they lose. Automate a patch cycle, script an onboarding, fix a root cause instead of a symptom — each of those reduces hours consumed. Their incentive quietly runs opposite to yours. And from your side it starts to read as "we're paying for hours we don't use," which is a reasonable thing to think and a bad place for a partnership to end up.
The better a block-of-hours provider gets at their job, the weaker their position becomes.
That's a structural problem, not a character problem. It's why we don't price that way. We meter on the environment we're actually managing — devices, servers, accounts — not on hours burned or on headcount. You get one number, flat, fixed for twelve months, no overages. If you grow mid-year the number doesn't move. It changes at an annual review, in a conversation, never as a surprise on an invoice. Automation becomes something we're motivated to do, because the efficiency is ours to gain and the stability is yours.
If you want the longer version of how managed IT gets priced generally, we wrote that up separately: how much managed IT services cost.
What to ask for before you sign anything
Whoever you talk to — us or anyone else — ask to see these written down. Documents are more useful than answers here, for both sides. Putting the split on paper is what surfaces the assumptions, and it gives you something to hold everyone to later.
- The split, area by area. Who owns Identity & Access, Devices & Endpoints, Email Security, Backup & Recovery, Support & Response, Network & Infrastructure.
- The coverage plan for when your internal person is out. What a two-week absence actually looks like, in writing.
- Tooling access. Whether your person gets into the monitoring console or only the ticket queue. Real co-managed means shared visibility — otherwise it's outsourcing with extra steps.
- The backup verification schedule. Who restores something on purpose, how often, and where the result gets recorded.
- The pricing mechanism — not the price. What can move the bill. Any lever that changes cost without your environment changing is one you'll eventually be discussing.
- Your named engineer and your escalation contact. You should have both names on day one, not have to find out during a crisis.
Why we'd tell you all this
Because organizations that understand their own technology make better decisions — and better partners later, if that day ever comes. Everything on that list applies to us the same as to anyone else, and a few items will help you argue for hiring internally instead. That's a fine outcome.
If you want the split written down for your specific environment, that's what our free IT risk review produces. Thirty minutes, then a one-page findings report on your security, backup, and support gaps, plus an inventory of what you're actually running. Frequently it's the first complete one an organization has ever had. It's yours to keep whether or not we ever speak again.
We're a veteran-owned team in the Denver metro, working with organizations in the 15-to-70 person range — nonprofits, professional services, and manufacturers. Senior engineers only, month-to-month, no multi-year lock-in.
If your IT is one person deep and you're tired of being the single point of failure, that's a conversation worth having.
Book a free IT risk review or call us at 720-794-0400.