Most managed IT proposals lead with a per-user price and a short bullet list: help desk, security, monitoring, "and more." That's marketing copy, not a scope of work. The agreement itself, the part that determines what happens when something breaks, usually gets read for the first time after something has already gone wrong. It shouldn't be. Here's what a managed IT agreement actually needs to define, and what to check for in Halian's own structure before you sign anything.

The four things every managed IT agreement should define

Strip away the marketing language and a real agreement answers four questions: what's covered, how fast we respond, what's explicitly excluded, and how issues escalate when the first response isn't enough. If a proposal can't answer those four in plain language, the price on it means very little, because you don't yet know what you're pricing.

What's covered under a fully managed scope

At the base tier, a fully managed agreement should include round-the-clock help desk access, patch and vulnerability management across your endpoints and servers, baseline endpoint security (not just antivirus, but managed detection on every device), and a recurring technology review, not a one-time onboarding call, but a standing checkpoint on what's working and what isn't.

Higher tiers layer on top of that base rather than replacing it. In Halian's structure, for example, the Growth tier keeps everything in Essentials and adds 24/7 SOC-backed threat response, cloud and infrastructure management, and backup and disaster recovery as standard inclusions rather than paid add-ons. Enterprise engagements add a dedicated account team, negotiated SLAs, and compliance or audit support on top of that. The point of a tiered structure isn't upsell, it's letting you match coverage depth to your actual regulatory and operational exposure instead of paying enterprise rates for a five-person office, or under-buying coverage for a business that's outgrown the basics.

Response times matter more than the price per user

A $10/user difference between two providers is easy to compare. A response-time commitment is the number that actually determines what a bad day costs you, and it's the one most proposals leave vague. Response time should be tied to severity, not treated as one flat number for every ticket:

  • Critical / Severity 1 (full outage, active security incident, ransomware, anything stopping the whole business from working): response begins within 15 minutes, any hour, any day.
  • Standard priority (a single user blocked, a non-urgent request, a configuration change): response within 4 business hours.

Notice the distinction: "response" is not "resolution." A 15-minute response commitment means an engineer is actively working the problem within 15 minutes, not that the outage is fixed in 15 minutes. Any agreement that blurs that distinction, or doesn't define severity levels at all, is one you should ask harder questions about before signing.

What's usually not included, and that's normal

A managed IT agreement covers the ongoing operation and security of what you already have, not the cost of getting new things. Net-new hardware purchases, a full office move, structured cabling for a new location, or a large-scale cloud migration are typically scoped and billed as separate projects, because they have a defined start and end date rather than being ongoing. That's not a provider padding the invoice, it's the difference between an operating expense and a capital project, and a legitimate agreement should say so explicitly instead of leaving it to be discovered mid-project.

Contract terms: why the commitment length matters as much as the scope

Many MSPs require a 12- to 36-month lock-in, partly because it protects their margin on the upfront onboarding work. Halian runs on month-to-month agreements instead. It's a deliberate trade: no long contract to renegotiate out of if the fit isn't right, and no incentive on our side to coast on a locked-in client. If a provider needs a multi-year commitment to make their numbers work, that's worth understanding before you sign, not after.

The price per user tells you what it costs. The response-time commitment and the contract term tell you what you're actually protected against.

Questions worth asking before you sign

  • What's the response-time commitment for a critical issue, in writing, not "as soon as possible"?
  • Is security monitoring included in the base tier, or is it a paid add-on?
  • What's explicitly excluded, and how is out-of-scope work priced and approved?
  • What's the minimum commitment length, and what does it cost to leave early?
  • Who escalates to whom if the first response doesn't resolve it?

The scope is the product, the price is just how it's packaged

Two managed IT quotes that look identical on price can cover completely different amounts of actual protection. Before comparing numbers, compare scopes: what's in the base tier, what response times are actually committed in writing, what's excluded, and how long you're locked in. Get those four answers first, and the price comparison becomes a lot easier to make honestly.

Not sure which tier of coverage your business actually needs?

Take our free IT Readiness Assessment and get a grounded recommendation based on your team size, current setup, and risk profile, no sales pressure attached.

Take the Free IT Assessment
Managed IT Pricing Contracts