Managed IT agreements are usually presented as standard paperwork, and most of them genuinely are. But a handful of clauses determine what happens when things go wrong — and those are the ones worth reading before signing rather than after.
What follows is what should be in the agreement, and what should give you pause.
Scope, in writing
The most important section, and the one most often vague. It should list specifically what is covered: which devices, which users, which servers, which applications, which locations.
Ambiguity here is not neutral. When scope is undefined, the definition gets decided later, during a dispute, by the party who wrote the contract.
Ask specifically how the scope changes as you grow. If you hire ten people, does the fee adjust automatically, at renewal, or by negotiation?
Exclusions, explicitly
A good agreement states what is not included as clearly as what is. Expect to see some or all of:
- Hardware and software procurement
- Licensing costs
- Project work above a defined threshold
- Third-party application support
- Cabling and physical infrastructure
- Support for personal devices
- Pre-existing issues identified during onboarding
The absence of an exclusions section is not generous. It means the boundary exists but has not been written down.
Service levels with consequences
Response time commitments should be defined by severity — a server outage and a password reset are not the same event — and each tier should have a stated target.
More importantly, ask what happens when a target is missed. A commitment with no remedy is a marketing figure. Meaningful agreements include service credits or an escalation path with defined consequences.
Be clear on the distinction between response and resolution. Most SLAs commit to the first and not the second, which is reasonable — but you should know which you are being promised.
Coverage hours and after-hours terms
Define business hours precisely, including holidays. Then establish what after-hours support means: is it included, billed at a premium, or unavailable? What is the response commitment overnight?
"24/7 monitoring" and "24/7 support" are different products and are frequently conflated in proposals. Monitoring means systems are watched. Support means a person responds. Confirm which you are buying.
Data and asset ownership
This clause matters more than any other at the end of the relationship, and almost nobody reads it at the beginning.
The agreement should state unambiguously that your business owns:
- Your data, including backups held by the provider
- Your domain registrations
- Your cloud tenants and the licences within them
- Your documentation — network diagrams, configurations, asset records
- Vendor accounts held in your name
If any of these sit under the provider's account, you have a dependency that is difficult to unwind. This is the most common cause of a painful exit, and it is entirely avoidable at signing.
Termination and offboarding
Look for four things:
- Notice period, and whether it is symmetrical. A 90-day obligation on you and 30 on them is worth questioning.
- Auto-renewal terms, and the window in which you must act. A long term that renews automatically with a short notice window is the clause most likely to trap you.
- Termination for cause — what constitutes a material breach and what your remedy is.
- A defined offboarding process: documentation handover, credential transfer, data export, and cooperation with an incoming provider. Ideally with a timeframe attached.
Ask about offboarding during the sales conversation. A provider confident in their service has no reason to make leaving difficult, and any hesitation at that question is informative.
Security and liability
- What security controls the provider commits to maintaining, on your environment and on their own access to it
- Their incident notification obligations — how quickly they tell you if they detect a compromise, or suffer one themselves
- Their insurance coverage, including cyber liability and professional indemnity
- Liability caps, which are usually limited to fees paid over some period. This is standard, but you should know the number
- Whether they will sign a Business Associate Agreement or equivalent, if you carry compliance obligations
That fourth point deserves attention. Liability is almost always capped well below the potential loss from a serious incident, which is precisely why your own cyber insurance matters and why the provider's controls are worth scrutinising rather than assuming.
Terms that should stop you
- No written scope, or scope described only in marketing language
- Automatic renewal for a multi-year term with a notice window under 60 days
- No documented offboarding process, or an explicit fee to release your own data
- Unlimited support with no fair-use definition
- Unilateral right to change fees or scope mid-term
- Provider-owned domains or tenants with no transfer provision
- Liability disclaimed entirely, including for their own negligence
Most providers will negotiate on several of these, particularly notice periods and offboarding terms. The willingness to discuss them tells you as much about the relationship as the final wording does.