"Co-managed IT" usually gets explained as a concept, an outside partner working alongside the IT person you already have. What rarely gets explained is what that looks like in practice. Who answers the phone. Who gets the alert at 2 a.m. Who owns the vendor renewal call. Here's the operational version.
Co-managed IT is close to exactly what it sounds like. Your existing IT hire keeps their job, their relationships, and their daily routine, and an outside partner, ACT360’s Co-Managed IT Services team in this case, fills in around them. Most explanations stop right there, at the org chart, and never get to the part that actually matters to the people living it, which is the ticket queue.
If you’re trying to figure out what co-managed IT changes about a normal week at your business, the org chart isn’t where the answer lives. The answer lives in who your team calls first when something breaks, what gets escalated and to whom, and what happens the night a server throws an alert with nobody awake to see it.
This article walks through what a real co-managed engagement looks like once the paperwork is signed, including the daily split of work, how requests actually get routed, what changes in the first few months, and what a routine Tuesday looks like next to a 2 a.m. outage. For the fuller breakdown of what’s included, pricing, and who it fits best, ACT360’s Co-Managed IT Services page covers that. This one is about the mechanics.
TL;DR. In a co-managed setup, your staff keep calling the internal IT person they already know. ACT360 works in the background on after-hours monitoring, security hardening, and specialized projects, and escalations go to a named contact, Adam or Jeffrey, not a queue. Access starts small and grows with the scope. In our experience, the first specialized project lands within 60 to 90 days, and the split gets revisited at every quarterly review.
What Is Co-Managed IT, Exactly?
Co-managed IT is a shared arrangement where your internal IT hire keeps the day-to-day relationship with your staff, and an outside partner covers defined gaps, usually after-hours coverage, specialized security work, project overflow, and strategic planning your internal hire doesn’t have the bandwidth to provide alone.
It sits between two other paths. Standalone IT support is a helpdesk relationship on its own, with an outside provider as the primary contact for every request. Full Managed IT hands over the entire relationship, monitoring, security, vendor management, and strategy under one roof, usually because there’s no internal hire to begin with. Co-managed IT assumes the internal hire already exists and is good at their job. It just isn’t realistic for one person to be the only line of defense, the security specialist, the after-hours contact, and the vendor negotiator, all at the same time.
That’s part of why more growing businesses are looking at co-managed arrangements instead of a second full-time IT hire. Nearly seven in ten small businesses in Canada now say a shortage of qualified candidates in their sector is the top obstacle to hiring, according to the Canadian Federation of Independent Business. The Information and Communications Technology Council has separately projected sustained demand for digitally skilled workers in Canada that continues to outpace supply. Waiting months to fill a second IT role isn’t realistic when the gap needs covering now.
Who Handles What in a Co-Managed IT Model?
In most co-managed arrangements, your internal hire keeps daily user requests and onboarding, while the outside partner takes after-hours monitoring, security hardening, specialized projects, and vendor work. It’s rarely as clean as an org chart makes it look, so here’s how the work typically splits once it’s actually running.
| Area of Work | Usually Stays With Your Internal Hire | Usually Moves to ACT360 |
|---|---|---|
| Daily user requests (password resets, printer issues, new software installs) | Yes, this is where they already have the relationships | Backup only, when your hire is out |
| New employee onboarding and offboarding | Yes, day-to-day execution | Support on access provisioning and security review |
| After-hours monitoring and alerts | Rarely realistic for one person to own alone | Yes |
| Security hardening, patching, and vulnerability management | Only if it’s their specialty | Yes, the handoff we see most often |
| Vendor contract negotiations and renewals | Sometimes, with support | Yes, for anything specialized |
| Cloud migrations and infrastructure projects | Involved, but not leading solo | Yes, leads the project |
| Strategic planning and technology budgeting | Input, always | vCIO-style structure and roadmap |
The exact split gets confirmed during the IT Readiness Assessment, not guessed at from a template. A business with one strong generalist hire and no security specialist will scope differently than a two-person internal team that just needs after-hours coverage. If you haven’t been through one before, here’s what to expect during an IT assessment.
Who Do Employees Actually Call First?
Almost always, the same person they already call. That’s the point. Co-managed IT is built to be invisible to most of your staff, not a second helpdesk they have to figure out.
Here’s how a request typically moves through a co-managed setup.
- An employee has a problem and calls or messages your internal IT hire, the same as always.
- If it’s routine, your hire handles it directly. Nothing changes.
- If it’s outside their specialty, security-related, or happens after hours, they escalate to a named ACT360 contact, Adam or Jeffrey, not a rotating queue.
- ACT360 works the issue and reports back to your hire, who stays the point of contact for your staff.
- Anything that needs to happen outside business hours routes directly to ACT360’s after-hours coverage, so nobody’s waiting until Monday.
The one exception is anything explicitly scoped as ACT360’s to own outright, like after-hours monitoring or a specific security tool. In those cases, staff get told upfront who to call, so there’s no confusion about which door to knock on.
Behind that handoff, the ticket record matters as much as the phone call. ACT360 runs its own service delivery on Autotask, and we built a reply portal on the Autotask API so whoever picks up a ticket can see the full conversation history, and who last replied, before they respond. In a co-managed setup, that visibility is what keeps your internal hire and our team from answering the same person twice. The Autotask reply portal case study covers how it works.
What Does a Typical Week With Co-Managed IT Look Like?
Most of a typical week looks exactly like it did before, with your internal hire handling routine requests. The difference shows up midweek, when specialized work gets handed off, and after hours, when alerts route to ACT360 instead of someone’s personal phone.
Monday morning usually starts the same way it did before co-managed IT existed. Your internal hire handles the weekend’s leftover tickets, sets up a new hire’s laptop, and fields the usual run of small requests. ACT360 isn’t visible in any of it, because there’s no reason to be.
Midweek is where the difference tends to show up. Say a vendor calls about a contract renewal, or a firewall needs a configuration review nobody’s had time to do properly. That’s usually the moment your internal hire flags it to their ACT360 contact instead of either ignoring it or trying to become a security specialist overnight. The work gets scoped, scheduled around production hours or business needs, and handled without pulling your hire off their regular workload.
Thursday night, after hours, is the scenario most businesses are actually paying for, even if it rarely happens. A server throws an alert at 11 p.m. Under a co-managed arrangement, that alert routes to ACT360’s monitoring, not to your internal hire’s personal phone. Having a defined incident response path in place before an incident happens, rather than improvising one at midnight, is exactly what the Canadian Centre for Cyber Security recommends for businesses of any size. Depending on severity, the alert either gets resolved overnight or your hire gets a clear summary Friday morning instead of a surprise.
What monitoring catches isn’t always a server. On one ACT360 engagement with a 35-person contractor, identity monitoring flagged account access from 3 countries within weeks of going live, plus 1 incident serious enough to isolate an account automatically. None of it had been visible before. That client was on full Managed IT rather than co-managed, but it shows what an after-hours monitoring layer is there to catch. The details are in the painting contractor case study.
Quarterly, the pace changes again. ACT360 and your internal hire sit down for a review that isn’t about ticket counts. It’s a look at what got handled, what’s coming up, whether the current split of responsibilities still makes sense, and whether anything needs to shift as the business changes. That’s also usually when a business finds out whether it’s outgrown a co-managed arrangement and is ready for something bigger. If growth is what’s stretching your internal hire, why small businesses outgrow their first IT provider explains where that usually happens.
How Does the Handoff Start in the First 90 Days?
The handoff starts with discovery, not a cutover. ACT360 learns what your internal hire already owns well, sets up access gradually, and in our experience schedules the first specialized project somewhere in the first 60 to 90 days, once both sides know how the other works.
The first few weeks look less like a cutover and more like an interview. ACT360 spends time understanding what your internal hire already owns well before touching anything, including which systems they’re confident in, where the actual gaps are, and what’s been quietly labelled “fine” because there’s never been time to look closer.
From there, access gets set up gradually rather than all at once, typically starting with documentation and monitoring tools before anything higher-stakes changes hands. The first specialized project is often a security review or a piece of infrastructure that’s been on the back burner. The 60 to 90 day window is our own pattern across ACT360 engagements, not an industry benchmark, and a business with an urgent gap can move faster. There’s no big-bang cutover weekend, because there’s nothing to cut over. Your internal hire’s day-to-day doesn’t stop while any of this happens.
What Tools and Access Actually Get Shared?
Usually less than people expect at first, and it grows as trust and scope do. A typical starting point is shared visibility into ticketing and documentation, so nothing gets solved twice, plus access to the monitoring and security tools ACT360 runs in the background.
In the environments we work in, that usually means some combination of these.
- Microsoft 365 and Entra ID, where email, file sharing, and user identities are managed. ACT360 gets the specific admin roles the scope needs rather than blanket Global Administrator rights, in line with Microsoft’s recommendation to keep Global Administrators to fewer than 5 people.
- Endpoint protection such as Microsoft Defender or another endpoint detection and response tool, so a security alert reaches someone after hours.
- A remote monitoring and management agent on servers and workstations, which is how an 11 p.m. alert reaches ACT360 and how patching gets tracked.
- Firewall management, including configuration reviews and firmware updates your internal hire hasn’t had time for.
- Ticketing and documentation. ACT360 runs service delivery on Autotask and keeps client documentation in IT Glue, and the scope sets what your internal hire sees in each, so work history isn’t split across 2 places.
Full administrative access to every system is rarely handed over on day one. It’s scoped to whatever the engagement actually covers, and it expands only when the work calls for it. That’s the least privilege principle Microsoft describes, meaning the right permissions, over the right scope, for the right length of time. The Canadian Centre for Cyber Security’s baseline controls make the same point for small and medium organizations, listing access control and authorization among the core controls.
How Do You Know Co-Managed IT Is Actually Working?
Co-managed IT is working when your internal hire still owns the relationship with your team, after-hours issues get handled without anyone losing sleep, and specialized work that sat on a to-do list actually gets finished. A few honest signals separate that from an arrangement that’s just adding a second invoice.
It’s working when
- Your internal hire still feels like the owner of the relationship with your team, not sidelined by it.
- After-hours issues get handled without anyone losing sleep over a phone that used to ring at midnight.
- Specialized work that used to sit on a to-do list indefinitely, a migration, a security hardening project, actually gets scheduled and finished.
- Quarterly reviews surface real recommendations, not a list of closed tickets.
It’s not working when
- Nobody defined upfront who owns what, so issues get handled twice or missed entirely.
- Your internal hire feels like they’re being quietly phased out instead of backed up.
- Escalations disappear into a general queue instead of reaching a named contact.
Most of what causes the second list isn’t a flaw in the model. It’s a scoping conversation that didn’t happen clearly enough at the start, which is exactly what the assessment step is supposed to prevent.
How Does ACT360 Handle Co-Managed IT?
ACT360 runs co-managed IT on the same ACTION methodology behind every engagement, starting with what your internal hire already does well, so the scope fills real gaps instead of duplicating work. A named contact, Adam or Jeffrey, coordinates directly with your internal hire.
For a co-managed arrangement specifically, the Assess and Comprehend steps focus on your internal hire’s existing strengths, not a generic checklist. And the named contact matters more here than almost anywhere else, since the relationship between your internal hire and ACT360 is what determines whether the split actually holds up under a real incident, not just on a slide during the sales conversation.
ACT360 has served more than 2,700 Ontario businesses over 16 years, and provides day-to-day co-managed IT coverage to growing businesses across Barrie, Newmarket, Orillia, Aurora, Innisfil, Markham, and Vaughan, plus the surrounding communities across Central and Southern Ontario.
Questions About Co-Managed IT
Who does my team call when something breaks, us or ACT360?
In almost every case, your team keeps calling the same internal IT hire they already know. ACT360 works in the background unless something is explicitly scoped as an ACT360 responsibility, like after-hours monitoring or a specific security tool your staff were told about upfront. The goal is to add coverage without adding a second helpdesk your employees have to learn.
Does ACT360 show up during business hours, or only after hours?
Both, depending on what’s scoped. Most co-managed arrangements are built around after-hours coverage and specialized project work, since that’s usually the biggest gap for a single internal hire. But daytime support happens too, especially during a specific project, a security review, or whenever your internal hire needs a second set of hands on something urgent.
How long does it take before co-managed IT actually feels like it’s working?
In ACT360’s experience, most businesses notice a difference within the first 60 to 90 days, once the first specialized project gets scheduled and the after-hours coverage has been tested by a real alert. The relationship keeps maturing after that. Quarterly reviews are where the split gets adjusted as your business and your internal hire’s workload change.
What happens to our internal IT person’s daily workload once co-managed IT starts?
Their day-to-day usually looks the same at first, just with fewer things falling through the cracks. The work that shifts is the specialized or after-hours pieces they never had time for anyway, such as security hardening, vendor negotiations, and overnight monitoring. Most internal hires describe it as finally getting backup, not losing responsibility.
Can a co-managed IT arrangement change over time as our business grows?
It’s designed to. The scope gets revisited at quarterly reviews rather than locked in at signing. Some businesses stay in a co-managed arrangement indefinitely because it fits how they’re structured. Others grow into needing a fuller relationship and move toward Managed IT once their internal team can no longer realistically own the day-to-day on their own.
Is co-managed IT more expensive than just hiring a second internal IT person?
Often not, though it depends on how much coverage you need. Job Bank puts the median wage for an IT specialist in Ontario at $47.00 an hour, roughly $98,000 a year at full-time hours, and a computer network technician at $35.71, roughly $74,000, before benefits, recruiting, and training. Co-managed IT is scoped to the specific gap, so the comparison comes down to whether you need after-hours coverage, security work, or project help, and how much of each. It also doesn’t disappear when one person takes a vacation.
Final Thought
Co-managed IT works when the split is specific, the escalation path is clear, and your internal hire feels backed up instead of watched. It doesn’t work when nobody defined any of that upfront. If you’re still deciding whether the model itself is the right call for your business, not just how it runs day to day, ACT360’s breakdown of when co-managed IT makes sense and when it doesn’t is the better starting point.
If you already know co-managed IT is the direction you want to go, the next step is figuring out exactly where the gaps are. An IT Readiness Assessment is a free, no-obligation look, starting with a 30-minute conversation, at what your internal hire already handles well and where a co-managed arrangement would actually help.
Call 705-739-2281 or email [email protected]