Buyer Guide · 2026

Co-managed IT: when to keep internal IT and when to let go

How co-managed IT actually works, which company profiles benefit most, how to divide responsibilities cleanly, and what to nail down in the contract before you hand a single ticket to an outside provider.

Quick answer

Co-managed IT splits responsibilities between your internal team and an MSP: staff keep day-to-day support and business knowledge, while the provider supplies 24/7 monitoring, security operations, tooling, and surge capacity. It costs $40 to $100 per user per month and suits most 50- to 250-employee firms.

Start here

What co-managed IT actually is

Co-managed IT is a partnership in which your internal IT staff and a managed service provider run your technology together, dividing the work by design rather than handing all of it to one side. Your employees keep what benefits from dedication and context; the MSP supplies the capabilities that are hard, expensive, or impossible to staff in-house. It is augmentation, not replacement.

That distinction is the whole point. A fully managed arrangement outsources the entire IT function to an MSP; break-fix calls someone only when something is already broken. Co-managed sits between them: you keep an internal team and add an MSP’s bench, tooling, and 24/7 coverage on top, with a clear line down the middle of who owns what. Done well, you get the dedication of employees and the breadth of a provider at the same time.

If you are still deciding between building a team, outsourcing entirely, or blending the two, start with our companion guide on MSP vs internal IT, which compares the three models head-to-head. This guide assumes you are leaning toward the hybrid and want to know how to make it work in practice.

The one-sentence definition

Co-managed IT means your team and an MSP share the same environment and tools, split responsibilities in writing, and stay accountable for different parts of the same outcome — so coverage is broader and deeper than either could deliver alone.

The mechanics

How a co-managed relationship works day to day

A healthy co-managed setup is not two teams working in parallel and hoping they do not collide. It runs on shared tools, an agreed split, and clear handoffs. These are the six mechanics that make it function.

  • Shared tooling. Both teams work inside the same remote monitoring and management (RMM), ticketing (PSA), and security platforms, so there is a single view of the environment rather than two disconnected ones.
  • A written responsibility split. Every major function is assigned to internal, the MSP, or shared — documented up front so nothing is assumed and nothing is dropped.
  • Ticket routing and escalation. Internal staff handle first-line and in-person issues, and escalate to the MSP’s engineers by defined rules when a problem exceeds their time or expertise.
  • After-hours handoff. Outside business hours, monitoring and response pass to the MSP’s network and security operations centers, so coverage never depends on one person’s phone.
  • A regular cadence. Recurring syncs and a periodic strategy review with a vCIO keep both sides aligned on priorities, projects, and roadmap.
  • Continuous documentation. Runbooks and asset records are kept current by both teams, so knowledge lives in the system rather than in one employee’s head.

The throughline is a single source of truth. When both teams share tools and documentation and route work by rule, the customer experience is seamless even though two organizations are involved. When they do not, co-managed degrades into finger-pointing — which is exactly what the pitfalls section below is about.

The payoff

Why companies choose co-managed

Co-managed solves a specific problem: a capable internal team that cannot realistically cover everything modern IT now demands. These are the six benefits that draw businesses to the model.

1

24/7 coverage without burnout

The MSP takes nights, weekends, and holidays, so your team is not permanently on call. This alone resolves the single biggest cause of internal IT turnover.

2

Real security operations

A 24/7 SOC with SIEM and MDR is almost impossible for a small team to staff. Handing security operations to the MSP closes the gap insurers and auditors now require.

3

Surge and project capacity

Migrations, rollouts, and office moves overwhelm a lean team. The MSP’s bench absorbs the spike without you hiring for a temporary peak.

4

Specialist depth on demand

Cloud, network, and compliance specialists you could never justify as full-time hires become available the moment a problem needs them.

5

Enterprise tooling, shared cost

RMM, PSA, EDR, and SIEM platforms come with the engagement, so you get an enterprise toolset without buying and maintaining each license yourself.

6

Retention and continuity

Your staff focus on higher-value, business-facing work while the MSP absorbs the grind — and if an employee leaves, the MSP’s documented coverage keeps the lights on.

The right fit

Which company profiles benefit most

Co-managed is not for everyone. It shines for organizations large enough to want internal staff but not large enough to fully self-staff every discipline. If you recognize your business in the table below, the model is likely a strong fit.

Company profileWhy co-managed fits
50–250 employeesToo big for a pure MSP relationship, too small to justify a full internal department
A lean team of 1–3 IT staffAdds 24/7 coverage, security, and bench depth without adding headcount
Compliance-heavy (HIPAA, CMMC, SOC 2)Internal keeps business context; the MSP supplies the SOC and audit evidence
Multi-site or distributed workforceThe MSP covers remote and after-hours while staff handle the primary location
Fast-growingElastic capacity carries you through scaling before the next internal hire lands
Cannot recruit or retain senior talentRents specialist skills a tight or rural labor market cannot supply
Strong generalists, thin on securityThe MSP fills the specific security and SOC gap without displacing the team

The common thread is a team that is good but stretched. If your internal staff are constantly firefighting, perpetually on call, or strong on your applications but light on security, co-managed adds exactly the missing layer. For a fuller view of how this maps against company size, see the by-size guidance in our MSP vs internal IT guide.

The division of labor

How to split responsibilities cleanly

The success of co-managed lives or dies on a clear division of labor. The guiding principle is simple: internal keeps what rewards proximity and context; the MSP takes what rewards scale, tooling, and round-the-clock staffing. The table below shows how that typically lands — treat it as a starting template, then put your own version in writing.

IT functionTypically internalTypically the MSP
Tier 1 helpdesk & floor supportOwns it — fast, in-person, knows the peopleAfter-hours and overflow
Tier 2/3 escalation & engineeringSharedDeep bench for the hard problems
24/7 monitoring & NOCOwns it
Security operations (SOC, SIEM, MDR)Owns it
Patching, RMM & endpoint managementCo-managed on the shared platformProvides and runs the platform
Backup, DR & continuityOversightExecutes and tests recovery
Strategy, budgeting & vendor managementInternal lead / vCIO owns itAdvisory and benchmarking
Line-of-business apps & institutional knowledgeOwns it
Projects, migrations & surgeCo-managedSupplies bench capacity
Compliance documentation & evidenceCo-managedSpecialist support

Two rules keep the split honest. First, every function must have a single accountable owner — “shared” means shared execution, never shared accountability, or it becomes nobody’s job. Second, write it down: a documented responsibility matrix in the contract is what prevents the gaps and overlaps that quietly sink co-managed relationships.

The options

Co-managed engagement models

Co-managed is not one fixed package. Providers offer it along a spectrum, from handing off a single discipline to a broad partnership across daily operations, security, and strategy. Pick the model that fills your specific gap rather than buying more than you need.

ModelHow it worksBest for
After-hours / overflowThe MSP handles nights, weekends, and ticket spikes onlyA solid team covering business hours but burning out on call
Security-only (MDR + SOC)The MSP owns security operations; internal keeps everything elseA strong IT team with a specific security and monitoring gap
Tooling & platformThe MSP supplies the RMM, PSA, and security stack your team operatesTeams lacking the budget to license enterprise tooling alone
Project & bench augmentationThe MSP supplies specialists for migrations and surges as neededLean teams facing large one-off projects without the staff to run them
Full co-managedA broad split across daily ops, security, tooling, and strategyMid-market firms formalizing the hybrid as their long-term model

Most relationships start narrow and widen over time. A common path is to begin with security-only or after-hours coverage to solve the most painful gap, prove the partnership works, then expand the split as trust builds. There is no obligation to hand over everything at once — and a good provider will not pressure you to.

The investment

What co-managed IT costs

Co-managed sits on top of your existing internal payroll, so think of it as an add-on rather than a replacement cost. Because the MSP is augmenting your team instead of running everything, it is meaningfully cheaper per user than full outsourcing. These are typical 2026 ranges, not quotes.

Co-managed serviceTypical 2026 rangeNotes
Co-managed IT (per user)$40–$100 / user / moThe broad partnership rate, on top of internal payroll
Security-only / MDR + SOC$10–$60 / user / moWhen you hand off only security operations
Monitoring / RMM platform$10–$50 / user / moTooling plus after-hours monitoring, per service
vCIO / vCISO advisory$1,500–$5,000 / moThe strategy and roadmap layer; sometimes bundled in
One-time onboarding1–3× monthly feeSetup, documentation, and deploying shared tooling

For comparison, fully managed IT — where the MSP runs everything and you keep no internal staff — typically runs $75 to $200 per user per month. Co-managed lands lower per user precisely because you are still paying internal salaries alongside it; the right way to judge the total is internal payroll plus the co-managed fee versus the all-in cost of either pure model. The full set of pricing models is in our MSP pricing guide.

Before you sign

The co-managed contract checklist

A co-managed contract has to do something a fully managed contract does not: define a boundary between two teams. Get these terms in writing before you split responsibilities, and most of the model’s failure modes never get a chance to appear.

  • A written responsibility matrix. Every major function mapped to internal, MSP, or shared, with a single accountable owner each. This is the single most important clause.
  • Escalation paths and response SLAs. Defined rules for when and how work moves between teams, with guaranteed response and resolution times, not marketing language.
  • Tool ownership and access. Clarity on who owns the RMM, PSA, and security tenants, and confirmation that you retain admin access and your own Microsoft 365 and security credentials.
  • Documentation and knowledge transfer. A requirement that runbooks and asset records stay current and accessible to both teams, so neither side becomes a single point of failure.
  • The security responsibility boundary. An explicit line on who owns the SOC, incident response, and each control, so security is neither doubled up nor dropped.
  • Pricing model and scope changes. How you are billed, what counts as in-scope, and how adding or removing a discipline changes the fee.
  • Exit and transition terms. How the relationship unwinds — data export, credential handover, and documentation — without holding your environment hostage.

For the broader vendor-selection process — references, track record, and overall fit beyond these co-managed specifics — pair this checklist with our guide on how to choose an MSP and the six-factor Trust Score methodology behind every provider we rank.

The judgment call

When to keep internal IT, and when to let it go

Co-managed forces a useful question for every function: keep it in-house, or let the MSP take it? The answer is rarely all-or-nothing. Use these two checklists to decide where each responsibility belongs.

Keep it internal when

  • It depends on deep knowledge of your business, people, or proprietary applications.
  • It needs an immediate, in-person, physical response that remote support cannot give.
  • It is core strategy — budgeting, roadmap, and vendor relationships you want to own.
  • Your team already does it well and it is not a source of burnout or risk.

Let the MSP take it when

  • It requires 24/7 staffing your team cannot sustain without burning out.
  • It is specialized — a SOC, SIEM, or compliance work that is hard to hire for.
  • It is a one-time surge, like a migration, that does not justify a permanent hire.
  • It currently rests on a single employee, creating an obvious continuity risk.

There is also a point where co-managed is no longer the answer. If your internal team shrinks to the point where it is mostly coordinating the MSP anyway, fully managed is often simpler and cheaper. If you grow large enough to fully staff every discipline in-house, you may bring more back internally — though most organizations keep the MSP for security operations even then. Co-managed is a model to grow with, and to revisit as your size and needs change.

Watch out

Co-managed pitfalls

Co-managed fails in predictable ways, and nearly all of them trace back to an unclear boundary between the two teams. Avoid these and the model tends to work.

  • Fuzzy scope. If the responsibility split is vague, work falls through the cracks — each team assumes the other has it. A written matrix is the cure.
  • Two teams, two toolsets. Separate RMM and ticketing systems mean no single source of truth and constant reconciliation. Share the platform or expect friction.
  • No single accountable owner. When “shared” means nobody is ultimately responsible for an outcome, problems linger between the teams.
  • Treating the MSP as just hands. A provider managed as disposable labor never invests in your environment. The relationship works best as a genuine partnership.
  • A territorial internal team. If staff feel threatened and withhold access or knowledge, the MSP cannot do its job. Position co-managed as support, not a threat to anyone’s role.
  • A blurred security boundary. If neither side clearly owns the SOC and incident response, security gets doubled up or, worse, dropped entirely. Name the owner explicitly.

Questions

Co-managed IT FAQs

Co-managed IT is a partnership in which your internal IT staff and a managed service provider run your technology together, dividing responsibilities by design. Your team keeps the work that benefits from dedication and context — day-to-day support, line-of-business applications, and strategy — while the MSP supplies what is hard to staff in-house, such as 24/7 monitoring, security operations, enterprise tooling, and surge capacity.

It is augmentation rather than replacement: the MSP adds a bench and round-the-clock coverage on top of your existing team, not instead of it.

Fully managed IT outsources the entire IT function to an MSP, often with no internal staff at all. Co-managed keeps your internal team and adds the MSP’s capabilities alongside them, with a written split of who owns what. Break-fix, a third model, only engages a provider after something has already broken.

The practical difference is control and context. Fully managed is simpler and usually cheaper for small businesses; co-managed preserves in-house knowledge and immediacy while filling the gaps an internal team cannot cover. Our MSP vs internal IT guide compares all three models in depth.

Co-managed fits best for organizations of roughly 50 to 250 employees with a lean internal team of one to three IT staff. That profile is too large for a pure MSP relationship but too small to fully staff every discipline — helpdesk, engineering, security, and strategy — in-house.

It is also a strong fit for compliance-heavy, multi-site, or fast-growing businesses, and for any company that struggles to recruit or retain senior IT talent. If your team is capable but constantly stretched, the model usually pays off.

The guiding principle is that internal staff keep what rewards proximity and context, while the MSP takes what rewards scale, tooling, and round-the-clock staffing. In practice, internal usually owns tier-1 helpdesk, line-of-business apps, institutional knowledge, and strategy, while the MSP owns 24/7 monitoring, the security operations center, the tooling platform, and surge capacity. Escalation, patching, and projects are commonly shared.

Whatever split you choose, give every function a single accountable owner and put the whole matrix in writing. “Shared” should mean shared execution, never shared accountability.

Co-managed IT typically runs $40 to $100 per user per month on top of your internal payroll, because the MSP is augmenting your team rather than replacing it. Narrower engagements cost less: security-only with MDR and a SOC is roughly $10 to $60 per user per month, and a monitoring or tooling platform around $10 to $50. A vCIO or vCISO advisory layer adds about $1,500 to $5,000 per month, and a one-time onboarding fee of one to three times the monthly rate is standard.

For comparison, fully managed IT runs $75 to $200 per user per month. See the MSP pricing guide for the full breakdown.

No — that is the defining feature of the model. Co-managed is built to augment your team, not replace it. The MSP takes on the work that is hard to staff in-house, such as 24/7 coverage and security operations, so your staff can focus on higher-value, business-facing work rather than being buried in alerts and after-hours tickets.

In practice, co-managed often improves IT retention, because it removes the burnout and single-point-of-failure pressure that drives good people to leave. If your goal is to remove internal staff entirely, you are describing fully managed IT, not co-managed.

At minimum: a written responsibility matrix assigning every function a single accountable owner; escalation paths with guaranteed response and resolution SLAs; clear tool ownership with confirmation that you retain admin access and your own Microsoft 365 and security tenants; a documentation and knowledge-transfer requirement; an explicit security responsibility boundary covering the SOC and incident response; the pricing model and how scope changes are billed; and exit terms covering data export and credential handover.

The responsibility matrix is the most important clause — it is what prevents the gaps and overlaps that cause most co-managed relationships to struggle.

Consider fully managed when your internal team has shrunk to the point where it mostly coordinates the MSP rather than doing hands-on work — at that stage, full outsourcing is usually simpler and cheaper. It can also make sense if you lose your last internal IT person and replacing the role is harder than expanding the MSP’s scope.

Conversely, if you grow large enough to fully staff every discipline in-house, you may bring more work back internally, though most organizations of any size keep the MSP for security operations. Treat the model as something to revisit as your size and needs change, not a permanent decision.

Find a co-managed partner

Augment your team with the right MSP.

Browse independently scored MSPs across dozens of US cities and 20 industry verticals, including providers experienced in co-managed and security-only engagements. Every provider is measured against the same six-factor Trust Score — no paid placements.