Begin with the systems the business depends on
List the people, devices, email, cloud services, business applications, network equipment, website and suppliers that matter to daily work. For each one, record the owner, administrator and acceptable downtime. This turns “we need IT support” into a service requirement.
Define the support boundary
- Named users, devices and business locations
- Operating systems, Microsoft 365, email and line-of-business software
- Network, Wi-Fi, printers and third-party internet service
- Websites, domains, hosting and other digital services
- Remote, on-site and out-of-hours arrangements
- Work that remains the responsibility of another supplier
A clear boundary avoids two providers each assuming the other owns a problem.
Separate response from resolution
A response target is the time to acknowledge and begin triage; it is not a promise that every fault will be fixed in that period. Hardware failure, third-party outages, access problems and ordered parts can affect resolution. Ask how priorities are set and what information the provider needs for urgent triage.
Include prevention and recovery
Support should not consist only of waiting for faults. Decide who owns updates, user changes, account security, device records, backup monitoring and recovery tests. If those tasks are outside the plan, assign them elsewhere rather than leaving them implicit.
Keep business control of critical accounts
The business should know who owns the domain, Microsoft 365 tenant, website hosting, backup service, licences and administrator credentials. A provider may administer them, but exit and emergency access should not depend on one personal account.
Choose the appropriate commercial model
Ad-hoc support works when needs are genuinely occasional and delays are tolerable. Monthly support can add continuity and agreed service expectations. A defined project is often better for migrations, replacements and major changes. Many small organisations use a mixture.
What good handover looks like
After work, the business should understand what changed, which risks remain and what to do next. For ongoing support, maintain an appropriate record of devices, services, owners and important decisions. Documentation should be useful without exposing credentials unnecessarily.
A short supplier checklist
- Can the provider explain scope and exclusions in plain language?
- Are response arrangements realistic and written down?
- Who owns security, backups and third-party coordination?
- How are additional costs and changes approved?
- What access and documentation will the business retain on exit?
Need help applying this to your business?
Vengera can assess the current setup, explain the priorities and scope any practical improvements.