Blog

What Is Co-Managed IT Support, and How Does It Work?

27 July 2026
What Is Co-Managed IT Support, and How Does It Work? - Post Image

Co-managed IT support means your internal team keeps ownership of your environment, while a provider extends it in specific, defined areas.

Last updated: 22nd July 2026

Author: Karen O’ Connor, General Manager, IT Services & Solutions, Datapac

Organisations usually turn to this model for one of two reasons, sometimes both:

  • A team that has the right skills but not enough time
  • A team that’s extended in an area it doesn’t have deep expertise in (security, cloud, or infrastructure, for example).

Either way, the shape of the arrangement is the same. Your team decides what stays theirs, and a provider fills in the rest.

What is Co-Managed IT Support

Co-managed IT support isn’t really a category on its own so much as the middle point on a spectrum. At one end sits reactive IT support, help when something breaks, with no ongoing ownership of the environment. At the other end sits fully managed IT services, where a provider takes on proactive monitoring, maintenance, and strategic planning across the whole environment. Co-managed sits between the two. Your team continues to directly operate and make day-to-day decisions on the areas it keeps, and a provider does the same for specific, defined parts elsewhere. For a fuller breakdown of the first two points on that spectrum, see our guide to managed IT services vs IT support.

What Typically Stays Internal, and What Extends to a Partner

There’s no formal standard governing how responsibility divides in a co-managed arrangement, however here are some examples of tasks and responsibilities, some of which will typically remain internal, and some of which are commonly extended to a partner:

 

Typically stays internal Typically extends to a partner
Strategic planning and the technology roadmap* 24/7 monitoring and after-hours coverage
Vendor relationships and contract negotiation Patch management
Major project leadership and budget decisions Specialist cyber security engagements and expertise
Institutional knowledge and business context Routine helpdesk ticket volume

*This will largely depend on the organisation. For organisations with established technology capability and leadership, this responsibility typically stays with them. For those with less mature capabilities, the IT provider can step in and provide this strategic support.

Institutional knowledge (why a system was configured a certain way, who to call when something unusual comes up) stay internal here because there’s already a team in place that owns them. That’s different from a fully managed relationship without a substantial internal team, where a provider often drives the technology roadmap directly, since nobody else is positioned to own that role. In co-managed, the internal team already fills it, which is exactly why it stays where it is.

Vendor relationships can commonly remain internal because contracts get signed with the organisation, not the provider. However, once again, this point can depend on the capability of the organisation, and some may extend vendor management and coordination to their IT provider’s scope of responsibilities.

Day-to-day user support can, once again, be variable. Some organisations keep it internal deliberately, since first-line support benefits from knowing the people and the business. Others extend it, precisely because high ticket volume is exactly the kind of routine, repeatable work that frees the most internal time once it moves elsewhere. Neither is more correct. It depends on whether your team’s time is better spent answering tickets or on the higher-value work that ticket volume is currently crowding out.

How Co-Managed IT Support Works

With co-managed IT support, it’s important to consider the mechanics of the arrangement, namely how a provider gets enough access to be useful without effectively taking over.

Granting Systems Access

Done properly, access is granted for the specific task at hand and expires automatically once it’s done, rather than sitting open indefinitely. That’s not red tape slowing things down, it’s what makes the arrangement work: your team can say yes to real, meaningful access without having to take it on faith that it’s only ever being used the way it’s supposed to be. Every action is logged against the task it was granted for, so there’s a clear record rather than a general assumption of trust.

For organisations that want tighter control again, more advanced Privileged Access Management can also be added on request, giving your team visibility over administrative activity down to the individual login, beyond the task-level access described above. This tends to matter most for organisations in regulated industries or with particularly sensitive environments, where visibility into access needs to go further than the default arrangement.

Reporting

Reporting works on the same principle: specific rather than merely reassuring. A properly run co-managed relationship reports against the actual split of responsibility agreed at the outset, which could include:

  • Patch compliance across the devices the provider has responsibility over
  • Monitoring alerts and how quickly they were resolved
  • Ticket volume and the tier and categories of issues coming through
  • Any security incidents along with the accompanying remediation

That’s meaningfully different from a general “everything’s fine” update, since it gives your team something concrete to check against what was actually agreed, rather than taking the provider’s word for it.

Formal Review

There’s usually a periodic review too, quarterly is common, where a named point of contact on the provider’s side sits down with your team to look at what’s working, what isn’t, and whether the split of responsibility still makes sense as your environment changes. This is also the natural point to revisit anything that’s ended up in a grey area since the last review, rather than letting ambiguity sit unresolved until it causes a problem.

When Co-Managed IT Support Makes Sense

A handful of situations tend to point toward co-managed support specifically, rather than reactive support or full managed IT services:

A capable team without enough time. Your team has the skills to do the work well, but routine tasks, monitoring, patching, ticket volume, are consuming time that would be better spent on the initiatives that actually move the organisation forward. The goal here is extending capacity, not expertise.

A genuine, ongoing skills gap in a specific area. Your team is strong generally but doesn’t have deep expertise in one or more particular areas. For co-managed IT support to be the best solution, this expertise gap will typically be ongoing. If the gap is really a single, time-boxed project, contract recruitment is often the simpler answer. Co-managed support fits when the need doesn’t have a natural end date: security threats don’t stop evolving once a project wraps, for example, and someone brought in project by project never builds the same standing familiarity with your environment that an ongoing co-managed relationship does.

Rapid growth outpacing internal capacity. As an organisation scales, technology demands usually grow faster than a small internal team can keep up with unaided, without necessarily justifying a much larger internal department yet.

Reducing single-point-of-failure risk. When most of the institutional knowledge about an environment sits with one or two people, their absence, a holiday, an illness, or someone leaving, becomes a real continuity risk. A co-managed arrangement means documented systems and a wider team stand behind that knowledge, not just the individuals who happen to hold it.

If you’re considering co-managed IT support to augment your team’s capabilities, please don’t hesitate to reach out. Our specialists are more than willing to talk you though what you need.

Frequently Asked Questions

Can a co-managed arrangement change over time?

Yes, and it usually should. As an internal team’s capacity or skills evolve, or as the organisation grows, the split of responsibility is normally revisited rather than fixed permanently at the start.

Do we need a full IT department to consider co-managed support?

No. It works just as well with a single IT generalist as with a larger team. The amount extended to a provider simply adjusts to match how much support already exists internally.

How is co-managed IT different from contract recruitment?

Contract recruitment places an individual under your direct day-to-day direction for a defined period, useful for a specific project or a skills gap with a clear end date. Co-managed support is an ongoing service relationship with a provider, not an individual, built around a persistent, defined area of ownership rather than temporary headcount.