For most of the last two decades, the conversation about IT operations was framed as a binary choice. Build an internal team, or outsource to a managed services provider. Pick one. The choice carried implications about cost, control, culture, and capability, and IT leaders on both sides of the question often defended their answer like a religious conviction.
That binary is breaking down, and the model replacing it — co-managed IT — is producing some of the most effective IT operations setups in the small and mid-market. The catch is that co-managed IT only works when both sides understand what they are signing up for. Done well, it gives internal teams genuine leverage. Done poorly, it produces confusion, duplicated effort, and the kind of finger-pointing that makes every incident worse.
This article is for IT leaders and service desk managers thinking about whether a co-managed arrangement makes sense for their organization, and how to structure one that actually works.
What Co-Managed IT Is — and What It Is Not
Co-managed IT is the formal partnership between an internal IT team and an external managed services provider, where each side owns clearly defined responsibilities and collaborates on shared ones. It is not outsourcing with a friendlier label, and it is not a staff augmentation contract dressed up in nicer language.
The core idea is that the internal team retains ownership of the things that benefit from institutional knowledge — business systems, user relationships, strategic projects, vendor management — while the MSP brings the things that are expensive or impractical to build internally: 24/7 monitoring, after-hours coverage, specialized security tooling, depth of expertise across technologies the internal team only touches occasionally, and the operational discipline that comes from running the same playbooks across dozens of clients.
The arrangements that fail tend to fail for one of two reasons. Either the boundaries between internal and external responsibilities are never clearly defined, or one side quietly assumes the other is handling something neither one actually is. Both failure modes are preventable, but only with deliberate setup.
The Responsibilities That Co-Managed Setups Usually Split Well
A few categories show up consistently in successful co-managed agreements:
Tier 1 service desk. The MSP handles high-volume, low-complexity tickets — password resets, basic application support, common how-to questions — freeing the internal team to focus on issues that require business context.
After-hours and overflow coverage. The internal team works business hours; the MSP covers nights, weekends, and holidays, plus surge capacity during peak periods.
Security operations and monitoring. Endpoint detection, SIEM, threat hunting, and incident response benefit enormously from the specialized tooling and 24/7 staffing that MSPs amortize across their client base.
Patch management and routine maintenance. Standardized, well-documented, and automatable — exactly what an MSP’s tooling is built for.
Specialized projects. Cloud migrations, security audits, infrastructure refreshes, compliance work. These benefit from MSP depth without justifying a full-time internal hire.
Backup and disaster recovery operations. Tooling, testing, and documented runbooks are areas where MSPs typically have a maturity advantage.
The Responsibilities Internal Teams Should Almost Always Keep
The flip side matters just as much. There are responsibilities that should generally stay with the internal team, regardless of how capable the MSP is:
Business systems ownership. ERPs, line-of-business applications, and anything that requires deep understanding of how the company actually operates.
User relationships and culture. Internal IT staff who know individual users, departments, and political realities will always do this better than external resources.
Strategic technology planning. The roadmap, the budget, the prioritization conversations with leadership. The MSP can inform these; they should not own them.
Vendor management for strategic suppliers. The internal team should be the primary relationship with major vendors, even when the MSP handles day-to-day administration.
What Makes the Partnership Actually Work
The mechanics of a successful co-managed relationship come down to a few non-negotiables:
- A documented responsibility matrix (RACI or equivalent) that both sides have signed off on
- Shared tooling visibility — the internal team should be able to see what the MSP sees, including ticket data, monitoring alerts, and asset inventory
- Regular operational cadence, typically a weekly tactical sync and a quarterly business review
- A clear escalation path with named contacts on both sides
- Transparent communication when something falls in a gray zone — handled in the moment, then formalized in the responsibility matrix afterward
The single biggest predictor of success is whether the MSP treats the internal team as the primary customer relationship. If the MSP positions itself as the senior partner trying to displace the internal team, the arrangement will deteriorate. If the MSP positions itself as the internal team’s force multiplier, it tends to last for years.
When Co-Managed Is the Wrong Answer
Co-managed IT is not the right answer for every situation. Organizations with very small or very large IT footprints often do better with one model or the other. A two-person company does not need the overhead of a co-managed structure. A 5,000-employee enterprise with a mature internal IT organization typically only needs MSPs for specialized engagements rather than ongoing co-management.
The sweet spot is the organization with one to five internal IT staff that needs depth, coverage, and tooling beyond what that team can practically deliver alone — and where the internal team is strong enough to lead the relationship rather than be overwhelmed by it.
For IT leaders evaluating whether their organization fits that profile, the most important conversations are internal: what the team is good at, what consistently falls through the cracks, and where leverage from an external partner would actually create breathing room. Once those answers are clear, structured guidance on co-managed IT support models becomes a useful reference for what to expect from a properly run partnership.
The Bottom Line for IT Leaders
The future of mid-market IT operations is not a battle between internal teams and MSPs. It is the partnership between them. The IT leaders who figure out how to structure that partnership well — with clear boundaries, shared tooling, and genuine collaboration — are building operations that consistently outperform both pure-internal and pure-outsourced peers.
The work of setting up a good co-managed relationship is non-trivial. The payoff, for teams that get it right, is an IT function that finally has the coverage, expertise, and operational maturity that the business actually needs — without the internal team being displaced in the process. For practitioners building toward that standard, frameworks like ITIL 4’s service value system provide useful structure for thinking through where internal and external responsibilities should land.