Managed IT is often sold as a list of technologies. The thing being bought is closer to a department: people who answer the phone, and someone above them who owns where all of it is going.
A person, by name
Every account has an adviser who knows the business and is reachable without opening a ticket. That is standard here, not an upgrade.
Who answers, and when
A security alert at any hour of the night reaches an analyst on shift at that hour. Your team at their desks reaches our help desk, which commits to fifteen minutes during weekday hours. A different set of people answers each one.
One monthly figure
Agreed before the work starts and held for the term. Projects are quoted separately and never surprise you inside a support bill.
Standards by default
Encryption, multifactor, patching, backup and monitoring go on every machine we manage. There is no tier where those come off.
The scope
Eight jobs we take off your desk
Open the ones you are unsure about. Each says what we do and where the line sits, so you can hold this next to a proposal from someone else and compare like for like.
The help desk your people call
Phone, email or the portal, whichever your team will use. Staffed weekdays from 5:00 AM to 6:00 PM Pacific, which covers a Portland start and a late Bay Area afternoon on the same shift. Tickets are picked up by a person inside fifteen minutes, and the same small group works your account often enough to recognize your file names.
An adviser and a plan you can read
Your adviser meets you on a schedule you set, brings the equipment that is aging out and the risks worth spending on this year. The output is a short written plan with dates and figures against it, in language you could hand to a board.
Patching and the unglamorous maintenance
Operating systems, browsers, the third-party software that never prompts anyone, firmware on the equipment at the edge of the network. Failures are chased until they clear rather than logged and forgotten. Disk health, certificate expiry and license renewals are watched on the same schedule.
Identity, access and joiners and leavers
Multifactor on every account, administrator rights granted for a task and taken back after, and a documented path for a new hire on day one and a departure the same afternoon. Most breaches start with a working login, so this is the part we are strictest about.
Backup, and a restore somebody has timed
Servers, workstations and the Microsoft 365 tenant, with a copy nobody can delete. The number that matters is how long a full restore takes, and that gets measured on your equipment and written down. The recovery page covers the plan behind it.
Monitoring and overnight cover
Endpoints, identity, mail flow and backups report in continuously, and a security operations center is on shift at every hour. We name the partner behind that shift openly on the monitoring page, along with what raises an alert and who picks it up at three in the morning.
Equipment, buying it and retiring it
A live inventory with warranty and age against every machine, and a refresh schedule you can budget from. Specification advice comes from people who know what your software wants. Machines are built, encrypted and enrolled before they reach the person using them.
Sitting on hold with your vendors
Internet circuits, phone systems, the design or accounting package your work depends on. We hold the account details and stay on the case until it closes. Your staff should be describing the problem once, to us, and then hearing back.
The commitment
What we sign up to, and what we do not
Response time is the promise most providers are vaguest about, because a single number has to cover a printer and a ransomware detonation. Two different jobs sit behind that number, handled by two different sets of people. Only one of them carries a clock.
1
Overnight
A critical security alert
Every night of the year · partner security operations center
Somebody on the security shift picks it up at whatever hour it fires. Their job is triage and containment before anyone starts a conversation, and then somebody phones you, working down a contact list agreed before anything happened. We put no minute figure on that one, because the promise is not ours to make.
2
The clock
A support ticket
Weekdays 5:00 AM to 6:00 PM Pacific · our own help desk
Fifteen minutes to first response, written into the agreement, from the same small group who work your account week to week. First response means a person who has read it and started on it, never an automated receipt. Outside those hours an emergency reaches the on-call engineer.
What we do not claim. Our help desk is not staffed overnight. Monitoring runs around the clock and the security shift is covered at every hour, but a password reset at 2:00 AM waits until morning unless it is an emergency. Any provider our size claiming their own help desk answers all night is worth one follow-up question: who answers at 2:00 AM, and do they work for the provider or for an answering service?
Getting started
What the first sixty days look like
Switching providers is the part that worries people, and reasonably so. Here is the sequence, so you can hold anyone to it.
Week one: take custody, break nothing
Administrative control of the tenant, the domain and the network moves to accounts you own, with the outgoing provider's access removed on an agreed date. Monitoring and backup go on first. Your people get one email telling them how to reach us, and the number to call if the email does not work.
Weeks two to four: find out what you have
Every machine, account, license, circuit and vendor contract gets found and written down, including the server in a closet nobody mentions and the subscription still billing a person who left in 2023. Most firms are paying for something they stopped using, and this is where it surfaces.
Days thirty to sixty: to standard, and the first real plan
Multifactor everywhere it is missing, local administrator rights removed, disk encryption on and the keys held somewhere you can reach them, patching caught up, and a first restore run end to end and timed. Anything that cannot be fixed inside the monthly fee gets quoted, with the risk of leaving it stated plainly. By day sixty your adviser brings the first costed schedule, covering the next twelve to twenty-four months, built from your own inventory and ticket history.
Named partners
Three ways this has gone for people
9 to 1
Servers at Dean Lewis Associates, consolidated down to a single box. Between twenty-five and thirty thousand dollars a year stopped going out the door.
2006
The year EnviroComp started working with us. Two decades is a long time to keep being the right answer, and it is the number we would look at first if we were buying this.
5.0
On Clutch, from Lyncon Construction. Jacob Bergstrom, Operator: “The most impressive thing about them is that every single person there is cool, nice, and good at their job.”
Where the line sits
Custom software development, and anything that needs a developer on your codebase. Line-of-business applications where the vendor holds the keys, though we will hold the account and chase them. Physical cabling and construction work, which we specify and manage but subcontract. Anything a license does not cover, because we will not run software you have not paid for. If a firm tells you all of that is included, ask which of it they have done this year.
Common questions
What does it cost?
A monthly figure driven mainly by how many people you have and what shape the environment is in when we take it over. The figure is fixed for the term, and project work is quoted on its own so it never turns up inside a support bill. The fastest route to a real number is the assessment, which puts a price on the gaps as well as on the service.
Can you take over without downtime?
Yes, and the sequence above is how. Nothing gets changed in week one except who holds the keys and what is being watched. The risky part of a handover is losing administrative access to something nobody documented, so we take custody first and go looking second. Where the outgoing provider is uncooperative, say so early and we will plan around it.
We already have an IT person. Does this replace them?
No. Where there is an internal person or team, the arrangement is co-managed: they keep the work they are good at and the relationships they own, and we carry the overnight cover, the tooling, the escalation and the vacation weeks. Firms usually come to us for the parts that do not fit in one person's calendar.
Do you come on site?
Yes, across the Bay Area, and in the Portland and Vancouver corridor. Most work is done remotely because it is faster for you, but equipment, cabling, a move, a new floor or a problem nobody can reproduce over a screen share are all reasons to be in the building. Site visits are part of the agreement, not a separate line.
Can we buy only part of this?
Some of it. Monitoring, backup and the security work can stand alone, and plenty of firms start there. What we will not do is manage machines with the encryption, multifactor or patching turned off to reach a lower number, because then we are being paid to watch something we were not allowed to protect.
How do we know it is working?
By the things that stop happening. Fewer tickets from the same machine, patching that no longer needs chasing, a restore that has been timed on your equipment, and a plan whose dates have been met. Your adviser brings those to the review, including the ones that went badly, because a report with nothing awkward in it is a report nobody read.
Start with fifteen minutes about the business
Not an audit and not a pitch. We want to understand what the firm is trying to do this year, and then we can be useful about where technology is costing you money, holding people up, or carrying a risk you have not priced.