This month we received one of the clearest IT support RFQs we have ever read. The company knew its environment, admitted what it could not verify, named its priorities, and asked for evidence instead of assurances. We declined it within an hour. The person who sent it thanked us for the honesty. See, when you evaluate an IT provider, the good ones also evaluate you.
Now, in this case, nothing was wrong with the prospect, and nothing was wrong with us. They were shopping for a configure-and-monitor arrangement with core responsibilities split between vendor and client. We fully manage every environment we take on, help desk included, and we do not split ownership of the environment itself. Different model, honest mismatch, quick answer. That exchange is worth explaining, because how to evaluate an IT provider is something that starts earlier than most people think.
You Are Comparing Models, Not Just Providers
Outsourced IT comes in a few different models: fully managed, co-managed alongside your internal people, and lighter monitor-only arrangements. Quotes for different models are not comparable, no matter how similar the monthly fees look. We cover how to choose between them in our guide to co-managed vs. managed IT services, and if you are weighing an internal hire instead, start with whether one in-house IT person is enough.
This post is about what comes before any of that: deciding who owns what, and why the answer matters more than the price.
Split Responsibility Fails At The Seams
Here is what 22 years of onboarding clients out of other arrangements has taught us, and helped define our approach to IT management for small business teams. When a split-responsibility setup goes wrong, it almost never fails inside anyone’s job description. It fails at the seams, in the work that sat between two parties who each assumed the other had it.
The gaps we find when we take over are consistent:
- Orphaned access. An employee left months ago. The provider disabled the Microsoft account, and nobody owned the CRM, the payroll platform, or the accounting login. The ex-employee can still get in.
- Unbacked-up cloud apps. The provider backed up “the infrastructure,” and everyone assumed that included the CRM and the accounting platform. It did not, because nobody was paid to back them up.
- Unowned credentials. Nobody can say who holds the API keys connecting the business systems to each other, or what breaks if one is reset.
- No incident lead. A security alert involving a business application, rather than a laptop, stalls while two parties wait for each other to take charge.
- After-hours assumptions. Everyone believed someone would answer at 9pm. Nobody had actually bought that.
None of these gaps came from incompetence. They came from responsibility lines that were never drawn.
Decide The Lines Before You Ask For Quotes
Most business owners do not enjoy shopping for IT. The vocabulary is opaque and every website says roughly the same thing. The highest-value step costs nothing: before you request a single quote, write down who owns each of the five items above, whether that is you, an internal hire, or the provider. If you cannot assign an owner to one of them, that is not a failure. That is the exact question your shortlisted providers need to answer in writing.
Then hold every quote to the same standard. Ask each provider to price the same responsibilities, state plainly what they will not do, and show evidence rather than assurance for anything they claim is already handled. Our guide to comparing IT support quotes covers the pricing side of that exercise.
Questions To Ask AI When Evaluating IT Companies
Nobody reads three IT proposals for fun, and honestly, you no longer have to read them alone. Paste your quotes into Claude, Copilot, or whichever AI your business uses, and ask questions like these:
“Here are two IT support quotes. List what each includes that the other does not, and what neither one mentions at all.”
“What responsibilities does this agreement leave with me? List everything not explicitly owned by the provider.”
“Where does this quote address backups for the cloud apps we rely on, like our CRM and accounting platform? If it does not, say so.”
“Walk me through what happens under this agreement when an employee leaves. Who does what, in what order, and what could fall through?”
“What questions should I ask this provider before signing?”
IMPORTANT TO NOTE: Many of these details won’t even be in the quote itself, but rather in the legal text. Ask questions.
REMEMBER: An AI will not know your business, and it can miss context a good advisor catches. But it is very good at finding what a document does not say, and the gaps are where the risk lives. If a provider’s quote survives that interrogation, you are looking at a serious firm.
Why A “No” Is Good News
Back to the prospect we declined. Their model was coherent and well reasoned. It simply was not ours. We fully manage every environment we take on because the seams above are exactly where businesses get hurt, and owning the whole environment is how we make sure no seam goes unowned. Saying yes would have meant selling them a compromise.
So if a provider you approach declines your request, or tells you their model does not bend to fit your structure, do not read it as a red flag. Read it as a provider who knows what they are good at. The dangerous quote is the one that says yes to everything.
What Full Management Does And Does Not Mean
One clarification, because it comes up on nearly every call. Fully managed does not mean we insist on owning your business applications. Plenty of our clients run a CRM, an ERP, or another line-of-business platform with an in-house system manager or a vendor who specializes in that platform. That is normal, healthy, and we work alongside those people all the time.
The line is straightforward. We own the front door. Identity, single sign-on, device access, and the security controls that decide who gets in. When we onboard or offboard someone, we provision or deprovision their accounts across the environment, including the login to your ERP. That is our job.
“We own the front door. What happens inside the room belongs to whoever runs that room.”
— Adam Thorn, Founder & Principal Technician, TUCU
What happens inside that application, the workflows, the configuration, the reports, the automations, is owned by the person who runs it. Same principle applies to integrations. If we set up SSO between Salesforce and Microsoft Entra, we manage that integration’s certificate lifecycle. If your ERP manager builds an integration between Salesforce and another tool, ownership of those credentials sits with them.
Automation platforms follow the same rule. Power Automate, Power Apps, and similar tools are functional silos with their own specialists. When our clients need serious automation work, we point them to partners who live in that world, like Kwiksand, who operate under their own agreement with the client. We grant them delegated admin over automations only, not over identity or security. Different rooms, different keys.
The point of drawing these lines in writing is that the seams above stay owned instead of assumed. When your ERP person needs a service account, a permission change, or an SSO adjustment, they have one accountable team to call, and so do you. What we decline is not collaboration. It is arrangements where ownership of the environment itself, the identity, devices, and security, is split or nobody’s.
What This Means For You
Sort the quotes by model before you sort them by price, put an owner beside every responsibility, and let your AI read the fine print with you. If you are replacing an existing provider rather than hiring your first, our guide to switching IT providers covers the transition itself. And if what you want is the whole environment managed under one roof, with the help desk, the devices, the security, and every joiner and leaver handled by one accountable team, that is precisely what we do.
One more honest note. We generally do not respond to formal tenders, and this one was a rare exception because the writer deserved a real answer. A thirty-minute conversation tells both sides more than a thirty-page proposal, so that is where we start.
Explore our Managed IT Services or book a call to talk through which model fits the way your business actually runs. If we are not the right fit, we will tell you, and you will have lost nothing but a pleasant conversation.


