Service desk: 778-321-2372 Existing clients: contact@brevitytech.ca
Guide

What is in a managed IT contract, and what an SLA promises

The five documents, the clauses that matter, and what a response time actually promises.

Most small businesses sign a managed IT agreement without reading it, which is understandable. It arrives as a PDF, it is written in a register nobody enjoys, and the alternative to signing is continuing to have the problem that made you call.

The parts that matter are short and there are few of them. Here is what should be in front of you, and what to look at in each.

The five documents

A properly structured engagement has five, though smaller providers often fold them into two.

The Master Services Agreement is the relationship. Term, payment, liability, confidentiality, what happens if either side wants out. It rarely changes between clients.

The Service Level Agreement is the promise. Response and resolution targets, and the priority definitions that decide which target applies. This is the document people think they are signing and frequently are not, because plenty of providers do not have one.

The service schedule or statement of work is the scope. What is included, what is not, and what out of scope costs. Per client, and per project where projects exist.

The Data Processing Agreement covers how your data is handled, where it lives, and on what basis. If you hold client files or patient records, your own compliance obligations require this of your vendors, so its absence is a problem you inherit.

A mutual non-disclosure agreement should be available before any assessment work, not after.

If a provider offers a one page quote and nothing else, that is not automatically a red flag at the very smallest end of the market. It does mean that every disagreement later will be settled by whoever remembers the conversation differently.

What "four hour response" actually means

This is the most quoted number in managed IT and the least examined.

It does not say response to what. An automated ticket acknowledgement is a response. So is a human reading your message and doing nothing about it yet. Neither is somebody working on the problem, which is what most buyers assume they are purchasing. Look for wording that distinguishes first response from work commencing.

It does not say response during when. Four business hours starting at 4pm on a Friday is Monday lunchtime under most definitions. Check whether the clock runs on business hours or calendar hours, and what the stated business hours are.

It does not say what happens if the window passes. A target with no remedy attached is a preference. Some agreements include a service credit. Many include nothing, which is common and not automatically unreasonable, but you should know which you have.

And it does not say which issues qualify. Every SLA has priority tiers, and the four hour figure usually attaches to one of them. The definitions are where the substance lives.

Priority definitions are the real SLA

A typical structure runs something like this:

  • Priority 1, the business is down or a critical system is unavailable to everyone
  • Priority 2, a group is affected or a core function is degraded
  • Priority 3, one person is affected and can still work
  • Priority 4, requests, changes, and questions

The interesting question is who decides. If the provider assigns priority unilaterally and the definitions are vague, the fast targets can be applied narrowly. Good definitions are specific enough that both sides would categorise the same incident the same way, and the agreement should say what to do when you disagree.

Also worth checking: whether there is a resolution target at all, or only a response target. Response targets are easy to meet and easy to publish. Resolution targets are the harder commitment and far less common.

The clauses worth reading

Scope and exclusions. The most important page in the whole set. You are looking for a written list of what is not covered, expressed in plain terms. Its absence does not mean everything is covered. It means the boundary will be decided later, by the other party, with an invoice attached.

Out of scope rates. What hourly work costs, what counts as a project, and whether after hours carries a premium.

Term and termination. Notice period, exit fee, and whether the term auto-renews. Auto-renewal with a long notice window is the clause most likely to surprise you, because it converts a month-to-month feeling into an annual commitment you forgot to exit.

Data and documentation on exit. What you receive when the relationship ends, in what format, and within what timeframe. Documentation of your own environment should be yours without argument. A provider treating it as their intellectual property has made leaving expensive on purpose.

Liability. It will be capped, usually at some multiple of monthly fees. That is standard and not worth fighting at this scale. It is worth reading so you know the number, because it is almost certainly smaller than the loss it would be covering, which is the actual argument for carrying cyber insurance rather than relying on a vendor contract.

Subcontractors. Whether the provider can use them, and whether your data goes with them.

Security obligations flowing both ways. A good agreement says what the provider will maintain and what you are responsible for. Where it only binds one side, it is usually the wrong side.

What this looks like when it goes wrong

The pattern is consistent. Nothing in the paperwork matters at all until something happens, and then all of it matters at once, usually on the same day.

A server fails on a Friday afternoon and the SLA turns out to run on business hours. An employee leaves and their account stays live because offboarding was never in scope. A migration is quoted at a fixed price and the discovery work turns out to be billable. A relationship ends and the network documentation does not come with it.

Not one of those is unusual. Each is decided by a paragraph somebody skipped.

A reasonable amount of diligence

You do not need a lawyer to read a managed IT agreement, though for a regulated practice it is money well spent on the data processing terms specifically.

For everyone else, an hour with a highlighter and four questions is proportionate. What is excluded. What the response commitment actually covers. What leaving costs and what I get on the way out. And what happens when the target is missed.

If a provider is uncomfortable walking through those, that is information too, and it is cheaper to have learned it now.


For the record, every engagement here runs on a Master Services Agreement, a Service Level Agreement with priority definitions, a service schedule, a Data Processing Agreement, and a mutual NDA available before any assessment. Response times are contractual rather than aspirational, terms are month to month with no exit fee, and your documentation is yours.

More on how we work, what is in each plan at pricing, and the related questions worth asking any provider in twelve questions to ask before you sign.

Related guides

Request a readiness review