Fast answer
The provider should operate endpoints, patching, monitoring, documented changes, and a named after-hours path for covered systems. Your company should keep legal ownership of Microsoft 365, the domain registrar, billing, backup contracts, and a break-glass admin that does not live only in the vendor's password vault. If you cannot produce that list in writing, nobody owns the environment. Tickets are being answered until they are not.
Most Greater Vancouver businesses do not lose a day because the internet failed. They lose a day because nobody can say who holds Global Admin, who can restore last night's backup, or who answers at 11 p.m. when the warehouse scanners stop talking. That gap is not a technology problem. It is an ownership problem.
This article is the ownership map we use before we accept managed IT services work. It is also the map we ask for when a company is about to leave an incumbent provider. If the current vendor cannot fill it in, the switch is already overdue.
Ownership is a written list, not a feeling
Owners get named. Roles get a second person. Credentials live in a company-controlled vault. Changes get a ticket, a date, and a rollback. That sounds bureaucratic until the bookkeeper is locked out of Microsoft 365 on a payroll morning in Burnaby, or a Richmond clinic cannot open the EMR because the MFA device belonged to a technician who left six months ago.
A provider that “handles IT” without that list is selling availability of a person. Managed IT is supposed to sell continuity of the environment. Those are different products. One of them still works when the usual technician is on vacation.
What the business should always keep
Keep these even if you outsource every ticket:
- Legal ownership of the Microsoft 365 tenant. The company is the tenant owner. The provider is an operator. At least one Global Admin must be a named employee or owner account with MFA, not a shared
admin@mailbox the vendor created. - Domain registrar and DNS billing. If the domain auto-renews on a personal credit card or a vendor portal you cannot open, you do not own the brand on the internet.
- A break-glass account. Stored offline, MFA-protected, tested twice a year, used only for emergencies. If the only way in is the provider's privileged access workstation, you have a single point of failure wearing a hoodie.
- Backup and security contracts in the company name. The provider can administer the product. The invoice, the export rights, and the recovery credentials should not vanish if you change vendors.
- Vendor relationships you already pay for. ISP, photocopier, alarm, line-of-business SaaS. The provider should have current contacts and escalation paths. They should not become the only party the vendor will talk to.
This is the same principle we use on on-demand and emergency IT: fix the incident, then write down who owns the next decision. Emergency work that leaves credentials in a personal notes app is how the next incident starts.
What the provider should own day to day
This is the operating layer. If it is in the monthly scope, the provider should be able to show evidence without calling the original installer.
Identity and access
User lifecycle, MFA enrolment, Conditional Access exceptions, privileged access reviews, and a current admin roster. When someone leaves a Coquitlam office on a Friday, their mailbox, VPN, and shared-drive access should already have a written owner and a same-day process. Identity is the control plane. If the provider does not own it, they cannot honestly own security either.
Endpoints and patching
A current asset list, patch compliance, disk encryption where the business requires it, and a path to reimage a laptop without waiting for a depot in another province. “We sent a Windows update” is not endpoint management. Neither is a spreadsheet last saved in 2023.
Network, firewall, and Wi-Fi
Documented configs, change history, and a known-good backup of the firewall. For warehouses and clinics this also includes network security segmentation and guest isolation. A provider that cannot restore last week's firewall config after a bad change does not own the network. They are hoping it does not break.
Backups and recovery
Jobs, alerting, immutability where the risk requires it, and restore tests on a calendar. Read why backups fail when needed if your current proof of backup is a green icon. The provider should own the operating of backups. You should still own the contract and the right to recover without them in the room.
Monitoring and after-hours path
Monitoring is not response. Covered clients should know which systems are watched, who is on call, how secure access is granted, and what happens when the first engineer cannot fix it. If after-hours is in the plan, it belongs in writing. If it is not, do not advertise it as 24/7. Our after-hours production support guide is the operating version of that sentence.
Documentation and vendors
Network diagram, identity map, backup jobs, ISP circuit IDs, firewall serials, Wi-Fi SSIDs and controllers, SaaS admin contacts, and the last restore-test date. That pack should be current enough that a second engineer can work from it on a Monday without a scavenger hunt. If it lives only in one person's head, the company is one resignation away from starting over.
The ownership table we actually use
| Area | Business keeps | Provider operates | Red flag |
|---|---|---|---|
| Microsoft 365 | Tenant, billing, break-glass Global Admin | Day-to-day admin, Conditional Access, user lifecycle | Only the vendor can sign in |
| Domain and DNS | Registrar login and billing | Record changes, mail authentication, cutovers | Domain on a personal card or unknown registrar |
| Firewall and Wi-Fi | Hardware title, support contract | Config, backups, change control | No config export, default passwords, no diagram |
| Backups | Contract, export rights, recovery credentials | Jobs, alerts, restore tests, runbooks | Never restored, vendor-only console |
| After hours | Decision on what is covered | Named on-call, secure access, escalation | Monitoring with no human path |
| Line-of-business apps | Vendor relationship and data | Identity, network path, backup of local components | Provider installed it and nobody has the vendor PIN |
Security is plumbing, not a separate product
Patching, identity, backups, and segmented networks are how security actually happens in a 12 to 80 person company. A quarterly “cyber workshop” does not replace those. If you want the baseline in one place, use our cybersecurity practices guide. Then ask the provider to show the same controls in your tenant, not on a slide.
Do not let a sales conversation turn every risk into a new SKU. Look across infrastructure, Microsoft 365, cloud, security, and business workflows, then decide based on operational need, risk, and budget. That is the same decision standard we use on assessments.
Multi-site does not mean three undocumented islands
A firm with a Vancouver office, a Surrey warehouse, and a Richmond clinic still has one identity system and usually one backup standard. Each building still needs its own ISP, firewall, Wi-Fi, and on-site contact. The provider should own that inventory. If ticket notes say “the other location” without a circuit ID, nobody owns the second site.
City pages exist so local context is easy to find: Vancouver, Coquitlam, Surrey, Richmond. The ownership map does not change by city. Only access hours and truck rolls do.
How to test a current provider this week
Ask for five artefacts. Give them five business days. You are not being difficult. You are checking whether the environment can survive a long weekend without the usual technician.
- Named Global Admin list, including the company-owned break-glass account.
- Last successful restore test, with what was restored and how long it took.
- Current network diagram plus last firewall config backup date.
- After-hours path: number, on-call role, and how they get secure access.
- Vendor list: ISP, domain, backup, firewall support, and the line-of-business app that would stop revenue if it failed.
If those come back as screenshots of a dashboard and a promise to “circle back,” you already know the answer. Use the hiring questions and the free IT assessment before you sign a longer term.
What NYRO Dynamics will own if we take the work
We will tell you, in the scope, which systems are operated by us and which remain yours. Essential and Complete plans are published on the managed IT page. Multi-site and co-managed work is custom because ownership has to be explicit when another internal IT person is already in the tenant.
We start with the business impact, identify the root cause, implement the right solution, and document what comes next. That last clause is the ownership clause. A fix that is not written down is a ticket, not a managed system.
If you are already mid-outage, skip the map and get IT help now. Ownership still gets written after the lights are back on. If you are choosing a provider, or wondering why the current one cannot restore a mailbox, start with the list above and a call to (778) 775-4535.