Headquartered in Coquitlam. Serving Greater Vancouver.
Get IT Help

Managed IT Ownership

What a Managed IT Provider Should Own for Your Greater Vancouver Business

A monthly invoice is not ownership. If identity, backups, vendors, and after-hours response have no named owner, you have a help desk, not a managed environment. This is the map we use with offices, clinics, warehouses, and multi-site teams from Vancouver to Langley.

By  10 min read Published

Fast answer

The provider should operate endpoints, patching, monitoring, documented changes, and a named after-hours path for covered systems. Your company should keep legal ownership of Microsoft 365, the domain registrar, billing, backup contracts, and a break-glass admin that does not live only in the vendor's password vault. If you cannot produce that list in writing, nobody owns the environment. Tickets are being answered until they are not.

Most Greater Vancouver businesses do not lose a day because the internet failed. They lose a day because nobody can say who holds Global Admin, who can restore last night's backup, or who answers at 11 p.m. when the warehouse scanners stop talking. That gap is not a technology problem. It is an ownership problem.

This article is the ownership map we use before we accept managed IT services work. It is also the map we ask for when a company is about to leave an incumbent provider. If the current vendor cannot fill it in, the switch is already overdue.

Ownership is a written list, not a feeling

Owners get named. Roles get a second person. Credentials live in a company-controlled vault. Changes get a ticket, a date, and a rollback. That sounds bureaucratic until the bookkeeper is locked out of Microsoft 365 on a payroll morning in Burnaby, or a Richmond clinic cannot open the EMR because the MFA device belonged to a technician who left six months ago.

A provider that “handles IT” without that list is selling availability of a person. Managed IT is supposed to sell continuity of the environment. Those are different products. One of them still works when the usual technician is on vacation.

What the business should always keep

Keep these even if you outsource every ticket:

  • Legal ownership of the Microsoft 365 tenant. The company is the tenant owner. The provider is an operator. At least one Global Admin must be a named employee or owner account with MFA, not a shared admin@ mailbox the vendor created.
  • Domain registrar and DNS billing. If the domain auto-renews on a personal credit card or a vendor portal you cannot open, you do not own the brand on the internet.
  • A break-glass account. Stored offline, MFA-protected, tested twice a year, used only for emergencies. If the only way in is the provider's privileged access workstation, you have a single point of failure wearing a hoodie.
  • Backup and security contracts in the company name. The provider can administer the product. The invoice, the export rights, and the recovery credentials should not vanish if you change vendors.
  • Vendor relationships you already pay for. ISP, photocopier, alarm, line-of-business SaaS. The provider should have current contacts and escalation paths. They should not become the only party the vendor will talk to.

This is the same principle we use on on-demand and emergency IT: fix the incident, then write down who owns the next decision. Emergency work that leaves credentials in a personal notes app is how the next incident starts.

What the provider should own day to day

This is the operating layer. If it is in the monthly scope, the provider should be able to show evidence without calling the original installer.

Identity and access

User lifecycle, MFA enrolment, Conditional Access exceptions, privileged access reviews, and a current admin roster. When someone leaves a Coquitlam office on a Friday, their mailbox, VPN, and shared-drive access should already have a written owner and a same-day process. Identity is the control plane. If the provider does not own it, they cannot honestly own security either.

Endpoints and patching

A current asset list, patch compliance, disk encryption where the business requires it, and a path to reimage a laptop without waiting for a depot in another province. “We sent a Windows update” is not endpoint management. Neither is a spreadsheet last saved in 2023.

Network, firewall, and Wi-Fi

Documented configs, change history, and a known-good backup of the firewall. For warehouses and clinics this also includes network security segmentation and guest isolation. A provider that cannot restore last week's firewall config after a bad change does not own the network. They are hoping it does not break.

Backups and recovery

Jobs, alerting, immutability where the risk requires it, and restore tests on a calendar. Read why backups fail when needed if your current proof of backup is a green icon. The provider should own the operating of backups. You should still own the contract and the right to recover without them in the room.

Monitoring and after-hours path

Monitoring is not response. Covered clients should know which systems are watched, who is on call, how secure access is granted, and what happens when the first engineer cannot fix it. If after-hours is in the plan, it belongs in writing. If it is not, do not advertise it as 24/7. Our after-hours production support guide is the operating version of that sentence.

Documentation and vendors

Network diagram, identity map, backup jobs, ISP circuit IDs, firewall serials, Wi-Fi SSIDs and controllers, SaaS admin contacts, and the last restore-test date. That pack should be current enough that a second engineer can work from it on a Monday without a scavenger hunt. If it lives only in one person's head, the company is one resignation away from starting over.

The ownership table we actually use

Area Business keeps Provider operates Red flag
Microsoft 365 Tenant, billing, break-glass Global Admin Day-to-day admin, Conditional Access, user lifecycle Only the vendor can sign in
Domain and DNS Registrar login and billing Record changes, mail authentication, cutovers Domain on a personal card or unknown registrar
Firewall and Wi-Fi Hardware title, support contract Config, backups, change control No config export, default passwords, no diagram
Backups Contract, export rights, recovery credentials Jobs, alerts, restore tests, runbooks Never restored, vendor-only console
After hours Decision on what is covered Named on-call, secure access, escalation Monitoring with no human path
Line-of-business apps Vendor relationship and data Identity, network path, backup of local components Provider installed it and nobody has the vendor PIN

Security is plumbing, not a separate product

Patching, identity, backups, and segmented networks are how security actually happens in a 12 to 80 person company. A quarterly “cyber workshop” does not replace those. If you want the baseline in one place, use our cybersecurity practices guide. Then ask the provider to show the same controls in your tenant, not on a slide.

Do not let a sales conversation turn every risk into a new SKU. Look across infrastructure, Microsoft 365, cloud, security, and business workflows, then decide based on operational need, risk, and budget. That is the same decision standard we use on assessments.

Multi-site does not mean three undocumented islands

A firm with a Vancouver office, a Surrey warehouse, and a Richmond clinic still has one identity system and usually one backup standard. Each building still needs its own ISP, firewall, Wi-Fi, and on-site contact. The provider should own that inventory. If ticket notes say “the other location” without a circuit ID, nobody owns the second site.

City pages exist so local context is easy to find: Vancouver, Coquitlam, Surrey, Richmond. The ownership map does not change by city. Only access hours and truck rolls do.

How to test a current provider this week

Ask for five artefacts. Give them five business days. You are not being difficult. You are checking whether the environment can survive a long weekend without the usual technician.

  1. Named Global Admin list, including the company-owned break-glass account.
  2. Last successful restore test, with what was restored and how long it took.
  3. Current network diagram plus last firewall config backup date.
  4. After-hours path: number, on-call role, and how they get secure access.
  5. Vendor list: ISP, domain, backup, firewall support, and the line-of-business app that would stop revenue if it failed.

If those come back as screenshots of a dashboard and a promise to “circle back,” you already know the answer. Use the hiring questions and the free IT assessment before you sign a longer term.

What NYRO Dynamics will own if we take the work

We will tell you, in the scope, which systems are operated by us and which remain yours. Essential and Complete plans are published on the managed IT page. Multi-site and co-managed work is custom because ownership has to be explicit when another internal IT person is already in the tenant.

We start with the business impact, identify the root cause, implement the right solution, and document what comes next. That last clause is the ownership clause. A fix that is not written down is a ticket, not a managed system.

If you are already mid-outage, skip the map and get IT help now. Ownership still gets written after the lights are back on. If you are choosing a provider, or wondering why the current one cannot restore a mailbox, start with the list above and a call to (778) 775-4535.

FAQ

Managed IT ownership questions

What should the provider own versus what we keep?

They operate endpoints, patching, monitoring, documented changes, and the after-hours path in scope. You keep tenant ownership, registrar, billing, backup contracts, and a break-glass admin that is not vendor-only.

Who should hold Microsoft 365 Global Admin?

A named company account with MFA, plus delegated or named admin for the provider. If only the vendor can sign in, you do not own the tenant.

Do backups belong to the provider?

They should run jobs, alerts, and restore tests. You should own the contract, export rights, and recovery credentials. A green dashboard is not ownership.

Does managed IT include after-hours support?

Only if the written scope says so. Monitoring without a named on-call path is not after-hours support.

What documentation should exist?

Diagrams, identity, firewall and Wi-Fi, backup jobs, vendor contacts, and a current asset list. If that pack lives in one technician's head, nobody owns the environment.

We have more than one Greater Vancouver site. Does that change ownership?

Each site needs ISP, firewall, Wi-Fi, and an on-site contact. Identity and backup remain one standard. Undocumented second sites are not managed. They are luck.

Put Named Owners on the Environment Before the Next Outage

NYRO Dynamics will review identity, backups, vendors, and after-hours coverage, then write down who owns what. Call from anywhere in Greater Vancouver.

About NYRO Dynamics

NYRO Dynamics is an IT support and managed services company headquartered at 3030 Lincoln Avenue #211, Coquitlam, BC V3B 6B4. We serve businesses across Greater Vancouver and the Fraser Valley with business IT support, managed IT, Microsoft 365, network engineering, enterprise wireless, cloud systems, backups, cybersecurity and technology projects. Our team includes engineers with Cisco, Fortinet, Microsoft, and AWS certifications. Our engineers bring experience supporting 300+ organizations across their careers. Rated 5.0 on Google. For urgent IT help, call (778) 775-4535 or email info@nyrodynamics.com.