Does Your Managed Services Retainer Buy Delivered Work, or Just Availability?

Quick answer

A managed services retainer buys one of two things: work that actually gets done, or just access to someone who could do it. If your monthly fee covers access, monitoring and an on-call engineer, but every task that changes your environment is billed on top at time and materials rates, you are paying for availability. That is an insurance policy, not IT management. 

Most IT managers can tell you their monthly managed services fee to the dollar. Far fewer can tell you what that fee actually produced last quarter. 

That gap is not a finance problem. It is a design problem in how a lot of managed services agreements are built. The fee is presented as the cost of the service, when in practice it is the cost of the relationship, and the service is billed separately. The result is an agreement that looks predictable on the invoice line that recurs, and is entirely unpredictable everywhere else. 

This article is written for the person who owns that relationship day to day: the IT Manager or Head of IT who has to defend the spend upward and get work delivered downward. It sets out how to tell which model you are actually on, why the difference compounds over time, and how to audit your own agreement without waiting for renewal. If you are earlier in the process and still shortlisting, our eight criteria for vetting IT and cyber providers covers the wider evaluation. 

What does a managed services retainer actually buy?

A managed services retainer is a recurring fee paid to an external provider to look after some or all of an organisation’s IT environment. The term covers two commercially different arrangements that are rarely distinguished in a proposal. 

  • The availability model: The monthly fee secures access: a service desk, monitoring, alerting, an escalation path and an engineer who will pick up the phone. Work that follows a ticket is quoted or billed hourly. The fee is a standing charge for readiness. 
  • The delivery model: The monthly fee carries an allocation of effort. Named activities are covered outright, a defined pool of plan value is available for everything else, and the provider draws down against it as work is completed. The fee is a purchase of capacity. 

Both are legitimate. They are not interchangeable, and they produce very different organisations after two years. The problem is that they are frequently sold with the same language. Proactive, partnership, extension of your team, single point of accountability. Those phrases describe an intent. The schedules at the back of the agreement describe what will actually happen. 

Which clauses decide whether your monthly fee produces value?

There are three clauses in a managed services agreement determine the outcome. 

  1. Does the fee include effort, or only access?

Find the inclusion schedule and look for a number: included hours, prepaid hours, plan value, a monthly allocation. If there is no number, or the number is zero, the fee buys access only. 

This is worth watching over the life of an agreement, not just at signing. A prepaid allocation that is reduced at a contract variation, sometimes to nothing, changes the entire commercial character of the arrangement while the headline fee stays familiar. The invoice looks the same. What it buys does not. Variations rarely get the scrutiny the original agreement got, which is exactly why the allocation is the clause most likely to move. 

  1. Does the scope schedule cover the assets that carry your risk?

Read the scope schedule backwards, as a list of what is excluded rather than what is included. Then map the exclusions against your own criticality register. 

There is a pattern worth naming here, because it is the opposite of what buyers assume. Exclusions tend to correlate with criticality. The assets that get carved out are the specialised ones: load balancers, hypervisor hosts, the platform running your core line of business application, the older systems that need genuine depth rather than generalist coverage. They are excluded precisely because they are hard, and they are hard for the same reason they matter. 

So the coverage gap is not evenly distributed across your environment. It concentrates in the places where an outage costs the most. An agreement can cover ninety percent of your asset count and almost none of your actual business risk. 

  1. Can your provider act without asking first?

Pre-authorisation is the clause almost nobody negotiates, and it is the one that decides whether you get proactive management or the appearance of it. 

If every action requires your written approval before the provider can proceed, then proactivity is structurally impossible, regardless of how good the provider’s people are. Someone on your side has to notice the issue, understand it well enough to approve remediation, and find time to sign off. Your provider becomes a queue that only moves when you push it. 

A pre-authorised activity list solves this. It defines the routine work the provider may simply do: patching within an agreed window, capacity adjustments below a threshold, certificate renewals, standard hardening, remediation of known-good fixes. Everything above the threshold still comes to you. Below it, work happens without a sign-off cycle. 

The Australian Signals Directorate makes the same point from a security angle in its guidance on managing your security when engaging a managed service provider: what the provider is responsible for, and what they are permitted to do, needs to be written down rather than assumed. We have worked through the ASD’s specific questions for providers in a separate article. 

Proactivity is not a personality trait of a provider. It is a permission setting in the contract.

Why does an availability-based retainer make your environment worse over time?

Under an availability based retainer, where the monthly fee covers access rather than delivered work, the cost is the visible problem. The behaviour it produces is the expensive one. 

When every action carries an hourly charge, your team starts triaging on price rather than on risk. The certificate rotation waits. The firmware update waits. The backup restore test, the one piece of work that tells you whether your recovery position is real, waits longest of all, because it is the easiest thing to defer and the hardest thing to justify as a line item when nothing is currently broken. It is also the test most organisations have never actually run. 

None of these decisions feel wrong in isolation. Each one is a reasonable call by a competent manager protecting a budget. Together, over eighteen months, they produce an environment with an accumulated maintenance debt that nobody consciously chose and no single person can point to. 

There is a second effect, and it is structural. A provider paid hourly for reactive work has no commercial reason to reduce the volume of that work. This is not an accusation of bad faith. Good engineers do good work under any model. But incentives shape what gets prioritised when everyone is busy, and a model that earns on incidents will not naturally invest unpaid effort in preventing them. 

Contrast this with a delivery based model, where the provider carries a fixed monthly value and absorbs the effort. Under that arrangement, every recurring fault your provider eliminates protects their own margin. Their commercial interest and your operational interest point the same direction. That alignment is the actual product. Everything else is delivery mechanics.

Why does predictable cost matter more than lower cost?

Internal business cases for changing managed services provider are frequently built on the wrong number, and this is the section worth getting right before you take anything to your CFO. 

IT managers are not usually judged on total spend. They are judged on variance. A forecast that lands within tolerance is a good year. A forecast blown apart by three unbudgeted remediation projects is a bad year, even if the total is lower than the year before. 

An availability model optimises the number that is easy to compare and leaves the hard number unbounded. A low base fee with unlimited time and materials exposure above it can produce the same annual total as a higher all-inclusive fee, or a worse one, while being impossible to forecast and actively discouraging the work that would reduce it. 

The comparison that matters is not monthly fee against monthly fee. It is total twelve month cost against total twelve month cost, with the variable component shown separately so you can see how much of your spend was unplanned. Any provider unwilling to model that with you is telling you something about where their revenue comes from. 

How do you tell an availability model from a delivery model?

The table below compares the two managed services commercial models across the clauses that matter most. 

WHAT TO CHECK AVAILABILITY MODEL DELIVERY MODEL
Monthly fee covers
Access, monitoring, on-call
Access, monitoring plus a defined allocation of work
Included effort
None, or reduced to zero by variation
Stated plan value or included hours, visible in the agreement
Routine work
Quoted or billed hourly, each time
Pre-authorised within agreed thresholds
Specialised assets
Commonly excluded or priced as add-ons
Named in scope from commencement
Approval to act
Required before most activity
Required only above defined thresholds
Cost behaviour
Low base, unbounded variable
Higher base, bounded and forecastable
Provider incentive
Earns more when more breaks
Protects margin by reducing faults
Reporting
Invoices for work done
Drawdown against plan value, plus scope review

How do you audit your own managed services agreement?

You do not need to wait for renewal to review a managed services agreement. You need the agreement itself, twelve months of invoices and about two hours. 

  1. Add up the real number. Take twelve months of total spend with your provider: the recurring fee plus every project, remediation, after hours and out of scope invoice. Compare it to twelve times the monthly fee. The difference is what the fee did not cover. 
  2. Calculate your variable ratio. Divide the non recurring spend by the total. If more than a quarter of what you pay your managed services provider is billed outside the agreement, you are not on a managed services agreement in any meaningful sense. You are on a support panel with a standing charge. 
  3. Read the schedule as exclusions. List every asset class named as out of scope, then mark the ones that would stop the business inside four hours if they failed. Any overlap is an uncovered risk you are currently carrying personally. 
  4. Count the approval gates. Work through your last ten tickets and note how many required a sign off from your side before the provider could proceed. Then estimate the elapsed time that sign off cycle added. That is the operational cost of the clause nobody negotiated. 
  5. Ask where the hours went. If your agreement does include hours, ask your provider to split last quarter’s consumption into planned improvement work and unplanned reactive work. A plan fully consumed by firefighting is failing quietly, and it will look healthy on a utilisation report. 
  6. Check the exit terms. Note the notice period, the auto renewal date and the after hours multiplier. A sixty or ninety day notice requirement means the decision to review has to be made well before the renewal conversation, not during it. 
 

If steps one and two produce numbers that surprise you, you have your business case. It writes itself in a single sentence: here is what we paid, here is what the fee actually covered, here is the variance we could not forecast. 

What does a good delivery based agreement include?

A managed services agreement built around delivered work rather than availability has a recognisable shape: 

  • One agreement across the estate. Infrastructure, Microsoft, network, the specialised platforms and cyber security under a single SLA and a single accountable provider, so nobody spends their week coordinating vendors and arbitrating whose fault an outage was. 
  • Specialist depth included, not bolted on. If a platform is critical to you, its expertise belongs in the core service. Depth priced as an optional module is depth you will hesitate to use. 
  • A stated plan value with visible drawdown. You should be able to see, each month, what was consumed and on what. 
  • A pre-authorised activity list. Routine work proceeds inside agreed thresholds without a sign off cycle. 
  • Scheduled scope reviews. Environments change. An agreement that is never revisited is an agreement drifting out of alignment with the estate it covers. 
  • Reporting you can hand upward. Numbers your CFO can read without translation, showing planned against unplanned work. 

Evolution Systems has spent years running IBM Power, Microsoft, network and cyber security environments for Australian organisations, and the pattern holds across all of them: the agreements that produce value are the ones where the provider is paid to prevent work, not to perform it. 

When is an availability only retainer the right choice?

An availability only retainer, where the monthly fee covers access rather than delivered work, is the correct commercial choice in some situations. 

If you have a mature internal team that handles all routine operations and genuinely only needs escalation cover for edge cases, paying for effort you will not consume is waste. The same applies to a stable environment with a low change rate, or to an organisation deliberately running a platform to end of life with no intention of investing in it. 

The caution is that internal capacity is easy to overestimate. Most mid-market IT teams are fully occupied keeping systems running, which leaves little room for the planned work an availability model assumes they will absorb. We have written separately about the gap between keeping systems operational and planning ahead. 

The test is honest consumption. If your reactive spend is consistently low and your internal team is doing the preventative work, an availability retainer is efficient. If your reactive spend is high and climbing, you are paying delivery model prices for an availability model service, which is the worst position of the three. 

What should you ask in your next contract review?

The useful question at a managed services contract review is not how much you are paying. It is this: what did this fee produce in the last ninety days that we can name? 

If the answer is a list of completed work, tickets closed inside SLA, patches applied, a tested restore, capacity added before it became urgent, the model is working. If the answer is that nothing broke, you are buying insurance. Price it as insurance and compare it to what an incident would actually cost you, because that is the only comparison that makes it a rational purchase. 

Take the next step

If your last twelve months of invoices told you something you did not expect, that is worth a conversation rather than a renewal signature. 

Evolution Systems provides managed IT services built on all inclusive plan coverage, pre-authorised activities and a single SLA across infrastructure, Microsoft, network, IBM Power and cyber security. 

Talk to us about a scope and cost review of your current arrangement. No obligation to change providers, just a clear picture of what you are paying for. 

FAQs

What is the difference between a managed services retainer and time and materials support?

A retainer is a recurring fee for ongoing management of an environment. Time and materials support bills for hours worked at an hourly rate with no recurring commitment and no cap. Many agreements combine the two: a retainer covering access and monitoring, with all remedial work billed as time and materials on top.

What should a managed services agreement include as standard?

At minimum: 24x7 monitoring and alerting, a service level agreement with defined response and resolution targets by priority, patching and routine maintenance, backup monitoring with periodic restore testing, a named scope schedule listing covered assets, a pre-authorised activity list with thresholds, named engineers, and regular reporting that separates planned from unplanned work. Anything critical to operations should be named in scope rather than treated as an add-on.

How much of my managed services spend should be billed outside the agreement?

There is no universal benchmark, because it depends on your rate of change. The useful measure is your own trend. Work out what proportion of your annual spend with the provider fell outside the recurring fee, then compare it to the prior year. A proportion rising while your estate is static means the agreement is covering less of the work your environment generates, and the commercial model is worth reviewing.

What are pre-authorised activities in a managed services agreement?

Pre-authorised activities are tasks your provider may carry out without seeking approval each time, within agreed thresholds. Typical examples include patching inside a maintenance window, certificate renewals, standard security hardening and minor capacity adjustments. A practical way to set the threshold is to mirror your own delegation of authority limits. Without a pre-authorised list, a provider cannot work proactively, because every action waits on a sign off from the customer.

How do I compare two managed services proposals fairly?

Normalise them to a total twelve month cost, not a monthly fee. Ask each provider to state the included effort as a number, list the assets excluded from scope, supply their pre-authorised activity list, and quote their after hours multiplier and notice period. Then model a realistic year of work through both. Proposals that look far apart on monthly fee often converge once the variable component is included, and sometimes reverse.

 

What should I check about after hours rates and notice periods?

After hours work is commonly billed at a multiplier of the standard rate, so a low headline rate can still produce high invoices if your change windows fall outside business hours. Ask how business hours are defined, not just what the multiplier is. Notice periods matter just as much: a sixty or ninety day requirement to prevent automatic renewal means the decision to review has to be made months before the contract ends.

Can I renegotiate a managed services agreement mid-term?

Often, yes, particularly at a scheduled scope review or when your environment has changed materially since signing. Renegotiation is also the more common outcome than switching. Bringing evidence helps: twelve months of invoices split into recurring and variable spend, a list of in-scope assets that no longer match your estate, and the specific clauses you want changed, usually the included allocation and the pre-authorised activity list.

Should specialist platforms like IBM Power be covered in a core managed services agreement?

If the platform runs a business critical workload, yes. Specialist expertise priced as an optional add-on creates a cost barrier in front of exactly the systems where delay is most expensive. Coverage in the core service removes the hesitation that leads to deferred maintenance on your most important assets.

Let's see how we can personalise your cloud computing needs

Evolution Systems is ISO 27001 Certified