What it is
A written engagement that spells out what your internal person keeps and what OKTO Solutions takes on, with no grey zone and no orphan task.
Co-managed IT services
Your business already has someone handling IT. In a co-managed model, OKTO Solutions does not replace that person: we cover what they do not have the time, the tools or the expertise to do. You set the dividing line, you keep your access and your decisions, and your team stops carrying all of it alone.
Co-managed IT is a written split of responsibilities between a company’s internal IT staff and an outside provider. Each side keeps a defined share of the work, using the same tools and the same documentation. The provider covers continuous monitoring, advanced security, projects and absences; the internal team keeps proximity and decision-making.
In short
Co-managed IT services split the responsibilities between your internal IT team and an outside provider. Each side keeps a defined share of the work, using the same tools and the same documentation. The model is sometimes called co-sourced IT or shared IT management.
A written engagement that spells out what your internal person keeps and what OKTO Solutions takes on, with no grey zone and no orphan task.
Quebec SMBs that already have a technician, an IT lead or a small team, but not the coverage or the tooling of a full department.
Your person is no longer alone, vacations and departures stop leaving holes, and projects finally move forward alongside the daily work.
The split
Co-managed IT falls apart when nobody knows who owns what. So the split gets written down before anything is touched. The table below shows the division we see most often with our clients: treat it as a starting point, not a mould. Every line can move from one column to the other depending on what your team wants to keep, and the final document is revisited at the review meetings. Two familiar problems disappear at the same time: the task nobody does, and the task two people do twice.
| Responsibility | Your internal team | OKTO Solutions |
|---|---|---|
| Front-line support for employees | Keeps the relationship and the cases that need company context | Absorbs repetitive requests and overflow, if you want that |
| Second level and escalation | Escalates when stuck, without having to justify it | Takes over with network, server and security specialists |
| Monitoring of workstations and servers | Reads the same dashboards, decides on the exceptions | Runs continuous monitoring, days, evenings and weekends |
| Windows and third-party patching | Approves the maintenance windows and the business exclusions | Deploys, verifies and reports on the patches applied |
| Cyber defence and security alerts | Stays informed and rules on anything that touches operations | Runs EDR, access hardening and the response to alerts |
| Accounts, access and multifactor authentication | Handles the arrivals and departures it knows about | Provides the procedures, the checklists and the controls |
| Backups and restore testing | Confirms which data has to be protected first | Operates the central backups and runs the restore tests |
| Firewall, network and remote access | Knows the quirks of the sites and the line-of-business software | Administers the equipment and documents the configurations |
| Line-of-business software and vendor relations | Stays the owner, since that knowledge is the hardest to replace | Steps in when a vendor insists on a technical counterpart |
| Projects: migration, servers, a new office | Sets the priorities and signs off for the teams involved | Supplies the hands, the method and the capacity without a hire |
| Vacation, illness, departure | Takes time off without leaving the company blind | Temporarily widens its share, then returns to the agreed split |
| IT roadmap and budget | Brings the ground-level knowledge and the internal priorities | Leads the exercise with the vCIO module and writes the roadmap |
The Base, Standard and Complet plans also serve as the backbone of a co-managed agreement, and the virtual CIO module adds three levels on top when management wants an IT roadmap and a predictable budget.
Three ways in
The split is decided with you, one engagement at a time, but the requests rhyme. Three setups come back almost every time, and most organizations start with the first one before widening the scope.
Most common
Your technician keeps every bit of contact with employees. We take continuous monitoring, patch management, managed cybersecurity and the security alerts, tools and licences included.
The usual trigger: nobody is watching the servers in the evening, on weekends or during vacation.
To free up a person
We add the first-level help desk. Passwords, printers and repetitive requests leave your person’s calendar, and they get blocks of uninterrupted work back.
The usual trigger: your technician spends every day on support and the projects never move.
One-off or transitional
We come in on a specific mandate, a migration, a server replacement, a new office opening, or to cover a leave, an illness and the gap between two hires.
The usual trigger: one person handles IT, and their departure would put the company at risk.
The method
This is the number one worry of the IT leads we meet, and it is a fair one: a provider who shows up with its own procedures and its own credentials can easily make someone feel they are being replaced. So we work in the opposite order. We start by listening to the person in the chair, we write down what they keep before we write down what we take, and we hand them the same keys we hold. A co-managed setup is working when this is true: six months in, your IT lead is the one defending the agreement in front of management.
We sit down with your IT lead and inventory what is genuinely covered today: workstations, servers, network, backups, licences, admin credentials. We also write down what has been sitting there for months for lack of time. This step happens with your person, never instead of them, and nothing goes to management before they have seen it.
Line by line, we agree on who answers users, who applies patches, who manages accounts, who watches alerts and who decides. The result is a short document your management and your team can read in ten minutes.
We roll out monitoring and ticketing, and your person gets in the same way we do. Same alerts, same tickets, same documentation. Your admin accounts and your licences stay in your name, and our credentials are named, so they can be revoked at any time.
A regular review meeting lets us readjust the split as your team grows or when a project shifts the priorities. The right division today is not the right one next year.
The payoff
The first effect is not technical: your internal person stops being the company’s single point of failure.
Repetitive requests and alert watching leave their calendar. They keep the files where knowing the company makes the difference: the line-of-business software, what the teams need, what management wants next.
Monitoring keeps running while your person is on vacation, in training or sick. A departure no longer leaves the company blind, since the documentation, the credentials and the history are already shared.
Your team gets monitoring, patch management, ticketing, managed security and reporting without buying, installing and maintaining each platform. Those licences come with the service.
OKTO Solutions was founded in 2025 by a group that has supported more than 100 organizations over more than 15 years. Your IT lead has someone to call before making an architecture or security decision.
Comparing the models
There are three ways to reinforce an internal IT team. The right one depends on the size of your organization and on what you want to keep in house.
Your person stays in the chair and keeps the relationship with employees. We add continuous coverage, the tools, managed security and project capacity. The split is written down and revisited on a schedule. You keep your admin credentials, your licences and your documentation, and our share can be widened or narrowed without starting over.
You gain a full-time presence and a stronger internal culture. In exchange, you have to recruit in a tight market, train, equip and hold on to that person, and you still do not get evening and weekend coverage or the deep specialties. Two people booking vacation the same week recreates the original hole.
If you have no IT person in house, the model that fits you is managed IT services instead. If security is the real trigger, start with managed cybersecurity for SMBs, which slots in well beside an internal team that is already in place.
Full outsourcing simplifies the management side: one party is accountable for all of IT. It is the right model when there is no internal resource, or when the one you had is leaving. The trade-off is losing the person on site who knows your quirks, and the change is heavier to absorb all at once.
Plenty of our co-managed engagements exist to keep someone who was heading straight for burnout. Once the night-time monitoring and the repetitive requests leave their calendar, they get their taste for the work back and the company keeps its technical memory.
Where we work
We work this way with organizations in Trois-Rivières, Quebec City, Lévis, Laval, Lavaltrie, Mont-Tremblant, Rouyn-Noranda and Baie-Comeau. The work is done remotely and on-site visits are scheduled when they are actually needed.
Questions and answers
We meet your IT lead, look at what is covered today and come back with a clear dividing line. You see what we would take, what your team keeps and what that frees up.
We use cookies that are strictly necessary for the site to work. Only with your consent do we add measurement cookies that tell us which pages get read. Refusing costs you nothing, and you can change your mind at any time from the bottom of any page. Cookie details.