Your MSP Fee Includes a Tool Stack. Audit It Before You Renew.
Your managed IT invoice may show one monthly fee. The service behind it could include a dozen tools your company never selected separately.
Endpoint management, antivirus, email security, backup, monitoring, ticketing, documentation, DNS filtering, security awareness training, remote access, and reporting may all sit inside the bundle. That can be efficient. It can also hide overlap, unclear ownership, weak coverage, and exit costs until the renewal is already on the table.
Do not ask only whether the MSP fee is competitive. Ask what the fee buys, which tools are active, who owns each account, what the provider does with each tool, and what happens if one piece leaves the bundle.
A good renewal review turns the monthly fee into an inventory you can test.
Start with the service, then name the tool
Buyers often approach this backward. They request a list of product names, compare those names with tools purchased elsewhere, and start looking for duplicates.
The product list matters, but it is not enough. One product may supply several functions. Two products may look similar while covering different devices, users, data, or hours. A tool may be installed without anybody acting on its alerts. Another may be absent from the invoice because the MSP rolls it into labor.
Build the inventory around the service the business expects:
| Service expected | Product or platform | Covered assets or users | Provider work included | Customer work retained | Evidence available |
|---|---|---|---|---|---|
| Endpoint management | Record the current tool | Devices, servers, or locations | Patching, scripting, inventory, remote support | Exception approval, application testing | Console export, patch report, ticket history |
| Endpoint security | Record every agent and module | Workstations, servers, cloud workloads | Monitoring, tuning, escalation, response | Risk decisions, containment approval | Coverage export, alert history, policy record |
| Backup and recovery | Record platform and storage | Systems, applications, data sets | Job monitoring, failure handling, restores | Recovery priorities, business validation | Job history, restore tests, retention settings |
| Network monitoring | Record collector and portal | Circuits, firewalls, switches, wireless | Alert review, ticket creation, escalation | Carrier authority, business impact validation | Device list, alert history, escalation records |
| Service desk | Record ticketing and remote tools | Users, sites, supported devices | Intake, triage, resolution, reporting | Local coordination, approvals, unsupported apps | Ticket export, SLA reports, escalation matrix |
Keep adding rows until every recurring service in the agreement has a tool, a coverage boundary, work on both sides, and evidence.
An empty cell is useful. It shows you where the renewal is running on assumption.
Reconcile four records that rarely agree
You need more than the proposal. Compare at least four views of the service:
- The signed agreement, statement of work, service descriptions, security addendum, and current renewal proposal
- The invoice, including per-user, per-device, per-site, consumption, storage, and project charges
- The provider’s console exports for active users, devices, licenses, policies, backups, alerts, and tickets
- Your own asset, identity, application, location, and finance records
The totals may differ. An MSP may bill by user while its endpoint platform counts devices. Backup may price by workload, storage, or retained data. One acquired office may still run a legacy agent. A retired server may remain in backup retention for a valid reason.
For every mismatch, record the cause and the decision. Do not fix a legitimate exception just to make the spreadsheet neat.
The useful question is not, “Why are these numbers different?” The useful question is, “Which number governs the fee, which number governs coverage, and can we defend both?”
Find overlap without cutting the wrong protection
Tool overlap is not automatically waste.
A Microsoft license may include a security feature while the MSP uses a separate platform for centralized policy, response, or multi-tenant operations. A firewall may include DNS controls while a separate service covers roaming users. Your SaaS vendor may retain data while the MSP’s backup product supports a different recovery need.
There may be a good reason to keep both. Make the provider explain it in operating terms.
For each apparent duplicate, ask:
- Which assets, users, applications, or locations does each product cover?
- Which control or recovery scenario would disappear if one product were removed?
- Who monitors each tool and during which hours?
- Which product is the system of record for policy, evidence, and reporting?
- Has the included feature been configured, or does it only exist in the license?
- What internal work would return to your team if the MSP removed its product?
- Does removing the product reduce the monthly fee, or is the fee sold as an indivisible service bundle?
That last question matters. A provider may standardize on one stack because it allows the service desk to automate work, train staff, and support customers consistently. It may not offer a dollar-for-dollar credit when you decline one component.
Okay, cool. The buyer still needs the commercial answer. Is the service worth its full fee with that component removed? Does the provider support the alternative? Who owns the work after the change?
Do not cancel a working control because another license appears to include similar features. Test the replacement first. Confirm coverage, policy, reporting, response ownership, and rollback.
Separate access from ownership
Provider-managed does not always mean provider-owned. It should not mean nobody knows.
For every tool, document:
- Contracting party and billing owner
- Tenant, account, subscription, or license owner
- Primary and backup administrators
- Identity provider and authentication method
- Provider service accounts and privileges
- Customer visibility into configuration, activity, and reports
- Data, configuration, and log export rights
- License reassignment or transfer options
- Access available after notice or termination
- Removal process for agents, accounts, integrations, collectors, and credentials
The ownership model can differ by tool. A multi-tenant RMM or security platform may reasonably sit under the MSP’s account. A cloud, domain, or core business tenant needs a different conversation. Backup data may be yours while the console belongs to the provider.
The problem is discovering during an incident or transition that your company cannot see, export, administer, or replace something it depends on.
Joint guidance from CISA and international cybersecurity authorities tells MSP customers to understand provider access, subcontractor risk, and the division of security responsibilities. It recommends contracts that explain services purchased, services not purchased, incident responsibilities, and customer-specific security requirements. That is also a clean commercial test for the bundle.
Test the controls with evidence
A screenshot from the sales presentation proves nothing about your environment.
Choose representative records and test them before renewal:
- Match a current employee and a departed employee across identity, endpoint, security, training, and ticketing systems.
- Match an active workstation, a server, a spare device, and a retired device across the asset list and every billed console.
- Trace one backup from protected workload through retention, monitoring, failed-job handling, and a controlled restore.
- Trace one endpoint alert from tool detection through human review, ticket creation, escalation, and closure.
- Trace one patch exception from policy through approval, deployment, validation, and reporting.
- Open an after-hours support request through the agreed test process and confirm what the service can actually start.
- Export one useful report without help from the account executive.
Use controlled tests, agree on the timing, and protect production.
CISA’s guidance says customers should restrict provider accounts to managed systems, audit their use, and disable them when they are not active. It also tells customers to ensure contracted backup services meet recovery requirements. The provider needs a defensible service. The customer needs to verify the outcome.
If backup is inside your bundle, connect this review to the backup restore evidence test. If broad security or response work is included, use the managed IT incident ownership test to prove who acts. If the bundle promises around-the-clock help, review the after-hours support model separately.
Price the bundle two ways
The provider’s monthly fee is only one cost view.
First, price what you receive:
- Recurring managed service fee
- One-time onboarding or remediation work
- Charges outside the base scope
- Storage, consumption, or overage charges
- Internal labor for approvals, exceptions, vendor coordination, reporting, and cleanup
- Separate products kept because the bundle does not meet the need
Then price what it would take to change:
- Replacement licenses and overlapping service periods
- Agent removal and deployment
- Policy and configuration rebuild
- Data, ticket, documentation, and log export
- Tenant or account transfer
- Integration changes
- Testing and rollback
- Provider transition assistance
- Internal time to run the migration
Exit cost belongs in the renewal review even when you stay. It shows how much leverage the next term gives away.
If the provider owns the tool account, ask what the customer receives at termination. A data export may not include configurations, scripts, policies, alert history, documentation, or a usable license. Run the relevant export before signing, using the same principle in the SaaS renewal data export test.
Put every tool into a decision state
Do not finish with one score for the MSP. Decide what happens to each service and tool relationship.
Keep it in the bundle when coverage is clear, the provider performs useful work, evidence supports the service, the commercial model is acceptable, and transition rights fit the risk.
Correct the records when the service fits but users, devices, licenses, policies, accounts, or invoices do not match.
Change the scope when the tool is useful but the provider’s work, customer responsibility, support hours, reporting, or price needs a written correction.
Remove or replace it when the capability is unused, duplicated without a defensible purpose, unsupported, or unable to meet the requirement. Test the replacement and document the handoff first.
Use a short bridge or competitive review when material coverage, ownership, export, security, or transition questions remain open near the notice deadline.
Put accepted changes into the agreement, statement of work, service schedule, security addendum, transition plan, or another controlled document tied to the contract. Meeting notes and helpful emails are weak protection after the term renews.
Renew the operating model, not the product list
A managed stack can be a strong reason to use an MSP. Standard tools can help the provider automate work and support the environment consistently.
But the bundle is not valuable because it contains many logos. It is valuable when the tools cover the right environment and the provider turns them into work your business needs.
Before the renewal meeting, bring the signed scope, renewal proposal, invoices, provider exports, internal asset and user records, current security and backup coverage, ticket history, and termination terms. Build the inventory. Reconcile the mismatches. Test a few ugly records. Price what stays and what changes.
If your managed IT agreement is approaching renewal, request a Contract and Spend Risk Review. Catch Advisors will help you expose bundled tools, overlap, missing ownership, and transition risk so you can decide what to keep, correct, remove, or compare before you sign.