Choose an IT support company by the quality of its operating agreement, not the length of its product list.
Small businesses need to know who owns user support, cloud administration, devices, networks, security, backups, vendors, documentation, projects, and planning. If the answer is “it depends,” the provider should be able to explain exactly what it depends on.
Use these questions to compare proposals across Greater Boston.
What is actually included?
Ask the provider to identify the included users, devices, sites, cloud services, network equipment, service hours, remote support, on-site work, maintenance, monitoring, security controls, backups, vendors, and planning activities.
Then ask what is excluded or billed separately. Common project boundaries include office moves, new cabling, major migrations, after-hours changes, new locations, large equipment installations, and remediation of an inherited environment.
An attractive monthly price is hard to evaluate when one proposal includes Microsoft 365 administration and network ownership while another includes only help desk tickets.
What response is promised—and what is not?
Response time is not resolution time. Ask how urgency is classified, when the clock runs, what channels clients may use, how an active outage is escalated, and whether after-hours access is contractual or best effort.
Look for language that protects both sides from ambiguity. “24/7 support” can mean a staffed technical operation, an answering service, automated monitoring, or eligibility for emergency escalation under a separate agreement.
Ask who communicates during a prolonged incident and how often the client receives a useful update.
How does local coverage work?
Greater Boston travel is not a radius on a map. A visit may involve building access, parking, loading, telecom-room keys, elevator windows, landlord approval, or a carrier technician.
Ask which communities receive normal on-site coverage, how travel is priced, how visits are scheduled, and what information is gathered before dispatch. A provider should explain when remote support is faster and when physical access is necessary.
Review the actual service-area guides rather than relying on a list of city names. A credible local page should explain real service context, not repeat the same paragraph with a different place name.
Who will know the environment?
A large service desk may offer broader staffing. A smaller founder-led provider may offer more direct context and accountability. Neither model is automatically better.
Ask:
- Who receives the first request?
- Who may administer privileged systems?
- Will the same people understand the account over time?
- How are changes, passwords, diagrams, and vendor decisions recorded?
- What happens if the primary technician is unavailable?
- Are subcontractors used, and under what controls?
The answer should match the complexity and risk of the business.
What evidence supports the security claims?
“We take security seriously” is not evidence. Ask which controls are included, who operates them, and how exceptions or failures are reported.
Topics may include multifactor authentication, administrator separation, device encryption, patching, endpoint protection, backup verification, email protection, privileged access, vendor access, and incident escalation.
Ask how the provider protects its own access to client systems. Confirm that controls required by contracts, regulations, cyber insurance, or customer questionnaires are mapped deliberately rather than assumed.
What documentation belongs to the client?
The client should have a usable record of its systems, providers, licenses, devices, networks, account ownership, recovery paths, and important technical decisions. Sensitive credentials require controlled storage, but the existence and ownership of the systems should not be held hostage.
Ask what documentation is delivered, how often it is updated, where it is stored, and what the client receives at termination. Tyler’s Tech Company’s published IT documentation study explains why documentation quality affects continuity, support, and provider transitions.
How are projects approved?
Managed support does not make every change part of the monthly fee. Ask how projects are scoped, priced, approved, scheduled, tested, and accepted.
A production-ready proposal should identify assumptions, client dependencies, exclusions, payment terms, change control, success criteria, and the handoff. This protects the client from an open-ended bill and the provider from being expected to absorb an undefined expansion.
What happens when the relationship ends?
Read the termination and transition language before signing. Confirm notice periods, final billing, data export, credential handoff, licensing ownership, equipment ownership, documentation delivery, administrative access removal, and reasonable cooperation with a replacement provider.
No client should discover during a transition that a domain, firewall, backup, or Microsoft tenant is registered under an individual technician’s personal account.
Check references for the operating experience
Ask references about communication, follow-through, documentation, billing clarity, security decisions, and how the provider handled a difficult incident—not only whether the team was friendly.
Verify public claims that matter to the decision. Partner badges, certifications, response promises, office locations, and staffing descriptions should be supportable and current.
The bottom line
The right provider makes ownership clearer. You should understand what is included, who responds, how local service works, what evidence supports security, what the client owns, and how the relationship can end cleanly.
Tyler’s Tech Company provides managed IT, break-fix support, Microsoft 365 management, networks, projects, and residential technology help across Greater Boston. If the direct, founder-led model fits what you are looking for, describe the environment and the support gap.