Skip to content
Managed IT & IT management

Managed IT contract: the clauses and SLA to check before signing

Managed IT services contract in Morocco: scope, SLA, exclusions, penalties, security, exit plan, notice. The clauses to review before you sign.

By the ALLSAFE SOLUTIONS engineering team30 September 20267 min read
IT support

Before signing a managed IT contract, read it with one rule in mind: what is not written down is not owed. A vague scope or a missing exit plan bothers nobody at signing, but costs dearly on the day of an outage or a change of provider. The clauses to check first are scope, SLA, exclusions, security and reversibility.

This article is for SMB owners and IT managers, in Morocco and elsewhere, who have a draft contract in hand. Choosing the provider is covered in our checklist for choosing an MSP, and the amounts in our article on managed IT pricing in Morocco. Here we go through the document clause by clause. This is a technical and operational reading grid, not legal advice: have the contract reviewed by your counsel.

1. Scope: what is actually covered

Scope is the most important clause, because every other clause refers to it. A good scope does not say “the company’s IT”. It lists, in an appendix, what is supported:

  • Devices: workstations, physical and virtual servers, firewalls, switches, Wi-Fi access points, printers, IP phones.
  • Cloud services: email, Microsoft 365 or Google Workspace, off-site backup, hosting.
  • Users and sites covered, including remote workers.
  • Services: monitoring, patching, account management, backups, user support, vendor management (carrier, software publishers).

Also check who updates the appendix when you add a workstation or a site: an inventory frozen on signing day soon becomes wrong.

2. The SLA: definitions before timeframes

The SLA (Service Level Agreement) is often reduced to a single number. Yet a timeframe only means something if the terms are defined. A serious SLA contains three elements.

Priority levels defined by impact, not left to the provider’s judgement in the middle of an incident:

Priority Typical definition Example Response time
Critical Business stopped or severely degraded for all or part of the company Main server, internet or email down At ALLSAFE SOLUTIONS: under 15 minutes
High Degraded service, workaround available One site without phones, an application slow for everyone To be set in the contract
Normal One user affected, no business stoppage Broken workstation, printer, access to grant At ALLSAFE SOLUTIONS: reply within 24 business hours
Planned Change request or improvement New employee, new firewall rule To be set in the contract

The distinction between response and resolution. Response time is the time between your report and the moment a technician actually starts working on it, not an automatic acknowledgement email. Resolution time is the time until the service is restored. The second sometimes depends on a carrier or manufacturer: the contract must say what the provider does in the meantime (chasing, workaround, keeping you informed).

The starting point and measurement. Does the clock start at the call, the email, the ticket or the monitoring alert? Who measures, and where is the result published? An SLA that is never measured is just a promise.

3. Service hours and on-call

A timeframe only applies within a time window. Check:

  • the business hours used (days, hours, public holidays);
  • what is covered outside business hours: monitoring only, or intervention by an on-call technician;
  • which incidents trigger on-call, and whether it is included or billed separately.

24/7 monitoring and on-call are not the same thing. The first detects a problem at night; the second fixes it. The contract must say clearly which one you are buying.

4. Exclusions: the clause to read twice

No flat fee can cover everything. The problem is vague exclusions, or ones discovered at the first incident. The most common:

  • projects (migration, new site, server replacement);
  • hardware and licences, billed separately;
  • travel outside a defined area;
  • incidents caused by a third party or by a device outside the scope;
  • disaster recovery or recovery after an attack, sometimes excluded or capped.

For each exclusion, ask how the work is billed if you need it: hourly rate, prior quote, fixed fee. An exclusion without a billing method is an unpredictable invoice.

5. Reporting and reviews

The monthly report is the proof that the SLA is being met. The contract should set its minimum content: incidents by priority with actual timeframes, backup status and restore tests, patches applied, security alerts, end-of-life equipment. We detail these indicators in our article on the monthly monitoring report.

Add a periodic review with a named contact to go over incidents, update the scope and plan projects.

6. Penalties and handling failures

Penalties are worthwhile if they are simple and measurable: for example a credit on the month’s invoice when a critical response time is missed, calculated from the monthly report. Complex penalties, capped at a token level or never measured, protect nobody.

Also plan for repeated failures: a written action plan, then a right to early termination.

7. Security and confidentiality

A managed IT provider holds the keys to your information system. The contract should cover:

  • Confidentiality: a commitment from the provider and each of its staff, including after the contract ends.
  • Access management: named accounts for each technician, MFA, logging, no shared passwords.
  • Subcontracting: which services are subcontracted, to whom, and under whose responsibility.
  • Personal data: each party’s role, hosting location, security measures. In Morocco, Law 09-08 and the CNDP govern this processing.
  • Security incidents: notification timeframe and channel, the provider’s role in the response.

8. Data ownership and documentation

Your data and your infrastructure documentation belong to you: network diagrams, inventory, configurations, procedures, administrator accounts. The contract must say so, and require the documentation to be kept up to date and accessible at any time.

9. Reversibility and exit plan

This is the clause people read least and the one that costs most when missing. It describes:

  • what is handed back: documentation, inventory, administrator access, configurations, backups and their encryption keys;
  • the handover timeframe and format;
  • assistance to the new provider (handover meeting, overlap period) and how it is billed;
  • the obligation to delete your data and disable the provider’s access after handover.

10. Term, renewal and notice

Check the commitment period, renewal (automatic or not), notice and price revision. Automatic renewal is not a problem if the notice period is reasonable: forgetting the date is the trap.

11. The pricing model

The contract must state how the price is calculated (per device, per user, block of hours or time and materials), how it changes when the scope changes and what is billed on top. Our pricing article compares these models.

Red flags

  • An SLA expressed as “best efforts” or “as soon as possible”.
  • No definition of priority levels.
  • No scope appendix, or an appendix without an inventory.
  • No reversibility clause, or exit fees that are not quantified.
  • Administrator accounts in the provider’s name rather than your company’s.
  • No monthly report.

Common mistakes

  • Negotiating price before scope: you compare contracts that do not cover the same things.
  • Confusing 24/7 monitoring with 24/7 intervention.
  • Forgetting the exit: reversibility is negotiated at signing, not on the way out.
  • Signing without legal review a long contract or one involving sensitive data.

Checklist before signing

  • Is the scope listed in an appendix, with an update procedure?
  • Are priority levels defined by impact?
  • Does the SLA separate response and resolution, with a clear starting point?
  • Are service hours and on-call written down?
  • Does every exclusion have a billing method?
  • Are the monthly report content and review frequency set?
  • Can penalties be measured from the report?
  • Are confidentiality, named access, subcontracting and personal data covered?
  • Do the documentation and administrator access belong to you?
  • Does the reversibility clause describe what is handed back, when and how?
  • Are the term, renewal and notice dates in your calendar?
  • Has the contract been reviewed by your legal counsel?

How we do it

At ALLSAFE SOLUTIONS, the contract starts from a free initial audit: the appended scope reflects the inventory we found. Our commitments are written down: 24/7 monitoring, critical incidents handled in under 15 minutes, other requests answered within 24 business hours. Every month, a report shows the timeframes actually met. The documentation and administrator access belong to you, and reversibility is planned from the day you sign.

If you are still weighing a provider against an internal team, our comparison of managed services vs in-house IT will help you decide. The details of our offer are on the managed IT page, with examples of our work in our case studies.

A contract to review or a provider to replace? Request your free audit: we will help you set a scope and an SLA that fit your business.

Frequently asked questions

What is the difference between response time and resolution time in an SLA?

Response time measures the gap between your report and the moment a technician actually starts working on it. Resolution time measures the time until the service is restored. The first can always be committed to; the second often depends on third parties (carrier, manufacturer) and must be framed with its exceptions.

What should a managed IT exit (reversibility) clause contain?

The list of what is handed back at the end of the contract (up-to-date documentation, inventory, administrator passwords, configurations, backups), the handover timeframe and format, assistance to the new provider and how it is billed. Without this clause, changing provider becomes a negotiation.

Should a managed IT contract include penalties?

They are useful if they are easy to calculate from the monthly report, for example a credit when a response time is missed. Theoretical penalties that are never measured protect nobody. What matters most is an SLA that is measured and published every month.

Should a lawyer review a managed IT contract?

Yes, as soon as the contract commits the company for a long period or involves sensitive data. This article is a technical and operational reading grid, not legal advice: liability, personal data and termination clauses deserve a lawyer’s opinion.

About the editorial team

ALLSAFE SOLUTIONS

Network, security and cloud engineers

Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.

LinkedIn
← All articles
CallWhatsAppFree audit