Guide
How to Choose an IT Provider
Most dissatisfaction with IT providers traces back to terms agreed at the start and never examined. These are the questions worth asking before signing rather than after.
At a glance
- Ask what is excluded, not just what is included
- Confirm documentation and credential ownership
- Read the exit terms before the service terms
- Insist on severity-based response commitments
Scope, exclusions and pricing
Inclusion lists read well. Exclusion lists tell you what you will be invoiced for. Ask specifically about project work, after-hours attendance, on-site visits, vendor liaison, new site setup, hardware procurement and application support — these are the common boundaries where expectation and contract diverge.
Understand the pricing model and what triggers change. Per-user and per-device pricing behave differently as an organisation grows, and clarity about which services scale with headcount avoids a difficult conversation later.
- Written exclusion list, not just inclusions
- Out-of-hours and on-site charging rules
- How pricing changes as headcount changes
- Notice period and price review mechanism
Ownership, documentation and exit
You should own your documentation, your administrative credentials and your tenant. A provider holding sole administrative access to your Microsoft tenant, domain registration or backup platform has meaningful leverage over you, whether or not they intend to use it.
Read the offboarding terms before anything else. What is handed over, in what timeframe, at what cost, and in what format. A provider confident in its service will make leaving straightforward; a provider that makes exit painful is telling you something.
- Client-owned documentation and credentials
- Named administrative access held by you
- Domain and tenant ownership under your control
- Written handover scope, timeframe and cost
Security, delivery and warning signs
Establish what security is included versus sold separately: MFA enforcement, endpoint protection, patch management, backup with tested restores, logging, awareness training. A managed agreement without verified backup and enforced MFA is incomplete regardless of price.
Ask who actually performs the work, what happens when your usual engineer is unavailable, how escalation works, and what reporting you receive. Warning signs: reluctance to give you administrative access, no documentation offered, vague or single-tier response promises, contracts longer than three years with no exit provision, and dismissiveness when you ask how a previous client's departure went.
Keep exploring
Related Oakville services
Most engagements combine several of these. Follow the thread that matches the problem you are trying to solve.
Questions
Frequently asked questions
- How long should a contract be?
- One to three years is typical. Longer terms are acceptable only with clear exit provisions and a review mechanism; without those, length is simply lock-in.
- Should we choose a local provider?
- It matters where physical presence is needed — hardware faults, moves, cabling, new sites. For cloud-centric organisations, capability and responsiveness matter more than distance.
- How do we compare proposals fairly?
- Normalise them. List the same inclusions, exclusions, response commitments and ownership terms side by side. Headline pricing is rarely comparable until you do.
Ask us the same questions
We will answer them directly, in writing, including the parts other providers prefer to leave until after signature.