How to read an MSP proposal when you are not an IT person

Three proposals, wildly different numbers, everyone sounding confident. Written by someone who writes these for a living: start at the exclusions page and work backwards.

You are not an IT person. You have three proposals in front of you, they are between eleven and forty pages long, and the monthly figures differ by a factor of two. Everyone sounds confident.

I write these proposals for a living, which puts me in an awkward position writing this. But the buyers who ask hard questions end up as better clients, so here is how to read one properly.

Start at the exclusions, not the inclusions

Every proposal has a page near the back headed “Out of scope” or “Exclusions”. Read it first. It is the only page written by someone being completely honest with you, because it is the page their lawyer cares about.

Common exclusions worth noticing: projects and change work, third-party application support, anything involving a vendor’s own helpdesk, after-hours attendance, cabling, and hardware procurement. None of these are unreasonable to exclude. The question is whether the excluded items are things you will need every month. If they are, the headline monthly figure is fiction.

Work out what a “user” means

Per-user pricing is standard and sensible. It is also where the numbers get slippery.

Does a user mean a person, a mailbox, or a device? For a school with 60 staff, 900 students, 40 shared classroom machines and a dozen kiosks, those three definitions produce wildly different invoices. For a warehouse with shift workers sharing terminals, likewise. Get it defined in writing, and get the definition of what happens when the count changes mid-term.

Interrogate the response times

Almost every proposal promises a response time. Very few define response.

An automated email saying “we have received your ticket” is technically a response. So is a human ringing you back within fifteen minutes. Both get written as “15 minute response” in a table. Ask specifically: is that time to acknowledgement, time to a human, or time to someone actively working the problem? Then ask what the penalty is for missing it. If there is no consequence, it is an aspiration rather than a service level.

Also ask what hours the SLA covers. “24/7 monitoring” and “24/7 support” are entirely different products, and the first is frequently sold in language that implies the second.

Follow the licences

A meaningful chunk of any monthly figure is pass-through licensing: Microsoft 365, backup, endpoint security, remote monitoring agents. Ask which licences are included, at what tier, and who owns the tenancy.

That last point matters more than it sounds. If the provider owns your Microsoft tenancy rather than administering yours, leaving them becomes considerably more painful. It is not necessarily malicious, and it is often just how they’ve always done it, but you want to know before you sign rather than during a divorce.

Ask the exit question early

Ask, in the first meeting, what leaving looks like. What is the notice period, what documentation do you receive, what happens to admin credentials, and is there an offboarding fee?

The answer tells you a lot about the provider’s confidence. Someone who expects to keep you by being good will answer it plainly. Someone whose retention strategy is friction will get uncomfortable. I have inherited environments where the outgoing provider handed over a spreadsheet of IP addresses and nothing else, and rebuilding that knowledge cost the client more than a year of fees.

Judge the discovery, not the document

Here is the single best signal, and it happens before the proposal arrives.

Did they come and look? Did someone open the comms cabinet, count the switches, ask what that unlabelled server does, and notice the air conditioning unit sitting directly above the rack? Or did they take a headcount over the phone and send a template?

A proposal written without discovery is a guess. It will be revised upward once reality intrudes, usually in month three, usually as “additional scope”. The provider who spent two hours crawling around your building and came back with a slightly higher number and a list of things you didn’t know were broken is almost always the better buy.

Red flags worth naming

  • Unlimited support with no fair-use definition. Nothing is unlimited. It just means the limits are undocumented and will be applied at their discretion.
  • No mention of documentation anywhere in the document.
  • Security described entirely as products. A list of vendor logos is not a security posture.
  • A three-year term with annual CPI increases and no break clause on a first engagement.
  • Pricing that is dramatically below the others. The work does not become cheaper because the invoice does.

The one question to ask all three

“What did you find during discovery that concerns you most, and what would you fix in the first ninety days?”

You will learn more from the three answers to that question than from a hundred pages of proposal. One of them will tell you something specific and slightly awkward about your own environment. That is usually the one to hire.


Written by

Matt Rollins is a Melbourne-based technology founder. He runs TechAssist, a managed IT provider serving growing Australian businesses, and is building TeachingBlox, AussieWave Hosting and Self Storage Auctions.

Start a conversation or connect on LinkedIn.