Layer3 Logo

For in-house IT teams

Co-managed IT

You keep what works. We own the rest.

Layer3 Flex assigns selected IT functions to us and leaves the rest with your team. Every function we take on carries a defined scope, a named owner and an agreed service outcome.

Model

Function ownership, not hours

Boundaries

Written scope and named owners

Certified

ISO/IEC 27001:2022

Choice

Nine functions to draw from

At a glance — how co-management works

Scope

Whole functions, not hours or a monthly time allowance. Each one comes with a written scope, a named owner on both sides, and reporting against the agreed outcome.

Starting size

A single function is enough. Plenty of arrangements start with just the service desk, or just endpoint operations, and grow from there.

Service desk

Take as much of the desk as you need — full desk, L1, L1 and L2, escalation only, overflow or after-hours. Tickets run on our board, on yours, or through an integrated workflow.

Tooling

For the functions we own we use our tooling, because we cannot be accountable for an outcome we have no visibility of. For the functions you keep, use whatever you use now.

Security

Where we operate endpoints or servers, our security baseline comes with them. Your own security tooling can be accepted, subject to review and a written responsibility boundary.

Pricing and terms

Each function is priced to the responsibilities Layer3 accepts, with scope, inclusions and any variable charges documented in your proposal and service schedule. The split is reviewed on an agreed cadence, and functions can be added or handed back with notice.

Track record

Who you are handing it to

Layer3 has supported New Zealand organisations since 2005, including many where trust, privacy and governance are the whole business.

Operating since 2005

21 Years

Two decades spent on the unglamorous part - documentation, policy, roadmaps and board-ready reporting.

The team

20+ Staff

Engineers, analysts and advisers based in New Zealand, working alongside your team rather than behind a queue.

Security operations

24/7

Round-the-clock monitoring and response through our managed detection platform, for customers on a covered plan.

Independently audited

ISO 27001

Delegated functions are delivered within Layer3's ISO/IEC 27001-certified ISMS and run to documented controls.

ISO/IEC 27001 certification mark

How it works

We own functions, not tickets

You decide which parts of IT your team keeps and which parts we take. For the functions assigned to Layer3, we own the tooling, work, outcome and reporting within the agreed scope.

The usual arrangement

Tools and hours

Access to a platform, a monthly time allowance and a shared inbox. Responsibility is negotiated ticket by ticket, and the boundary is wherever the last conversation left it.

How we do it

Function ownership

You assign whole functions. Each one carries a written scope, a responsibility matrix, a named owner on both sides, and reporting against the outcome we agreed.

Your team keeps what it is good at. We are accountable for the rest.

The functions

Choose what we own

Choose one function or combine several. Each is scoped to your environment and priced to the responsibilities Layer3 accepts.

01

Service desk

An agreed share of end-user support, from the full desk down to escalation only. The options are set out below.

02

Endpoint operations

The operational health of desktops and laptops: agent, asset inventory, monitoring and alerting, Windows and third-party patching, device health, standard remediation and reporting.

03

Server operations

Nominated physical and virtual servers: monitoring and alerting, patching, maintenance, capacity and health checks, standard remediation, escalation and reporting.

04

Security operations

Security monitoring and response across the agreed estate - endpoint, identity, email and network telemetry, alert handling and investigation, through to a full managed SOC.

05

Microsoft 365 operations

Defined Microsoft 365 responsibilities: user, licence and mailbox administration, policy and baseline management with drift monitoring, security and identity posture, backup and archive.

06

Network operations

Nominated firewalls, switches and wireless access points: firmware, configuration backup, monitoring, standard changes, troubleshooting and vendor coordination.

07

Infrastructure operations

Private cloud, Azure, virtualisation, storage and backup infrastructure: workload operations, backup monitoring, alerting, capacity management, maintenance and incident escalation.

08

IT governance

Operational reporting, service reviews, risk register, technology roadmap, budget planning, vCIO sessions and executive reporting.

09

Engineering capacity

Named engineering time alongside the functions - L3 escalation, your own work queue, onsite presence, leave cover and project work. It sits beside function ownership, it does not replace it.

Every agreement includes the operating layer underneath: the responsibility model, reporting framework, escalation routes and service coordination that make shared ownership work. Functions are selected on top of it.

Service desk

How much of the desk do you want us to run?

The service desk is the function most teams hand over first, and the one that varies most. Pick the share that matches where your team is stretched.

Full service desk

We receive and manage end-user tickets. Your team is freed for project and platform work.

L1 service desk

We handle intake, triage and first-line resolution. Anything beyond that comes back to you.

L1 and L2 service desk

We handle routine and escalated operational support, so your team only sees the genuinely complex.

L3 escalation

You keep L1 and L2. We take the advanced issues your team does not want to carry alone.

Overflow

We absorb agreed overflow, leave cover and peak demand, so a resignation or a busy month is not a crisis.

After hours

Agreed out-of-hours support is available and charged according to the service schedule.

Tickets can run on our board, on yours, or through an integrated workflow between the two. Whichever you choose, one team owns the queue.

Operating evidence

What your IT manager can see

Co-management only works when both teams share the same current picture. Layer3 reports on the functions it owns so your IT manager can see performance, exceptions and the work that needs a decision.

01

Service performance

Queue ownership, ticket volume, ageing, service-level performance and escalations.

02

Operational health

Patching, endpoint and server coverage, availability and control exceptions.

03

Risk and change

Open risks, planned changes, decisions, accountable actions and due dates.

04

Review cadence

Operational reporting is reviewed on the cadence agreed in the service schedule.

Client example

A service desk brought back under control

A 200-user organisation had an internal IT manager leading the function, but day-to-day support demand had begun to consume the team. Layer3 took ownership of L1–L3 support and introduced consistent triage, escalation and resolution.

Service desk

Layer3 manages L1–L3 support, including intake, triage, escalation and resolution.

Client leadership

The internal IT manager retains operational leadership, business alignment and priority setting.

Cloud platform

Layer3 provides private cloud services alongside the organisation's Azure environment.

Outcome

The queue was brought back under control, recurring demand became visible and escalation paths became clear.

An anonymised client example based on services Layer3 provides.

Security baseline

We do not operate what we cannot protect

Where we own endpoints or servers, our security baseline comes with them. The baseline is included because operational ownership depends on a defined level of protection.

Included by default

Management

Monitoring agent, alerting and managed patching across everything we operate.

Endpoint

Next-generation antivirus and endpoint detection and response on every device in scope.

Visibility

Security event retention, so an investigation has something to look at.

Optional uplift

Response

MXDR and automated containment with a 24/7 human SOC behind it.

Control

Application allowlisting, and secure VPN with Zero Trust network access.

Retention

Extended security event retention where compliance or insurance requires it.

If you would rather keep your own security tooling, we can accept it - subject to review and a written responsibility boundary, so it stays clear who is watching what.

Not sure which

Managed or co-managed?

The difference is not size or budget. It is whether you have an internal IT capability worth keeping.

Fully managed

We take the whole environment

Choose this if you have no internal IT team, or one person stretched across everything. Service desk, endpoints, servers, Microsoft 365, security and strategy are combined in a managed plan, with scope, inclusions and any variable charges documented in your proposal and service schedule.

See fully managed IT

Co-managed

You keep what works

Choose this if your IT team is good but stretched, carries too much risk in one person, or never gets to the strategic work. You keep the functions your team does well and assign the rest to us, each with a written scope and a named owner.

See co-managed IT

Plenty of organisations start with one and move to the other as the team changes. The split is reviewed on a set cadence, not fixed at signing.

Getting started

How we scope it

Scoping is a conversation about responsibility, not a licence count. We work through a short series of sessions with your IT lead.

01

Map

What you have now

Current responsibilities, tooling, team capacity and the gaps your IT lead already knows about but has not had time to close.

02

Choose

Which functions we own

Your team keeps what it does well and what it enjoys. We take the functions that are eating time, carrying risk, or depending on one person.

03

Define

Scope and responsibility

Each function gets a written scope, an explicit boundary and a named owner on both sides. Service levels, priorities, escalation paths and reporting measures are documented too.

04

Transition

Take the handover

Agent deployment, board configuration, documentation and knowledge transfer for the functions we are taking. Your team keeps working throughout.

05

Operate

Report and review

Reporting against each function is reviewed on an agreed cadence. For major incidents, the service schedule defines who leads the response, who communicates and which actions require client approval. The split can change as your team changes.

Start the conversation

Work out the split

A 30-minute session with your IT lead and one of our senior advisers to map what your team holds today, where it is stretched, and which functions are worth handing over. No preparation required and no obligation.

Common questions

Before you ask

The questions in-house IT leads ask us most often about co-managed arrangements. If yours is not here, ask us directly.

Book a discovery call

No. The model only works if your team keeps the functions it is good at. We take the ones that are eating time, carrying risk, or depending on a single person. If we ever recommend taking more, it will be because a function is not being covered - not to grow the agreement.

A single function. Plenty of arrangements start with just the service desk, or just endpoint operations, and grow from there once the working relationship is proven.

For the functions we own, yes - we cannot be accountable for an outcome we have no visibility of. For functions you keep, use whatever you already use. Where you want to keep your own security tooling on something we operate, we can accept it subject to review and a written responsibility boundary.

Ours, yours, or an integrated workflow between the two. What matters is that one team owns each queue and the boundary is written down.

That is exactly what the overflow and after-hours service desk scopes are for, and one of the most common reasons teams start a co-managed arrangement. Cover can be standing, or arranged around known absences.

In a managed plan we take the whole environment and you have no internal IT team to speak of. Co-managed assumes you do, and divides responsibility function by function.

See fully managed IT.

Yes. Teams grow, people leave, and priorities move. Scope is reviewed on a set cadence and functions can be added or handed back with notice.

Whoever owns the function, and that is written down before we start. Each function has a defined scope, an explicit boundary and a named owner on both sides, so the answer is never worked out during an incident.

Layer3

Book a discovery call - 30 minutes, no obligation