Operating since 2005
21 Years
Two decades spent on the unglamorous part - documentation, policy, roadmaps and board-ready reporting.
For in-house IT teams
You keep what works. We own the rest.
Layer3 Flex assigns selected IT functions to us and leaves the rest with your team. Every function we take on carries a defined scope, a named owner and an agreed service outcome.
Model
Function ownership, not hours
Boundaries
Written scope and named owners
Certified
ISO/IEC 27001:2022
Choice
Nine functions to draw from
Scope
Whole functions, not hours or a monthly time allowance. Each one comes with a written scope, a named owner on both sides, and reporting against the agreed outcome.
Starting size
A single function is enough. Plenty of arrangements start with just the service desk, or just endpoint operations, and grow from there.
Service desk
Take as much of the desk as you need — full desk, L1, L1 and L2, escalation only, overflow or after-hours. Tickets run on our board, on yours, or through an integrated workflow.
Tooling
For the functions we own we use our tooling, because we cannot be accountable for an outcome we have no visibility of. For the functions you keep, use whatever you use now.
Security
Where we operate endpoints or servers, our security baseline comes with them. Your own security tooling can be accepted, subject to review and a written responsibility boundary.
Pricing and terms
Each function is priced to the responsibilities Layer3 accepts, with scope, inclusions and any variable charges documented in your proposal and service schedule. The split is reviewed on an agreed cadence, and functions can be added or handed back with notice.
Track record
Layer3 has supported New Zealand organisations since 2005, including many where trust, privacy and governance are the whole business.
Operating since 2005
21 Years
Two decades spent on the unglamorous part - documentation, policy, roadmaps and board-ready reporting.
The team
20+ Staff
Engineers, analysts and advisers based in New Zealand, working alongside your team rather than behind a queue.
Security operations
24/7
Round-the-clock monitoring and response through our managed detection platform, for customers on a covered plan.
Independently audited
ISO 27001
Delegated functions are delivered within Layer3's ISO/IEC 27001-certified ISMS and run to documented controls.

How it works
You decide which parts of IT your team keeps and which parts we take. For the functions assigned to Layer3, we own the tooling, work, outcome and reporting within the agreed scope.
The usual arrangement
Access to a platform, a monthly time allowance and a shared inbox. Responsibility is negotiated ticket by ticket, and the boundary is wherever the last conversation left it.
How we do it
You assign whole functions. Each one carries a written scope, a responsibility matrix, a named owner on both sides, and reporting against the outcome we agreed.
Your team keeps what it is good at. We are accountable for the rest.
The functions
Choose one function or combine several. Each is scoped to your environment and priced to the responsibilities Layer3 accepts.
01
An agreed share of end-user support, from the full desk down to escalation only. The options are set out below.
02
The operational health of desktops and laptops: agent, asset inventory, monitoring and alerting, Windows and third-party patching, device health, standard remediation and reporting.
03
Nominated physical and virtual servers: monitoring and alerting, patching, maintenance, capacity and health checks, standard remediation, escalation and reporting.
04
Security monitoring and response across the agreed estate - endpoint, identity, email and network telemetry, alert handling and investigation, through to a full managed SOC.
05
Defined Microsoft 365 responsibilities: user, licence and mailbox administration, policy and baseline management with drift monitoring, security and identity posture, backup and archive.
06
Nominated firewalls, switches and wireless access points: firmware, configuration backup, monitoring, standard changes, troubleshooting and vendor coordination.
07
Private cloud, Azure, virtualisation, storage and backup infrastructure: workload operations, backup monitoring, alerting, capacity management, maintenance and incident escalation.
08
Operational reporting, service reviews, risk register, technology roadmap, budget planning, vCIO sessions and executive reporting.
09
Named engineering time alongside the functions - L3 escalation, your own work queue, onsite presence, leave cover and project work. It sits beside function ownership, it does not replace it.
Every agreement includes the operating layer underneath: the responsibility model, reporting framework, escalation routes and service coordination that make shared ownership work. Functions are selected on top of it.
Service desk
The service desk is the function most teams hand over first, and the one that varies most. Pick the share that matches where your team is stretched.
Full service desk
We receive and manage end-user tickets. Your team is freed for project and platform work.
L1 service desk
We handle intake, triage and first-line resolution. Anything beyond that comes back to you.
L1 and L2 service desk
We handle routine and escalated operational support, so your team only sees the genuinely complex.
L3 escalation
You keep L1 and L2. We take the advanced issues your team does not want to carry alone.
Overflow
We absorb agreed overflow, leave cover and peak demand, so a resignation or a busy month is not a crisis.
After hours
Agreed out-of-hours support is available and charged according to the service schedule.
Tickets can run on our board, on yours, or through an integrated workflow between the two. Whichever you choose, one team owns the queue.
Operating evidence
Co-management only works when both teams share the same current picture. Layer3 reports on the functions it owns so your IT manager can see performance, exceptions and the work that needs a decision.
01
Queue ownership, ticket volume, ageing, service-level performance and escalations.
02
Patching, endpoint and server coverage, availability and control exceptions.
03
Open risks, planned changes, decisions, accountable actions and due dates.
04
Operational reporting is reviewed on the cadence agreed in the service schedule.
Client example
A 200-user organisation had an internal IT manager leading the function, but day-to-day support demand had begun to consume the team. Layer3 took ownership of L1–L3 support and introduced consistent triage, escalation and resolution.
Service desk
Layer3 manages L1–L3 support, including intake, triage, escalation and resolution.
Client leadership
The internal IT manager retains operational leadership, business alignment and priority setting.
Cloud platform
Layer3 provides private cloud services alongside the organisation's Azure environment.
Outcome
The queue was brought back under control, recurring demand became visible and escalation paths became clear.
An anonymised client example based on services Layer3 provides.
Security baseline
Where we own endpoints or servers, our security baseline comes with them. The baseline is included because operational ownership depends on a defined level of protection.
Management
Monitoring agent, alerting and managed patching across everything we operate.
Endpoint
Next-generation antivirus and endpoint detection and response on every device in scope.
Visibility
Security event retention, so an investigation has something to look at.
Response
MXDR and automated containment with a 24/7 human SOC behind it.
Control
Application allowlisting, and secure VPN with Zero Trust network access.
Retention
Extended security event retention where compliance or insurance requires it.
If you would rather keep your own security tooling, we can accept it - subject to review and a written responsibility boundary, so it stays clear who is watching what.
Not sure which
The difference is not size or budget. It is whether you have an internal IT capability worth keeping.
Fully managed
Choose this if you have no internal IT team, or one person stretched across everything. Service desk, endpoints, servers, Microsoft 365, security and strategy are combined in a managed plan, with scope, inclusions and any variable charges documented in your proposal and service schedule.
See fully managed ITCo-managed
Choose this if your IT team is good but stretched, carries too much risk in one person, or never gets to the strategic work. You keep the functions your team does well and assign the rest to us, each with a written scope and a named owner.
See co-managed ITPlenty of organisations start with one and move to the other as the team changes. The split is reviewed on a set cadence, not fixed at signing.
Getting started
Scoping is a conversation about responsibility, not a licence count. We work through a short series of sessions with your IT lead.
01
Map
Current responsibilities, tooling, team capacity and the gaps your IT lead already knows about but has not had time to close.
02
Choose
Your team keeps what it does well and what it enjoys. We take the functions that are eating time, carrying risk, or depending on one person.
03
Define
Each function gets a written scope, an explicit boundary and a named owner on both sides. Service levels, priorities, escalation paths and reporting measures are documented too.
04
Transition
Agent deployment, board configuration, documentation and knowledge transfer for the functions we are taking. Your team keeps working throughout.
05
Operate
Reporting against each function is reviewed on an agreed cadence. For major incidents, the service schedule defines who leads the response, who communicates and which actions require client approval. The split can change as your team changes.
Start the conversation
A 30-minute session with your IT lead and one of our senior advisers to map what your team holds today, where it is stretched, and which functions are worth handing over. No preparation required and no obligation.
Common questions
The questions in-house IT leads ask us most often about co-managed arrangements. If yours is not here, ask us directly.
Book a discovery callNo. The model only works if your team keeps the functions it is good at. We take the ones that are eating time, carrying risk, or depending on a single person. If we ever recommend taking more, it will be because a function is not being covered - not to grow the agreement.
A single function. Plenty of arrangements start with just the service desk, or just endpoint operations, and grow from there once the working relationship is proven.
For the functions we own, yes - we cannot be accountable for an outcome we have no visibility of. For functions you keep, use whatever you already use. Where you want to keep your own security tooling on something we operate, we can accept it subject to review and a written responsibility boundary.
Ours, yours, or an integrated workflow between the two. What matters is that one team owns each queue and the boundary is written down.
That is exactly what the overflow and after-hours service desk scopes are for, and one of the most common reasons teams start a co-managed arrangement. Cover can be standing, or arranged around known absences.
In a managed plan we take the whole environment and you have no internal IT team to speak of. Co-managed assumes you do, and divides responsibility function by function.
Yes. Teams grow, people leave, and priorities move. Scope is reviewed on a set cadence and functions can be added or handed back with notice.
Whoever owns the function, and that is written down before we start. Each function has a defined scope, an explicit boundary and a named owner on both sides, so the answer is never worked out during an incident.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation