Setting expectations
Why an IT support agreement matters.
Informal support arrangements often create confusion about what is included, who should respond and how quickly a problem must be handled.
A written agreement creates a shared understanding between the customer and service provider. It should explain the supported environment, available hours, escalation path, service limitations and commercial terms.
Broad statements such as “full IT support” can create disputes unless the supported services, users and systems are clearly defined.
Service coverage
Define exactly what is supported.
The agreement should identify every major service, system, location and user group covered by the support arrangement.
Users and Devices
Specify the number of users, laptops, desktops, mobile devices and approved operating systems.
Servers and Cloud
List supported physical servers, virtual machines, cloud services and hosting environments.
Networks
Identify firewalls, switches, Wi-Fi, internet links, VPNs and supported sites.
Applications
Record which business applications, databases, email platforms and integrations are included.
The scope should also state
- Whether remote and onsite support are both included.
- Whether hardware repairs and replacement parts are included.
- Whether third-party vendor coordination is covered.
- Whether after-hours and weekend support are available.
- Whether project work is billed separately.
- Which locations and business entities are covered.
Service levels
Define priorities and response commitments.
Not every issue has the same business impact. The agreement should classify incidents according to urgency and operational effect.
Priority 1 — Critical
A major business service is unavailable, many users are affected or there is a serious security incident.
Priority 2 — High
An important function is degraded or a smaller group of users cannot work effectively.
Priority 3 — Normal
A standard support issue affects one user or a non-critical business function.
Priority 4 — Request
A planned change, access request, installation or general assistance request.
Response time is not the same as resolution time. The agreement should explain both.
A response commitment normally means that the service provider acknowledges the request and begins investigation within the stated period. Resolution may depend on complexity, suppliers, replacement parts or third-party services.
Support availability
State when support is available.
Business Hours
Define normal support hours, public-holiday treatment and the applicable time zone.
After-Hours Support
Explain which incidents qualify and whether additional charges apply.
Emergency Channels
Provide the authorised process for urgent escalation outside standard hours.
Planned Maintenance
Define notice periods and permitted maintenance windows.
Shared responsibilities
Define what each party must do.
A support relationship works best when both parties understand their operational and security responsibilities.
Service-provider responsibilities
Deliver agreed support, maintain records, communicate progress and protect customer information.
Customer responsibilities
Provide authorised contacts, accurate information, access and timely approvals.
User responsibilities
Follow security procedures, protect credentials and report problems promptly.
Third-party responsibilities
Clarify where internet providers, software vendors and hardware manufacturers remain responsible.
The provider should know who may approve access changes, purchases, password resets and high-risk configuration changes.
Operational protection
Address security, monitoring and backups.
Support agreements should explain whether security, monitoring and backup services are included or handled under separate services.
Endpoint Security
Define antivirus, endpoint protection, patching and device-monitoring coverage.
Monitoring
State which servers, services and devices are monitored and how alerts are handled.
Backups
Define backup frequency, retention, storage location, restore testing and customer responsibilities.
Access Control
Explain privileged access, credential handling and administrator-account controls.
Incident Escalation
Define how suspected cyber incidents are reported, contained and escalated.
Data Protection
Include confidentiality, data-handling and relevant POPIA responsibilities.
Exclusions and additional work
Clearly explain what is not included.
Exclusions protect both parties from unexpected assumptions and unplanned costs.
Common exclusions may include
- New infrastructure and major project work.
- Hardware replacement parts and manufacturer repairs.
- Unsupported or unlicensed software.
- Data recovery from failed or damaged media.
- Cybersecurity incident response outside the contracted scope.
- Third-party subscription and licensing fees.
- Work caused by unauthorised changes.
- Travel and onsite work outside the agreed area.
Governance and reporting
Include reporting and regular service reviews.
Reporting gives the customer visibility into ticket volumes, recurring problems, service performance and technology risks.
Ticket Reporting
Opened, resolved and outstanding incidents by category and priority.
SLA Performance
Response performance against the agreed service targets.
Recurring Problems
Identification of repeated issues requiring permanent remediation.
Recommendations
Suggested upgrades, security improvements and lifecycle actions.
The agreement itself should be reviewed when the organisation adds users, locations, systems or materially changes its technology environment.
Final checklist
Before signing an IT support agreement.
- Confirm every supported service and location.
- Understand response and resolution targets.
- Confirm normal and after-hours support.
- Review exclusions and additional charges.
- Confirm backup and cybersecurity coverage.
- Verify escalation and authorised contacts.
- Confirm reporting and review frequency.
- Understand contract duration and termination terms.