Managed IT Service (Package)

Service Definition • Armstrong Bell • 8 August 2026

Document summary

This document sets out what's included in our Managed IT Service package.

At a glance, this package covers:

  • Service Desk support, 08:30–17:00 weekdays, with SLA-backed response and resolution targets

  • Incident and problem management, including root-cause analysis for recurring issues

  • 24×7 proactive monitoring, alerting and patch management for endpoints and servers

  • 24×7 Managed Detection and Response (MDR), NCSC Early Warning, and active Secure Score management

  • Secure password management, monthly service reporting, and backup monitoring

  • A structured onboarding process covering service, security, and project management setup

Service desk support

Our Service Desk is available weekdays 08:30–17:00, delivered by ABL-employed staff at our head office, accessible by email or telephone. Extended coverage hours are available on request.

Tickets are raised in our incident management system and progressed through to resolution, with quality monitoring built in throughout.

Our service desk covers:

  • The core Microsoft suite of products for endpoints, servers and associated cloud products, plus any systems we supply

  • Mainstream applications such as anti-virus, Microsoft Office, and remote access tools

  • Hardware from our preferred vendor list, chosen to keep our team's expertise consistent and deep (list available on request)

Line-of-business applications aren't covered – these need an active support agreement with the software vendor.

Service Level Agreements (SLA)

Tickets are assigned a priority from 1–4. New tickets emailed in default to priority 3, then reviewed for adjustment.

Priority level Definition
P1 – Business Critical

Business-critical systems down, majority of users affected, no workaround

P2 – High

Systems severely degraded, blocking key day-to-day work

P3 – Normal

Non-critical issue, workaround available

P4 – Change Request

A requested addition or change – e.g. a new starter, software install, or configuration update


P1 and P2 incidents must be phoned in – these can't be logged by email.

Priority level P1 P2 P3 P4
Target response time 15 minutes 1 hour 2 hours 8 hours
Target resolution 4 hours 8 hours 2 working days 3 working days


Incident management

Reported incidents are reviewed, investigated, escalated where needed, and resolved in a timely manner:

  • Reporting: customer reports via phone or email

  • Logging: logged with a unique reference for tracking

  • Categorisation: assessed for urgency/impact and assigned to an engineer

  • Investigation: resolved with the customer kept informed throughout

  • Closure: closed with customer confirmation; knowledge base article updated or created where appropriate

Every ticket has an assigned owner. Our service management team monitors KPIs at both the service and individual-ticket level, with automatic alerts as tickets approach their SLA.

Problem management

This identifies and fixes the root causes of recurring or significant incidents, reducing future disruption through both reactive and proactive work.

Conducted periodically – typically at a quarterly meeting, or sooner if recurring tickets are identified:

  • Identification: via incident trends, monitoring, or proactive risk analysis

  • Logging: logged, referenced, and categorised by impact/urgency

  • Root cause analysis: structured investigation to find and fix the underlying cause

  • Resolution: permanent fix implemented, with an interim workaround provided if this takes time

  • Prevention: ongoing proactive review to reduce future unplanned downtime

  • Closure: closed once confirmed resolved and documented

Third-party vendor management

We build an understanding of your third-party providers during onboarding, including introductions to key suppliers. This means smoother day-to-day support, and faster progress on issues that span multiple vendors.

Where an issue is multi-supplier – e.g. a performance, reliability or connectivity problem – our team can liaise with the third party on your behalf and manage the process collaboratively. This doesn't replace your existing vendor relationships (e.g. Sage or other line-of-business contracts), which should be maintained separately.

Proactive monitoring and alerting

We use Datto RMM for monitoring and device management across all managed endpoints, including servers, with alerts on threshold breaches or status changes.

Standard checks on Windows servers:

  • Online/offline status, disk space, CPU and RAM usage

  • Status of critical services (per server type and any bespoke configuration)

  • Patch compliance and hardware status

Network devices (routers, switches, firewalls) are monitored via SNMP for up/down status, critical links, and hardware changes. Additional monitoring – CCTV, building management, other network-connected assets – can be added on request.

Windows patch and OS version management

Devices are patched via Datto RMM under our standard policy, unless an alternative is agreed.

Patches are approved where they're a critical, security, definition, or rollup update, or address an actively exploited vulnerability.

Release cycle: deployed to a small "beta" group first; rolled out to remaining devices after 7 days, balancing update speed against the risk of a faulty Microsoft release.

Feature updates (bringing Windows 11 to its latest version) are scheduled and tested with the customer during periodic reviews, given some can affect core functionality.

24×7 Managed Detection and Response (MDR)

Requires Microsoft 365 Business Premium or Microsoft Defender for Endpoint Plan 1 (available via our Microsoft partnership); otherwise the free built-in Windows Defender is used.

Devices are onboarded into Defender and given an additional monitoring agent via Datto RMM. Devices outside this platform needing extra configuration may incur a charge.

Devices are monitored 24×7; suspicious signals are reviewed, with our partner's SOC investigating further where needed.

Pre-approved response actions:

  • Host isolation for high-confidence threats, until resolved

  • Remediation of High/Critical incidents by the SOC

  • Remote reboots where required, including servers

Devices can be excluded from active remediation where necessary. All incidents are reported to our service desk for review or further action.

NCSC tools deployment and registration

We deploy the NCSC's Early Warning service during onboarding, alerting our service desk to any signals of network compromise. This complements, rather than replaces, active cyber defence.

  • MyNCSC account creation, and registration of domains/IP addresses

  • Early Warning configuration and alert routing to our service desk

  • Ongoing review and investigation of alert data

Active management of Microsoft Secure Score

Secure Score's recommendations, and your score, change over time. We monitor this and deploy tested baselines to improve it where viable – aiming to increase protection as far as sensibly possible, not to chase a perfect 100, which would require disproportionate cost and restriction for most organisations.

  • Monthly review of score data and new baselines

  • Vendor recommendations reviewed and applied where appropriate

  • Customer engagement before applying anything with a cost, risk, or change implication

Progress is tracked over time, with periodic reporting available.

Password management

Customers can use MyGlue (IT Glue/Kaseya) for secure, cloud-based password storage, with single sign-on configured via Microsoft Entra ID during onboarding.

Service reporting

An automated service report is provided by default (opt-out on request), covering:

  • Tickets raised and priorities

  • SLA performance

  • Ticket type

  • Customer satisfaction data

  • Patch compliance

Read the full Customer Service Report guide

Backup monitoring and remediation

Backup services we supply are monitored for failures, with jobs re-run promptly to minimise the risk of unprotected or outdated data.

Onboarding

The onboarding steps for the core components are listed below:

  • Service

    • Ticketing/knowledge-base setup and monthly reporting configuration

    • Site visits to build knowledge of infrastructure and services, including photographs for future troubleshooting

    • Standardised device build process, and starters/leavers process agreed with the customer

    • MyGlue configuration, and secure storage of updated admin passwords

  • Service Management

    • Introduction to your Service Delivery Manager and how our services work

    • Welcome pack, escalation processes, and third-party vendor introductions

  • NOC (proactive services)

    • Datto RMM tenant build, agent deployment to servers, and advanced monitoring configuration

    • Testing and refinement of proactive alerting across network infrastructure and other components

    • Patch management policy configuration and RMM deployment package creation

    • Network configuration backups stored in IT Glue; Office 365 and server backups deployed as required

    • Pilot deployment of Datto RMM with full review, then full rollout to endpoints

    • ScalePad integration for asset management and warranty reporting

  • Cyber Security

    • MDR tenant configuration, with pre-approved remediation actions and escalation processes defined

    • MDR agent deployment, registration confirmation, and detection/alerting testing

  • Project Management

    • Introductory call, Project Initiation Document, and risk log with proposed mitigations

    • Project plan build-out, and information-sharing handover with the incumbent supplier

    • Ongoing project management meetings and highlight reports at an agreed frequency

    • Continual quality/risk management and reporting, through to project closure