Digitplus
Managed Services

How to Write a Managed Services Scope of Work That Prevents Scope Creep

Most disputes with an IT support provider are about a line nobody drew. How to count the estate, write exclusions with a handoff, state the price assumptions and run change control.

Digitplus Editorial Team9 min read
A close-up of a neat stack of white paper in black and white

Most fights with an IT support provider are about a line nobody drew.

It starts small. A director's mailbox reset on a Saturday, as a favour. Three laptops set up the night before a board meeting, never logged. A verbal "can you also keep an eye on the CCTV recorder" that never reaches the contract. Each one is reasonable. Over a year they redraw the engagement, until the provider feels used and the client feels overcharged. Both are partly right.

A managed services scope of work is the document that stops this. It draws the boundary around the service and states what the price assumes. It is worth separating from the two papers it usually travels with. The master services agreement sets the legal frame, such as liability and termination. The service-level agreement sets the performance promises, and our guide to what an IT SLA should cover goes through those clause by clause. The scope of work is the part this piece is about. Merge it into the SLA and you lose the ability to argue cleanly about either.

Count the estate, site by site

"We manage your IT" is not a scope. A scope reads more like this, for example: 84 endpoints, 6 servers, 2 firewalls and one Microsoft 365 tenant, across a head office and one branch. The count is what gets priced. Later, it is what change control measures against.

Count before signing, and count per site. Endpoints, servers physical and virtual, network equipment, cloud tenants, printers if they are in scope. If the provider cannot produce that list after the onboarding visit, they have not looked closely enough to price it.

Multiple sites need their own lines. Remote support and on-site visits cost different amounts, and travel adds its own line. Each should be bounded. A head office in Abuja with a branch in Port Harcourt cannot sit under one undifferentiated rate. If an engineer's flight to the branch is an unstated assumption, the first trip becomes the first dispute. Decide in writing whether travel is included, capped or billed per visit.

The same goes for on-site response. Our own agreements state the committed on-site time for each site. For priority faults in the FCT we aim for same-day, and the agreement carries the figure we are held to. Ask any provider for the per-site number, in writing. For the support models that sit behind those numbers, see IT support for companies in Abuja.

Write every exclusion with a handoff

The exclusions list protects the client as much as the provider. It removes the "I thought that was covered" argument before anyone is angry enough to have it.

Some exclusions recur in Nigerian offices, and each should be explicit:

  • Power equipment. Generator, inverter and UPS hardware faults, fuel and servicing.
  • The internet link. Faults on the carrier's side of the router.
  • Surge damage. Equipment lost to a bad changeover or a voltage spike.
  • End-of-life hardware. Devices the manufacturer no longer supports.
  • Software development. Building or heavily customising applications.

An exclusion on its own is a dead end, so give each one a handoff. Power equipment is excluded, but the provider monitors the UPS and raises an alert with your generator contractor. The internet link is excluded, but the provider diagnoses the fault, logs it with the carrier and chases it. Surge damage is excluded from support, but the provider quotes the replacement. Written that way, the exclusion says who acts, and nobody waits at the boundary.

Be careful with exclusions written as conditions. A clause that suspends the provider's obligations during "power-related events" can cover most of the hours your systems are actually at risk. Grid instability is a known operating condition here, and the scope should treat it as one.

State what the price assumes

A fixed monthly fee rests on assumptions. Write them down, with what happens when one breaks. The usual ones:

  • The count. The endpoint and server numbers stay within a stated tolerance of the signed figure. Pick a figure, such as 10%.
  • Access. The provider has working administrator access to everything in scope, documented at onboarding.
  • A coordinator. One named person on the client side approves requests and arranges site access.
  • Supported hardware. Devices in scope are under warranty or within an agreed age.

When the count drifts past the tolerance, or every job starts with a hunt for a password, the price assumption has failed. The scope should say what follows: a recount and a re-rate at the next review, never a surprise invoice.

Then separate run work from project work. Keeping the estate running is the retainer. A cloud migration, an office move, a network redesign or a new Microsoft 365 rollout is a project, scoped and quoted on its own. Project effort billed as routine support is the single most common way a retainer stops being predictable. How retainers and projects are priced against each other is covered in what managed IT services cost in Nigeria.

Who owns what: a sample responsibility matrix

Most friction in a managed services engagement is about ownership, not skill. A responsibility matrix fixes ownership in advance. For each function, one party is Responsible for doing the work, exactly one is Accountable for the outcome, some are Consulted, and others are Informed.

FunctionProviderClient IT leadClient executive
Endpoint patchingR/ACI
Backup jobsR/ACI
Test restoresRAI
Monitoring and alertingR/AII
Joiners and leaversRAC
Security incident responseRAC
Telling the client about a data breachR/AII
Notifying the NDPC of a data breachCRA
Liaison with other suppliersRAI

Two rows deserve a second look. Backups can run every night and still be useless if nobody ever restores one. Make the provider run the test restores, and keep the client accountable for confirming the business could actually recover from them.

The breach rows follow the Nigeria Data Protection Act 2023. A provider with access to personal data is a processor. Under section 40(1) a processor that becomes aware of a breach must notify the controller that engaged it. Under section 40(2) the controller then has 72 hours to notify the Commission. The provider cannot carry your duty for you, so the scope should state how fast they tell you. Our own service contracts carry a data processing agreement and a stated notification time by default, for exactly this reason.

Change control that people actually use

Boundaries decay without a way to move them on purpose. Change control is that way, and it has to be light enough that people use it. It needs four answers:

  1. Who can raise a change: the named coordinator.
  2. How it is logged: a ticket or an email, never a corridor conversation.
  3. Who approves it on each side.
  4. How the price moves as a result.

Tie the last answer to a unit of work, so growth is billed openly instead of being absorbed or refused. A per-device rate for each new endpoint. A block of pre-bought hours for small requests. A provider who absorbs every extra request eventually cuts corners elsewhere. One who refuses every request is useless. A logged, priced change avoids both.

Keep the retainer and the hardware apart in the contract. Support labour is a naira cost and should not move with the exchange rate. Hardware replacements and spares are imported, and their prices track the dollar. Put the second group on its own lines, priced at the time of order, so a move in the rate never reopens the whole agreement.

Review the scope on a fixed date. Quarterly suits most estates. An inventory agreed in January and never revisited is fiction by June.

Do not overwrite it, either. A forty-page scope of work for a ten-person office is a document nobody reads. Two pages that count the estate and name the exclusions will do more.

Frequently asked questions

What belongs in a managed services scope of work?

The counted estate per site, the service hours, the exclusions with their handoffs, the assumptions the price depends on, and the change-control process. A responsibility matrix belongs alongside it. Response and resolution targets sit in the SLA.

How do we stop scope creep with an IT provider?

Log every request that sits outside the written scope as a change, with a price attached, even when the price is zero. Review the inventory every quarter. Creep comes from unlogged favours, so the fix is a log.

Is project work included in a managed services retainer?

Not unless the scope says so. Migrations and office moves are normally quoted separately. If your retainer is silent on it, ask before the first project starts, not after the invoice.

Who is responsible for data protection when IT is outsourced?

Your organisation stays the controller under the NDPA 2023 and keeps the duty to notify the NDPC. The provider is a processor, must tell you promptly about a breach, and needs a written agreement with you. The matrix should show both duties.

If you already have a managed services contract, send it to us. We will mark where its scope is silent and where an exclusion has no handoff, whether or not you move your support to us. That review is how our managed services engagements start for small and mid-sized businesses and larger estates alike.

Related to this: Managed Services.

Have a project that needs this thinking?

Tell us what you’re planning. We’ll come back with practical next steps and a clear, line-itemised proposal, no obligation.