
Outsourcing system administration: what you hand over and what you keep
The question almost never comes out of a strategy. It comes because one person knows everything, and that person is going on holiday. This is what there actually is to decide.
System administration is not the same as a service desk. The service desk answers your colleague's question; system administration keeps upright the machines that question was about. You can outsource one and keep the other, and that happens often.
What you hand over is the execution: updates, monitoring, backups, access management and out-of-hours cover. What you keep is the decisions: which supplier, which budget, which risk you accept. A party that takes the second one too is selling you dependency rather than management.
The sum is almost never about the hourly rate. It is about what one departing administrator costs you, and about the work that never gets done: patching, documenting and testing a restore.
What system administration is, and where it stops
System administration is keeping running what sits underneath your workplaces: servers and virtual machines, the operating system on them, updates, user rights, the backup, and the monitoring that tells you something is breaking before anyone phones.
That is a different thing from a service desk. The service desk is the conversation with your colleague who can no longer reach his files; system administration is the reason he can or cannot. In small organisations the same person does both, and that is exactly where the two blur — with the result that the maintenance work always loses to the ringing phone.
That distinction is the heart of this decision. You can outsource the service desk and keep the administration, or the other way round, or both. What you cannot do is outsource it without naming which of the two you mean. How we set up the first sits under IT service desk.
The three reasons it lands on the table
In the conversations we have, this question almost always comes from one of three directions, and rarely from a plan.
- One person knows everything. He has been there ten years, he sorts it out, and nobody else can get in. That is not a criticism of him — it is a risk the organisation allowed to grow. As long as he is there it works beautifully, and that is precisely why nothing gets done about it.
- There is no cover outside office hours. A failure at half past six in the evening is a call to a private mobile. That works until the once it does not.
- The work that never gets finished. Patching, documenting, clearing out accounts nobody uses, and demonstrating once a year that a backup can actually be restored. This is the work that yields the moment something urgent appears, and there is always something urgent.
Only the third is a reason to change something structural. The first two can also be solved with a second administrator or an on-call arrangement — more expensive per hour, but without a handover. We say so during the conversation, because a provider who only knows his own answer is not an adviser.
What you hand over and what you keep
This is where contracts most often go wrong, because it is not made explicit.
What moves is the execution. Patching systems, monitoring them, managing accounts and rights, the backup and the restore from it, and being reachable outside office hours. That is work with a rhythm and a demonstrable result, and it lends itself to being handed over.
What stays is the decision. Which supplier you pick, what you spend, which risk you accept and when something gets replaced. That belongs with the organisation carrying the consequences. A management party that takes this over delivers convenience in the short term and dependency in the long, and that is exactly why this question is back on the table in five years.
In practice it comes down to one agreement you want in writing: we may do anything that falls inside the agreed boundaries, and anything outside them we put to you. That makes the split workable rather than theoretical.
Where the cost sits
Amounts do not appear on this site. The structure does, because that is where the surprises live.
Management is almost always charged per unit: per workplace, per server, per user, or a combination. That is transparent as long as you know what falls under a unit. The two questions to ask: does recovery after an incident fall inside that price or outside it, and does a user with two devices count as one or as two.
Then there is the transition itself. Taking over an estate costs work before anything is managed: inventory, documentation, clearing out what nobody recognises. A provider who offers that for free is not doing it, or is charging for it elsewhere. We budget it separately and say how long it takes.
And then the side that rarely reaches paper. What does it cost you now that patching does not happen, that no restore has been tested, and that one person can go on holiday? Those are not lines in a budget, but they are half the trade-off.
Where a handover goes wrong in practice
Four things, in the order we meet them.
- The estate is not written down. There is no overview of what runs, which licences are live and who holds which rights. That is normal and it is no disgrace, but it does have to happen first. A provider who starts without an inventory is guessing.
- The departing administrator is not involved. This is the expensive mistake. What he knows is written nowhere, and after his last day it is gone. Involve him, pay him for it if need be, and let the handover overlap rather than abut.
- The expectation is 24/7 and the agreement is not. Read what it says about response times outside office hours, and what "response" means: someone who looks, or someone who fixes.
- The clearing-out gets postponed. There is always a list of things that will happen "later". Put dates against it, or that list will be the same in two years, only longer.
What we do before taking anything over sits under managed IT: first take inventory and write down what we find, including what the previous party did well, and only then agree a handover.
Questions we get about this
The ones that come up most often when this is on the table.
What is the difference between system administration and a service desk?
The service desk is the conversation with the user: they call, mail or report something and get an answer. System administration is the maintenance of the systems that report was about: servers, updates, rights, backups and monitoring. In small organisations the same person does both, and then the maintenance work structurally loses to the ringing phone. You can outsource them separately, and which of the two you mean is the first question that needs answering.
So do we have to let our system administrator go?
No, and in most cases that is the worst scenario. What we most often see work is that the administrator stays and the work shifts: they take on what is specific to your organisation — the applications, the suppliers, the people — and the generic maintenance with an on-call rota goes outside. That usually makes their job better too. Replace them with a contract and you lose the knowledge that is written nowhere, and that knowledge is exactly what a handover runs aground on.
Can we outsource part of it?
Yes, and that is more often sensible than doing everything at once. The usual first step is monitoring and backup, because those prevent the most damage and are the least entangled with how you work. What is then still not covered we name explicitly, so you make a deliberate choice rather than buying false comfort.
What if it turns out not to work?
Then you want to be able to leave. Before you sign, ask what it looks like when you go: which documentation you take with you, who holds the passwords and the keys, and whether the estate is in a shape someone else can take over. A management party without a ready answer to that is itself a risk. We write it down before we start, because the exit has to exist before you need it.
Where this lands with us
The services this subject falls under.
Curious what sits underneath yours?
The inventory is the first step and it stands on its own: you get the overview even if you do nothing with us afterwards.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.