Home/Resources/Co-managed versus fully managed monitoring

Resources · Network operations

The question is not which platform is better. It is what your existing investment is worth.

Both shapes deliver the same coverage. They differ on who owns the tooling, and that single difference drives most of the decision.

The dividing line

Co-managed means the engineers are the provider's and the monitoring platform stays yours. Fully managed means both come from the provider under one contract.

Everything else follows from that. Licensing, who tunes thresholds, what happens at renewal, and what you are left holding if the engagement ends are all downstream of the tooling question rather than separate decisions.

Which means the honest first question is not about features. It is whether the monitoring investment you already have is genuinely working, or whether it is a sunk cost being defended out of habit.

Side by side

What actually differs.

Co-ManagedFully Managed
Monitoring platformYour existing tools — SolarWinds, Nectar or your ownThe provider's platform and NMS
LicensingYou keep your existing licencesIncluded, nothing separate to manage
NOC engineersThe provider's, operating your platformThe provider's, operating their platform
Level 1 resolutionIncluded — ticketing, resolution, escalationIncluded natively
Best whenYou have monitoring investment worth keepingYou want software and engineers under one contract

When co-managed is the right shape

Co-managed exists specifically to extend an existing team rather than replace one, and it is usually correct where the tooling is sound and the gap is human.

  • You have already invested in a platform your team knows and the dashboards are genuinely used.
  • The gap is coverage hours rather than capability — most often overnight and weekends.
  • You want to keep configuration control, because your change process is built around the current tooling.
  • Compliance or procurement constraints make moving monitoring data to a provider's platform its own project.

When fully managed is the right shape

Fully managed removes a set of decisions rather than adding people to them, which is worth more than it sounds where nobody currently owns the tooling well.

  • There is no existing platform, or the existing one is licensed and not meaningfully used.
  • Nobody internally owns threshold tuning, so alert noise has been accumulating unaddressed.
  • You would rather hold one accountable party for both detection and response than split it across a licence and a service.
  • Renewal timing on the current platform is forcing a decision anyway, which makes the comparison a genuine one rather than a hypothetical.

Questions that decide it

These separate a tooling problem from a staffing problem, which is the distinction the two shapes actually address.

  • What is currently monitored, and what is monitored in the sense that a tool is installed but nobody reads the alerts?
  • Which alerts fire that nobody acts on, and would anyone notice if they stopped firing?
  • If the platform vanished tomorrow, what would you actually miss — the data, the dashboards, or the licence you already paid for?
  • Is voice covered by the same platform as data, or is it on a separate track nobody watches?

An organization that cannot answer the first question has a tuning problem before it has a sourcing decision, and either shape will underperform until that is dealt with. Threshold tuning is part of onboarding for exactly that reason.

Related

Where to go next.

Scope the function, not a bundle.

A NOC assessment reviews what is monitored today, what is not, and which shape fits the gap.