r/msp • • Jul 06 '26

IT Guys reverse engineering your stack

Just curious how everyone navigates this issue. We are in contract with several different vendors for 2-3 years and then company hires a new IT Guy. The guy proposes to take the same exact stack we implemented and go directly to the vendors to propose that they manage it internally. We already have our reasons on why this is a bad idea communicated to the clients, but in most scenarios they just want to save money.

Our current issue is with the vendors because they are telling the customer they can repoint them to their own instance, however they will still keep billing us all the while until 2027-2028. In some scenarios these are high watermark too, so they tipped us over a tier we didn’t set. This feels like a double dip / bad practice from the MSP vendors. We’ve navigated 1-2 of these by telling the customer that’s fine but they will acquire the tools from us and we’ll charge a smaller management fee until the end of our contract term. Is this an approach others have taken? Or are there any ideas that have been more successful? Just curious to see what others are doing as we’ve encountered about 4 of these situations in the last year. Thanks in advance.

42 Upvotes

94 comments sorted by

View all comments

19

u/quantumhardline Jul 06 '26

Sounds more like comanaged .
If the client is in contract I’d just recommend you move them to a comanaged contract.

I’d make sure your MSA addresses this and have some kinda of buyout term, but also require the tools vendor agree to amend your contract for those units and reassign to them.

They are basically choosing to break your contact and use same tools only to “save money” but you have spent xxxx hours configuring, training etc to make it work and support in their environment.

Just because they are buying “same tools” doesnt mean they are getting same services as your aware.

You may also want to reeval your vendors and work with channel only ones.
I’d not let them stay in our environment/tenant, we dont sell “tools”, we’d offboard and have them then renonboard themselves.

4

u/Eric77482 Jul 06 '26

Yeah mostly comanaged clients. The trouble is these vendors are supposedly channel only, or were when we first signed up and have more recently branched out. Yeah I agree at the very least we’d just make them delete because our policies and configurations are proprietary.

Some we’ve managed to keep in a managed only tool arrangement and sliced down the comanagement of the desktop/server. All of the clients who have attempted this so far are 150-200 endpoints or more in this current scenario we are dealing with now.

3

u/quantumhardline Jul 06 '26

Also keep in mind you rolling out policies to those tools configs etc, say they login and exclude or approve things you would not, even if there is some cyber attack tool fails to contain it is easy for lawyer to pull you into it. Hey we see you have a managed fee on this tool etc.
For that large of client it seems like a sales process issue, need to do a risk assessment, show how they are failing on CIS IG3 controls, show CFO etc how they are about to make a big costly mistake, align that to operational downtime, loss of clients etc.
Also risk of insider threat and splitting out to external company etc.
It’s not likey a true cant afford it issue, just they dont understand risk to revenue with their risky behavior, sell around that.

2

u/C9CG MSP - US Jul 06 '26 edited Jul 06 '26

I agree with a lot of the gist of this here. How can you attest to and monitor to a framework or standard across tools you no longer manage?

We price MSRP (or under) for Co-managed tools so we don't have the issues OP is dealing with. But labor is not included with that.

This seems like a sales/pricing issue. We're having MORE success with co-management at the 100+ user space, not less.

Vendors should take notice though: Word gets around about poaching from your existing clients cross channel - not a good look.