Managed Run is the service layer over agents that already do the work: the catalogue of what is in scope and what deliberately is not, three service levels measured from sources that are not ours, the list of levels we will not commit to yet and the reason for each, and a named person who can stop the whole fleet at three in the morning.
Not ours. Four numbers you already have, multiplied in the order below. Whatever comes out is the figure this offer is measured against — and it is the figure to check with your own finance team before you talk to anyone, including us.
The positions you cover around the clock. Not people — positions. One seat that must be filled every hour of the year.
By the people each position takes. Once you subtract leave, training, sickness and the legal working year, covering one seat continuously takes closer to five people than to four.
By your fully loaded cost per person, for the country you actually staff it in. Use the onshore figure if you have already ruled out doing it elsewhere — most regulated buyers have, and comparing against a blended rate flatters the wrong option.
What you already pay for the out-of-hours premium on every managed line in your contracts. Moving a managed service from business hours to full cover is a consistent, published uplift — and where that uplift is a flat amount per unit rather than a percentage, it grows as a share of the total the larger your estate gets. Pull the figure off your own schedule; you will find the same line in every one.
That is the seam. Agents cover the night at no marginal cost; people do not. What still needs people at night is the decision under ambiguity and the crisis — which is a much smaller rota than the one you staff today, and the only part of it this offer asks you to keep.
We publish no price on this page on purpose. The unit is per governed asset in the units your own schedule already uses, with full cover as a multiplier rather than an invented availability tier, volume tiers as your estate grows, and a capped outcome component on counters that can be verified from outside. Ask us for the schedule when you want it.
Most run proposals hand you a page of percentages. Here is ours, in two halves, and the second half is the one worth reading — because a service level nobody can recompute is not evidence, it is a claim.
Every figure we publish carries four things beside it: the window it was measured over, the system it came from, how much of that window that system actually covered, and whether the source is independent of us. Below the agreed sample size we print insufficient evidence rather than a percentage. Where the record that would tell us how something was handled is incomplete, it counts against us, never for us.
One sheet per service, and beside each one its state. A service with no sheet is not in the service, and an exclusion written down in advance is cheaper than the same exclusion discovered during an incident.
Agents read and act, through a team that owns the action, with a path to act that actually exists.
Incidents and remediation on standardised infrastructure · production change · patch compliance and exposure closure · storage · backup, restore and proven recovery · non-human identity hygiene · governance of the agent fleet · the service reporting itself.
We read your tool continuously and act on what it raises. We do not administer the tool, so we refuse any unit that prices administration we do not perform.
Your monitoring and its probes · your log platform · your configuration database · cloud provisioning, where plans are prepared and verified and a person applies them.
Written into the catalogue as an exclusion, naming who keeps it. We say this before you ask, not after you sign.
Network device administration · the user-facing service desk · database administration beyond observation and recommendation · disaster-recovery failover orchestration · cloud cost optimisation.
Each sheet also carries the part nobody writes down: your coverage hours and ours stated separately, the dependencies and what happens when one is unavailable, your own obligations, a named owner per agent, how each level is measured and whether you can recompute it, the volume envelope, and what counts as a change to the sheet — including a change of model, prompt or autonomy level, because that changes how a production system behaves.
Every class of action holds a level and a budget over a rolling window. The budget is spent by a failed autonomous action, by a rollback, and entirely by a single action taken outside its declared scope.
The class keeps its level and keeps accruing the evidence for the next one — decisions accepted without correction, attempts that stayed inside their bounds, the scope's configuration quality, and every qualification scenario passed on the version actually running.
The class drops back to supervised at once, with no meeting and no notice. That is not a penalty and not a failure of the service — it is the retreat both sides signed for in advance. Failing to carry it out is the breach.
A single event that eats more than a fifth of the budget forces a review with named corrective actions before the class can earn its level back.
The same kind of failure twice sends the class back to recommending only, and its qualification scenarios are extended before anyone discusses promoting it again.
Never automatic. Promotion is decided in the monthly review on a prepared record, and the decision is written down and signed. Stopping is always allowed; restarting is a person's decision.
An action taken outside its scope that actually took effect is a governance breach, and its remedy is control rather than money — the class is suspended, the cause is written up at our cost, and it is re-promoted only after a re-qualification you witness. An attempt that a guardrail blocked is not a breach: we report the count and the cause, and we expect it to be greater than zero, because a period reporting no attempts at all is either a period nobody looked at or a period nobody tested.
A receipt is something a tool can produce. A handover is a named person taking ownership of the record in your own system and saying what happens next.
So no agent in this service holds a tool that can acknowledge an alert, and none can change a ticket's owner or its state. Not as a policy — as a missing capability. It is the difference between measuring a handover and manufacturing one.
The first deliverable is not an agent. It is a measurement of the run as it is today — frozen, signed, with the queries recorded so you can recompute every figure, and with what it does not contain stated. Without a before, nobody can argue about the after.
Volumes by category, severity, scope and hour. The spread of your delays, not the average. Recurrence. Effort agreed by both sides before. Out-of-hours callouts and what came of them.
Backup conformance, event triage, catalogued standard work, patch compliance, configuration hygiene. High volume, low unit risk, procedures already written.
Systems, virtualisation, storage, containers. Autonomous on a known cause with a runbook your team wrote; supervised otherwise.
Production databases, core network security, continuity. Observation and recommendation only — and one of them is watched from wave 1, so the record exists long before anyone asks for action there.
Two more things we ask for, and neither costs money. Keep a hold-out scope: two comparable scopes over the same period, one with agents and one unchanged, because it is the only way to tell the fleet's effect from a quiet quarter. And agree the success criteria in writing before go-live — the metric, the denominator, the source, who adjudicates, and what happens commercially if the answer is no. A gate that cannot fail is not a gate. Headcount is not the criterion: it is computed from the baseline at the end and reported, because a pilot optimised on removing people produces agents nobody dares put into production.
The service depends on things you own. When one of them slips, the honest consequence is not that we failed — it is that the affected class drops back to supervised and that level is suspended, with the date, the measurement and the owner recorded. It resumes when the obligation is met.
Priced per governed asset in the units your own schedule already uses, with full cover as a multiplier, volume tiers as the estate grows, and a capped outcome component only on counters that can be checked from outside. We take a share of savings only where somebody else issues the number — a cloud provider's invoice qualifies; "incidents avoided" does not.
Managed Run holds the service. The work is done by Incident Neutralisation, Change Guard, Fix Squad, Recovery Proof and Identity Hygiene. Coming in is Run Takeover; leaving is Reversibility Dossier.