What a Managed IT Services Contract Should Include: Ontario Guide

Most managed IT disputes are not really about service. They are about a contract that never said what the service was: the helpdesk was "unlimited" until a project arrived, and the exit was "simple" until someone asked for the admin passwords. Both arguments are avoided by a few clauses that are cheap to write and expensive to leave out.
This guide walks through what a managed IT services contract should contain for an Ontario business: the documents involved, the scope, the service level agreement (SLA), onboarding, security and data, pricing and the exit. It is written by a provider, IT Rapid Support at 7810 Keele St in Vaughan, so read it with that in mind. It is not legal advice; for a large or unusual agreement, have a lawyer read the final version.
The Documents: Master Agreement, Schedules and the Proposal
A managed IT contract is usually more than one document. The master services agreement (MSA) carries the legal terms: liability, confidentiality, payment, term and termination. One or more schedules or statements of work describe the actual service: which users, devices and sites are covered, what is included and what the SLA is. The proposal you were sold on is often a third document, and it is frequently not part of the contract at all.
That catches people. If the proposal promised quarterly reviews or restore testing, check that the same promise appears in the schedule you sign; with an "entire agreement" clause, anything that lives only in the proposal or a sales email may not bind anyone.
Scope: What Is Included, and What Is Not
Scope is where most of the money is. A good schedule lists the covered users and devices, the sites, the software the provider supports and the recurring work it will do without being asked. For a typical managed agreement that recurring work is the helpdesk, monitoring of servers, workstations and network devices, patching, Microsoft 365 or Google Workspace administration, endpoint protection, backup monitoring and restore testing, and staff onboarding and offboarding.
The exclusions matter as much as the inclusions. Look for written answers on these:
- Projects. Office moves, server replacements, Microsoft 365 migrations and new-site builds are commonly quoted separately. The contract should say how a project is defined and how it is priced, so the line between support and project is not decided after the invoice.
- After-hours work. Is the helpdesk staffed outside business hours, and is after-hours work included or billed at a different rate?
- On-site visits. Included, included up to a limit, or billed per visit? Is travel time charged?
- Third-party systems. Line-of-business software, phone systems, printers and vendor-managed equipment often sit outside scope. The contract should say whether the provider will at least coordinate with the vendor.
- Hardware and licences. Are they bought by you, or supplied and owned by the provider? This becomes important at exit.
"Unlimited support" is only meaningful if the scope around it is written down. Ask what is unlimited, and for whom. Our guide to comparing managed IT quotes goes through the line items that most often go missing from a quote.
The SLA: Response, Resolution and Priority Definitions
A service level agreement should define three things: how issues are prioritised, how quickly the provider responds at each priority, and what happens when it does not. Without the first, the other two are meaningless, because the provider decides what counts as urgent.
Priority definitions are usually tied to business impact. A sensible structure has something like a critical level (the whole office or a core system is down), a high level (a group of users or one important function is affected), a normal level (one user, with a workaround) and a low level (requests and changes). Read the definitions, not just the labels, and check where your real risks fall. A warehouse whose label printers stop shipping goods should not have that filed as a single-user printer ticket.
Then check what each time actually measures. Response time is how quickly someone acknowledges the issue and starts work. Resolution time is how quickly it is fixed, and most providers will not commit to it because some faults depend on vendors and carriers. Neither should be confused with an automated ticket email. Check also whether the clock runs 24/7 or only during business hours, because a four-hour response on a business-hours clock can mean the next morning.
Finally, look at the remedy. Some agreements offer service credits when targets are missed; many offer nothing but a review. Credits are rarely large, so the more useful protections are reporting on response performance and a right to terminate if targets are persistently missed.
Onboarding Terms
The first sixty to ninety days decide whether an agreement works. The contract or schedule should describe onboarding as a defined piece of work: discovery of what exists, documentation, deployment of monitoring and security tools, collection of credentials, and the handover from the outgoing provider. It should also say whether onboarding is billed separately, included, or spread across the monthly fee.
Ask what you will have at the end of it. A reasonable answer is a written inventory of devices, users, licences and systems, a network diagram, a list of who holds administrative access to what, and confirmation that backups have been tested. If you are moving from another provider, our guide on how to switch IT providers sets out the order to secure your domain, admin accounts and backups before notice is given.
Security Responsibilities and Your Data
Security clauses are where vague wording does the most damage, because after an incident everyone reads them very closely. The schedule should list which security controls the provider runs and which remain yours. For example: endpoint detection and response, patching, email filtering, multi-factor authentication, backup and restore testing, security awareness training, and 24/7 threat monitoring. If a control is not listed, assume it is not being done.
It should also be clear about incident response: what the provider will do if you are breached, whether that work is included or billed, and how quickly they will engage.
On data, three points are worth getting in writing. First, ownership: your Microsoft 365 or Google Workspace tenant, your domain and your data belong to you, and the provider holds access on your behalf. Second, privacy: if you hold personal information, PIPEDA (or PHIPA for health information in Ontario) still makes you accountable for it when a service provider handles it, so the contract should require the provider to protect it, to use it only to deliver the service, and to tell you promptly about any breach. Under PIPEDA, organizations must report breaches of security safeguards that create a real risk of significant harm to the Office of the Privacy Commissioner and notify affected individuals, which you can only do if your provider tells you. Third, location: if it matters to you or your clients where data is stored, ask.
Pricing, Changes and Renewal
Managed IT is usually priced per user or per device each month. The contract should say how the count is taken and when it is updated, so a new hire or a retired laptop changes the bill in a predictable way. It should also say how prices can change during the term, how much notice you get, and whether there is a cap.
Check the rate for work outside scope. A project rate or hourly rate written into the agreement avoids a surprise when the first out-of-scope request arrives. Remember that prices in Ontario are normally quoted before 13% HST.
Renewal deserves a careful read. Many agreements renew automatically for another full term unless notice is given inside a specific window before the anniversary. Put that date in your calendar the day you sign.
Term, Termination and Exit
Terms range from month-to-month to three years or more. A longer term can buy a lower monthly rate or spread an onboarding cost, but it should come with a way out if the service fails: termination for persistent SLA failure, not just for non-payment. Also check for early-termination fees and how they are calculated.
The exit clause is the one most often missing, and the one you will be most grateful for. A good one commits the outgoing provider to hand over, within a stated period after notice: all administrative credentials, documentation and network diagrams, backup data in a usable form, and cooperation with the incoming provider. It should say whether that work is included or billed, and at what rate. It should also confirm what happens to tools the provider installed, such as monitoring agents and security software, and to any hardware or licences they supplied.
How IT Rapid Support Writes Ours
For transparency, here is how our own agreements work. We start with a free assessment, then propose one of three plans, Co-Managed IT, Fully Managed IT or Managed IT + Security, as a flat monthly fee priced per user or per device. Our managed plans are month-to-month rather than multi-year lock-ins. Onboarding follows four stages, Assess, Plan, Onboard, Operate, and your Microsoft 365 tenant, your domain and your data remain yours throughout. We do not publish a guaranteed response time on our website; ask us, and anyone else, to put response targets in writing. General IT work outside an agreement is billed at CA$185 an hour plus 13% HST and scoped in writing first.
If you are in York Region, our managed IT services in Vaughan page explains how the agreement is delivered from our Keele Street office. To have an existing contract or proposal reviewed against this checklist, call (289) 582-9930 or contact us.
Frequently Asked Questions
What should a managed IT services contract include?
At minimum: a master agreement with the legal terms, a schedule listing covered users, devices and sites, what is included and excluded, an SLA with priority definitions and response targets, onboarding scope, the security controls the provider runs, data ownership and privacy terms, pricing and change terms, and the term, renewal and exit arrangements.
What is the difference between response time and resolution time in an IT SLA?
Response time is how quickly the provider acknowledges an issue and starts working on it. Resolution time is how quickly it is fixed. Most providers commit to response times rather than resolution times, because some fixes depend on software vendors or internet carriers. Check whether the clock runs 24/7 or only in business hours.
How long should a managed IT contract be?
There is no single right length. Month-to-month gives the most flexibility; a one- to three-year term may lower the monthly rate or spread onboarding costs. Whatever the term, look for a right to terminate if service targets are persistently missed, and note the auto-renewal notice window.
Who owns our data and admin accounts under a managed IT contract?
You should. The contract should state that your Microsoft 365 or Google Workspace tenant, your domain and your data belong to your business, that you keep at least one administrator account of your own, and that the provider hands over credentials, documentation and backups when the agreement ends.
Do Ontario businesses need privacy terms in an IT contract?
If you hold personal information, yes. PIPEDA, and PHIPA for health information in Ontario, keep you accountable for personal information that a service provider handles for you. The contract should require the provider to safeguard it, use it only to deliver the service and notify you promptly of any breach, so you can meet your own reporting obligations.
Share this resource

IT Rapid Support Team
Managed IT & Cybersecurity, GTA
IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.
More from this authorRelated Resources

Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC
Original research: we checked the public SPF and DMARC records of 290 mail-enabled Vaughan business domains on 4 October 2026. Only 17.9% enforce DMARC; 48.6% have no DMARC record at all.
Read more: Vaughan Business Email Security Study 2026: Only 17.9% Enforce DMARC
IT Support for Mississauga Logistics and Warehousing
IT support for Mississauga logistics and warehousing firms: WMS uptime, warehouse Wi-Fi and scanners, EDI and carrier portals, 24/7 shifts, ransomware.
Read more: IT Support for Mississauga Logistics and Warehousing
IT for Medical and Dental Offices in Mississauga
What PHIPA expects of a Mississauga medical or dental office's IT: breach reporting, EMR vendors, backups, MFA, phishing and patient Wi-Fi separation.
Read more: IT for Medical and Dental Offices in MississaugaNeed Expert Security Advice?
Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.
Get in Touch