Chapter 8Handbook

How we work with you

Onboarding, hold points, escalation

We do the work well first. Referrals come from that, not from a sales campaign.

What Concierge IT means

You will see Concierge IT across the rest of our site, so it is worth being precise about it. Most providers use a word like that as the name of their expensive tier.

It is not a tier and it is not a product. Concierge IT is the method: how we deliver whichever of the three managed services in Chapter 7 you are on. Support, Security, Intelligence, or all of them, the way we work is the same.

The rest of this chapter is that method, written down so you can hold us to it.

How an engagement starts

1

A conversation, then an assessment

The assessment is free and there is no obligation at the end of it. We look at what you are running and score it honestly against the ten points in Chapter 4, including the ones you will not enjoy hearing.

2

A proposal you can read once

The fixed monthly figure, any uplift work priced separately, and the assumptions it rests on. If something we assumed turns out to be wrong, you hear about it before the work starts.

3

Onboarding, where the list gets built

Every system, service and account, with a name against each. It goes into your own SharePoint, not only ours. You also get the escalation path in writing, so nobody is guessing who to call at 6:30 in the morning.

4

Then the monthly rhythm

Support and monitoring day to day, and a report each month covering the six things listed in Chapter 5. Including the months we miss a target.

Hold points

On site, a hold point is a step that cannot proceed until someone has checked it. Nobody argues about them because everyone has seen what happens when work gets covered up before it was inspected.

IT needs the same thing, and the places it needs them are the places money and access move.

  • A change to bank details on an invoice or a supplier record. Verified out of band, against a number you already held, not the one in the email asking for the change.
  • A new account, or an existing account gaining admin rights.
  • Someone leaving. Access dies the same day, and there is a record that it did.
  • Anything that moves data out of your tenant.

Verify the change, not the invoice. The tooling supports the procedure, it does not replace it, and a control nobody follows is not a control.

The hold points we run on ourselves

Fair question at this point: who checks us. We hold the admin rights. If hold points only apply to your business and not to the provider carrying your keys, they are not a standard, they are a sales pitch.

  • Changes are approved before they happen. Production changes are approved by our service delivery manager, which means the person making the change is not the person signing it off.
  • Significant work gets a second set of eyes before it touches anything live.
  • Privileged access is checked out, not standing. Nobody sits logged in with admin rights all day waiting for something to break.
  • Restore tests run to a schedule, not when somebody remembers. The dates and results are in your monthly report whether the news is good or not.

The team shares the responsibility for all of that. Craig carries the accountability for it.

Which is the same split Chapter 1 asks you to accept about your own business. You can subcontract the work. You can never subcontract the duty. It would be a strange thing to publish and then not apply to ourselves.

Coverage and escalation

During coverage hours we work issues as they come in, against the response and restoration targets in Chapter 5. Outside those hours we respond to critical issues only, through the escalation path handed to you at onboarding.

When something is broken you get a person, a priority, and an expected time. If the priority looks wrong to you, say so and we will move it. You know what stops your business better than we do.

How we roll anything out

This is the part most providers get wrong, so it is worth explaining with the story that taught me.

I spent a stretch doing health and safety and compliance for a plumbing and civil business.

Here is something you probably do not know unless you are a plumber. Your house is earthed through a copper rod in the ground. If that neutral connection fails, the electricity still has to go somewhere, and because water systems are copper, it will happily go through the water line instead.

Which is fine, right up until someone unscrews the water meter, grabs one side in each hand, and pulls. The current goes across from one arm to the other, straight through the heart. That has killed people.

There are safety systems for it. Isolating gloves, bridging clamps, keeping yourself out of the water. All of it works, and people skipped it. Not because they are idiots. Because it is slower, and it is uncomfortable, and there are eleven more jobs today.

We did not build a new process. The crews were already taking before and after photos for dilapidation records, because if you skipped that you did not get paid. So we bolted onto that. Same iPad, same job, same photos. One more photo showing the bridging clamp on, and the serial number recorded, which was being written on paper anyway.

Is it slower than just ripping in? A bit. Is it hundreds of times safer? Yes.

The fix was not technology. The fix was noticing that people skip the safe way when the safe way is the hard way, and making the safe way the easy way instead.

That is how we roll anything out here. Compliance sticks when the compliant path is the convenient one. We bolt onto what your team already does rather than inventing a new burden for them to resent.

If a control we put in makes your team's day worse, they will route around it, and we will have achieved nothing except a line in a report.