Co-Managed IT for New Jersey Manufacturers: Scope Checklist

By Rivell Editorial Team · Updated 2026-08-20

Co-managed IT is a collaborative model where internal IT staff and a managed service provider share agreed responsibilities rather than one party owning the entire environment. Rivell’s co-managed IT services NJ are designed to work alongside existing IT staff rather than replace them, and this checklist applies co-managed IT for manufacturers specifically — sites, production applications, vendor relationships, and change approvals that internal teams typically know best. Use it alongside Rivell’s general co-managed IT guide and manufacturing IT support New Jersey resources to define exactly which tasks stay internal and which move to a provider.

When manufacturers consider co-managed IT

Manufacturers typically look at a co-managed arrangement when internal IT staff need reinforcement in specific areas without giving up ownership of production systems, vendor relationships, or site-level knowledge. Scope in a co-managed relationship may include cybersecurity reinforcement, after-hours coverage, specialized project expertise, network management, cloud services, backup and recovery, application support, help desk, onsite support, infrastructure, and technology planning. Which of these apply — and how much of each — depends on what the internal team already covers and what gaps the written agreement is meant to close.

Internal knowledge that should remain visible

Manufacturing clients may retain internal knowledge of applications, sites, business priorities, and change approvals while assigning agreed operational tasks to a provider. Before defining scope, it helps to document this internal knowledge explicitly so it isn’t assumed to transfer along with a task. Examples worth capturing:

  • Which applications run at which sites, and who administers each one
  • Business priorities that should shape maintenance windows and change timing
  • Who holds final approval for changes to production-adjacent systems
  • Vendor and integrator relationships tied to specific equipment or software

Build the responsibility matrix

Actual ownership of any task varies by organization and must be written task by task rather than assumed from a general model description. A responsibility matrix is the practical tool for this: it lists each workstream, states who makes which decisions, and records what evidence confirms the work was done. The matrix below is a starting structure — the specific assignments belong in the written agreement.

WorkstreamDecisions to documentEvidence to retain
Network and infrastructureWho approves configuration changes and maintenance windowsChange records and configuration documentation
Manufacturing applications and vendorsWho owns each application relationship and vendor escalationVendor contact list and application ownership log
CybersecurityWhich controls the provider manages versus the internal teamMonitoring and control reports referenced in the agreement
Backup and recoveryWho verifies backups and who initiates a restoreBackup verification logs and recovery test records
User supportWhich tickets route to the provider versus internal staffTicket routing rules and support logs
Projects and changesWho approves scope, budget, and go-live for a given projectProject approval records

Network and infrastructure ownership

Network management and infrastructure are common areas of co-managed scope, but the specific division — who configures switches, who manages firewalls, who owns wireless coverage on the production floor — should be documented rather than assumed. The same applies to cloud services: if a provider manages cloud infrastructure alongside on-premises systems, the agreement should state which environments are in scope and which remain under internal administration.

Application and vendor handoffs

Manufacturing environments often run production, ERP, or equipment-specific applications tied to particular vendors or integrators. Application support can be part of co-managed scope, but manufacturing clients typically retain internal knowledge of how these applications connect to production processes and which vendor relationships require internal sign-off. For each application, document who handles day-to-day support requests, who manages the vendor relationship, and who approves updates or changes.

Cybersecurity and compliance boundaries

Cybersecurity reinforcement can be part of a co-managed scope. Cybersecurity and compliance support do not guarantee prevention of incidents or guarantee compliance outcomes — the organization, together with its qualified advisers, determines which regulatory or contractual obligations apply and how they are met. Scope documentation should state which security controls or monitoring the provider handles, which the internal team retains, and where compliance-related evidence needs to be produced for audits or customer requirements.

Backup and recovery ownership

Backup and recovery is a common co-managed workstream. Ownership questions to resolve in writing include who configures and monitors backup jobs, who verifies that backups completed successfully, who initiates a restore, and who tests recovery procedures. Recording these decisions in the responsibility matrix avoids relying on assumptions about who is watching backup status day to day.

Support hours and escalation

After-hours coverage can be included in co-managed scope, but the specific hours, support channels, response commitments, and exclusions must be verified in the written agreement rather than assumed from a general description. The same applies to escalation: which alerts or tickets route directly to the provider, which route to internal staff first, and what the escalation path looks like when an issue spans both teams. These details belong in the agreement, not in this checklist.

Onboarding and access

Before a co-managed arrangement starts operating, both sides typically need to align on access: which systems the provider needs credentials for, how those credentials are provisioned and revoked, and which tools the provider uses to interact with the environment. Vendor dependencies — third-party software or hardware vendors the provider will need to coordinate with — should also be identified and documented at this stage.

Evidence and review cadence

Ongoing co-managed relationships work best when both sides agree on what evidence demonstrates a task was completed and how often the responsibility matrix itself gets reviewed. Evidence, tools, vendor dependencies, and escalation paths should all be verified in the written agreement, and the matrix should be revisited as internal staffing, applications, or sites change.

Provider comparison checklist

When evaluating a co-managed provider for a manufacturing environment, it helps to ask each candidate the same set of scope questions:

  • Which of the workstreams above does the provider offer, and which are excluded?
  • How is after-hours coverage defined, and what channels does it use?
  • What tools does the provider require access to, and how is that access managed?
  • What evidence or reporting does the provider produce for each workstream?
  • How are vendor dependencies for manufacturing-specific applications handled?
  • What does the escalation path look like when an issue involves both teams?

Rivell’s managed IT services in NJ and co-managed IT services NJ pages describe the provider’s general service areas; the answers to these questions should be confirmed in the written agreement for a specific manufacturing environment.

How this differs from Rivell’s general co-managed guides

This checklist is scoped specifically to manufacturing environments and is meant to complement, not repeat, Rivell’s other co-managed IT content. For a broader explanation of what co-managed IT is and how shared responsibility works generally, see What Is Co-Managed IT? Shared Responsibility Guide. For an overview of Rivell’s co-managed offering in New Jersey, see Co-Managed IT Services in New Jersey. Rivell’s separate guide comparing co-managed IT services and managed IT services covers how the two models differ; this page assumes that context and does not repeat it. Broader topics such as co-managed vs fully-managed comparisons and general co-managed IT benefits are covered in Rivell’s existing guides, while this page focuses specifically on manufacturing scope and responsibility-matrix work. For manufacturing IT support New Jersey services beyond co-managed scope, see Managed IT Services for Manufacturing. This page focuses on the scope-definition and responsibility-matrix work manufacturers need before or during a co-managed engagement.

FAQs

Does co-managed IT replace our internal IT staff? No. Co-managed IT is designed to work alongside existing IT staff rather than replace them, with internal teams and the provider sharing agreed responsibilities.

Who decides which tasks the provider handles? Ownership varies by organization. Each task should be assigned in writing — through a responsibility matrix — rather than assumed from a general description of co-managed IT.

Does cybersecurity support guarantee we won’t have an incident? No. Cybersecurity and compliance support do not guarantee prevention of incidents or guaranteed compliance outcomes. The organization and its qualified advisers determine which obligations apply and how they are addressed.

What should we confirm before after-hours coverage starts? The specific hours, support channels, response commitments, and exclusions should be verified in the written agreement rather than assumed.

Can co-managed IT include cloud and backup services for a manufacturing site? Cloud services and backup and recovery can both be part of co-managed scope. The specific division of who configures, monitors, and verifies each workstream should be documented individually.

Conclusion

A workable co-managed IT arrangement for a manufacturer starts with a clear, written responsibility matrix rather than a general description of the model. Documenting internal knowledge, assigning each workstream, and confirming after-hours scope, evidence, and escalation paths in the agreement gives both the internal team and the provider a shared reference point. Review the matrix as sites, applications, and staffing change so scope stays accurate over time.

Facebook
Twitter
LinkedIn