The short answer
Before you sign with any Melbourne provider, get five things in writing: a guaranteed response time with priorities defined, whether onsite support is included, per-user pricing with a list of what is in and out, cyber security as part of the service rather than an add-on quoted later, and what happens when you leave, including who owns your Microsoft 365 tenant, domain and documentation.
Then send an identical scope to two or three providers, ask each for a sample monthly report, and walk away from anyone who will not put response times in the agreement. Our own numbers are published on this site, so you can hold us to the same test.
Choosing a managed IT provider is hard for one specific reason: the websites all say the same thing. Proactive monitoring, fast response, a partnership approach. The real differences only show up later, in the agreement you signed, the report you do or do not receive each month, and the week you decide to leave. So this guide ignores the marketing layer entirely and works through the six places the differences actually live, with the question to ask at each one. We sell managed IT, so read this knowing that, and hold us to every test in it.
1. Response times, in writing
This is the most useful comparison point in the whole process, because it is the only one with a number attached, and two definitions decide whether the number means anything. A response time is the time until a technician is engaged on your issue, not the time until it is fixed. And a target is what a provider aims for, while a guarantee is what it commits to in the agreement. A provider who volunteers both definitions is being straight with you.
We publish ours: a critical issue, the entire business unavailable, gets a remote response within 1 hour in business hours with a 15-minute target, with defined times for high, medium and low priorities including after hours. The full table is here, and it is guaranteed in the AgileMANAGED agreement.
Ask this: What is your guaranteed response time for a critical issue, how is critical defined, and where does it appear in the agreement?
What good looks like: A written SLA with defined priorities, stated business hours, and published after-hours arrangements.
Red flag: A verbal same-day promise that appears nowhere in the contract.
2. Onsite, remote, and what is actually included
Most day-to-day issues resolve faster remotely: passwords, mailboxes, software faults. Some jobs need a person in the building: failed hardware, cabling, office moves. Nearly every provider offers both, so the real question is what your monthly fee includes. We split this deliberately rather than blurring it: AgileCORE is the remote tier, and AgileCOMPLETE includes onsite support and managed servers.
Ask this: Are onsite visits included in the monthly fee, and what is your coverage area?
What good looks like: Onsite inclusions stated in the plan, with a coverage area the provider can actually service.
Red flag: Onsite available on request, with no published rate and travel billed by the quarter hour.
3. Pricing you can compare like for like
Per-user fixed pricing is the model that keeps the provider's incentives pointed the same way as yours, and the figure worth comparing between providers is the all-in per-user number with security included. Ours are on the pricing page: AgileCORE from $85 per user per month and AgileCOMPLETE from $130, which become $129 and $174 with AgileSECURE included, all ex GST. We wrote a full breakdown of what managed IT should cost a Melbourne SMB if you want the market context, and the estimator prices your own headcount.
Ask this: What is the all-in monthly figure per user for our headcount with security included, and what sits outside it?
What good looks like: A published or written per-user price with an inclusions list, and a short, clear list of what is billed separately.
Red flag: A low headline rate that quietly excludes security, projects, licences and after-hours.
4. Security in the service, not on the price list
The gap between providers is widest here, and vague answers are the most expensive kind. At a minimum, a provider supporting an Australian small business should be running multi-factor authentication, endpoint detection and response, patching on a defined schedule, tested backups, email security and staff awareness training as standard. Frameworks give you a ready-made checklist: ask which Essential Eight controls are in place, or where the environment sits against SMB1001. You do not need to be technical to ask, and the shape of the answer tells you plenty.
Ask this: Which security controls are in place for your clients, named individually, and when was one of our backups last restored and shown to us?
What good looks like: Controls listed one by one with a maturity view, and backup restores demonstrated rather than assumed.
Red flag: You are covered, we handle all that. Security described as one product instead of a set of controls.
5. The exit tells you more than the pitch
The healthiest question you can ask a provider you have not hired yet is how you would leave them. Our AgileMANAGED agreements provide for 90 days written notice either way, and our general terms for work outside a signed agreement run on 30 days. We think anything up to a 12-month term is reasonable in this market. What should never be negotiable is ownership: your Microsoft 365 tenant, your domain, your licences and the documentation describing your environment belong to you, whoever manages them. We wrote a separate guide to how switching actually works, because the mechanics matter less than most people fear.
Ask this: If we gave notice tomorrow, what would the handover include, and who owns our tenant, domain, licences and documentation?
What good looks like: A defined offboarding process and written confirmation that you own everything.
Red flag: A multi-year lock-in with automatic renewal, or a domain registered in the provider's own name.
6. Local, and accountable by name
When something is badly wrong, what matters is who answers and whether they know your environment. We are based in Mornington and work across Melbourne and the Peninsula, with meetings at your office, and every client has named people who own the account. Whoever you choose, the test is the same: can they tell you exactly who answers the phone, where that person sits, and which person owns your outcome? Our tagline carries the standard we think any provider should be held to: your business IT, someone's responsibility, by name.
Ask this: Who exactly answers when we call, where are they, and which named person owns our account?
What good looks like: Named people, a local team, and one accountable owner for your environment.
Red flag: A queue with no names attached and an account manager who changes every quarter.
Run the comparison properly
Three providers is the right number. Write your scope once, headcount, servers, the software you depend on and your hours, and send the identical document to all three so the quotes are comparable. Ask each for two artefacts: a sample monthly report, which shows what you will actually receive, and a reference from a business your size. Then take the six questions above into the meetings. You are not testing technical knowledge, you are testing whether specifics are available on request. Our free 10 questions to ask your IT provider checklist covers the same ground in printable form, and what is an MSP explains the model itself if you are starting further back.
One last thing. We wrote this guide knowing you might use it to choose someone else, and that is fine. A provider confident in its service should be willing to hand you the test.