CloudRadial’s Blog for MSPs

Co-Managed IT Portal: One Shared Surface for Two Teams (2026)

Written by CloudRadial | September 30, 2026

Co-managed IT is one of the fastest-growing shapes an MSP relationship can take, and it breaks a quiet assumption most service desks are built on: that there is one client contact who handles tech and everyone else is an end user.

In a co-managed account there are two teams. The client keeps its own internal IT people, often with a lead who owns a budget and answers to their own leadership, and they work alongside the MSP rather than handing everything over. That changes what the client-facing surface has to do.

The short version: a co-managed client is not a fully managed client with an IT person attached. They are two teams sharing responsibility, and what they need most is shared visibility with clean role boundaries and one ticket record both sides trust. A portal that treats the internal IT lead like an end user will not serve a co-managed account, and a shared mailbox with a spreadsheet on the side will not either.

This article covers what co-managed clients actually need, how per-role portal access delivers it, and how the ticket stays clean when two teams touch it.

 

Co-managed is a different animal

In a fully managed relationship, the MSP owns service delivery end to end and the client's people are consumers of it. In a co-managed relationship, the client keeps an internal IT function and the two teams split the work: internal IT might handle day-to-day requests and desktop support while the MSP takes projects, escalations, security, and the parts that need scale. Sometimes the division runs the other way. Either way, two teams now share one environment, and the friction is almost always the same: nobody has a shared view of what is happening, and the boundaries between the teams are fuzzy.

The usual patchwork (email threads, a shared mailbox, a spreadsheet of open items, and the PSA's stock portal that nobody logs into) does not give either side a reliable picture. The internal lead cannot see the whole environment. The MSP cannot tell what internal IT has already touched. Work gets duplicated, or it falls into the gap between the two teams and gets dropped.

 

What co-managed clients need that fully-managed don't

Four things set the segment apart.

Admin-level visibility for the internal IT lead. In a fully-managed account the client contact mostly needs the support loop: report an issue, check status. A co-managed IT lead needs far more: the whole org's tickets, endpoints, licenses, and compliance posture, because they are partly responsible for the environment and they answer to their own leadership for it.

Clear role boundaries. Internal IT staff should see more than end users but not necessarily everything the lead sees, and end users should still get the simple support surface. One flat "client login" cannot express that.

A shared, clean ticket record. When two teams work the same environment, the ticket is what keeps them coordinated. Both sides need to look at the same record and trust it.

Reporting the lead can carry upward. The internal IT lead has a boss. Giving them defensible reporting they can present to their own leadership is a retention lever that fully-managed accounts rarely call for.

 

One portal, two teams, different permissions

This is where the Unified Client Portal's model fits the segment almost exactly. UCP is configured per client and per user role from a single tenant, so the same portal serves very different views to different people. In a co-managed account that means the internal IT lead logs in as a Client Admin with broad visibility into their org's tickets, infrastructure, compliance posture, and reports; internal IT staff get a role scoped to their part of the work without full admin reach; end users get the support surface, where they request help, check status, and complete anything the lead or the MSP requires of them; and the MSP works the partner side, configuring roles and delivering service across every client.

One tier note matters here. UCP Starter includes two user roles per client, while UCP Professional includes up to ten. A co-managed account usually needs more than two once you account for the lead, internal staff, and end users, so co-managed is realistically a Professional configuration. For a closer look at how role-scoped request forms shape intake, see the service catalog.

 

Keeping the ticket clean when two teams touch it

The risk in any co-managed setup is the ticket record fracturing between the two teams. UCP handles this by not trying to own the record at all. The PSA stays the single source of truth for every ticket, and UCP reflects that one record to both the MSP and the client's internal IT, so both sides look at the same thing rather than two divergent copies. UCP is not a PSA replacement, and it does not run the escalation between internal IT and the MSP. That workflow lives where it should, in the PSA.

What UCP adds on top is structured intake. Requests come in through forms with conditional logic, attachments, and single or multi-level approvals, and each form routes straight to the correct PSA board and type. A request lands clean and in the right place from the start, which is exactly what keeps two teams from stepping on each other. The ticket stays the shared, trustworthy unit of work.

If a co-managed client also wants conversational support in the channels their people already use, that is ChatAI, a separate product from UCP, and co-managed client service-desk support is available on ChatAI Enterprise. The portal and the chat are distinct products that fit together, not one bundled feature.

Proving value at review time

The co-managed IT lead has something a typical client contact does not: their own leadership to answer to. That makes reporting a real differentiator. On UCP Professional, the lead can see compliance posture scored against roughly 550 partner-customizable triggers, endpoint and license visibility, and on-demand PDF reports they can take straight into their own leadership meetings. The Planner gives the MSP and the lead a shared roadmap of what is going right, what is going wrong, and what is being done about it. Compliance policies, the Planner, custom reporting, and on-demand QBRs are Professional features. For the MSP, this is what makes the relationship hard to unseat: the internal lead looks good to their own boss because of the surface you provide, and that is a difficult thing for a competitor to price against.

 

The bottom line

Co-managed clients are two teams sharing an environment, and they need a surface built for that: role-scoped visibility so each person sees the right thing, one ticket record the PSA keeps honest, structured intake so requests land clean, and reporting the internal lead can carry upward. One shared portal, configured per role, does all of it. A stock portal and a spreadsheet do not.

See it configured for a co-managed account. Book a demo to walk through role-scoped access, structured intake, and the reporting an internal IT lead can take to their own leadership.

 

 

Frequently asked questions

What is a co-managed IT portal?
It is a single client portal that an MSP and a client's internal IT team both use, with different permissions. The internal IT lead gets admin-level visibility into their environment, internal staff get a narrower role, and end users get the support surface, all from one tenant configured per role.

How is co-managed support different from fully-managed?
In a fully-managed relationship the MSP owns service delivery and the client's people are consumers of it. In co-managed, the client keeps an internal IT function and the two teams split the work, so the client-facing surface has to give the internal side real visibility and clean boundaries, not just a place to report problems.

Can internal IT and the MSP share one portal with different access?
Yes. UCP is configured per client and per user role from one tenant, so the internal IT lead, internal staff, and end users each get a different view. Role granularity is why co-managed usually lands on UCP Professional, which includes up to ten roles per client versus two on Starter.

Does the MSP lose control of the ticket in a co-managed setup?
No. The PSA remains the single source of truth for tickets, and UCP reflects that one record to both teams. UCP does not run the escalation between internal IT and the MSP; it gives both sides the same clean view and structured intake so work is not duplicated or dropped.