The question comes up at predictable moments. You've hit 50 people and the MSP relationship is starting to strain. You're at 150 and wondering whether the person running point on technology should be an employee, not a vendor. Or you're building a budget and need to understand what each model actually costs before the board asks.

Most of the guidance on this decision frames it as a philosophy question. It isn't. It's a math and operations question, and the right answer shifts at different headcount thresholds. Here's the framework.

What in-house IT, MSP, and co-managed actually mean

In-house technology is a model where the organization directly employs the people who manage its technology environment. That can mean a full team with a technology director, helpdesk staff, and specialists, or it can mean a single person who owns the function. What defines in-house is accountability: technology employees are on your payroll, reporting to your leadership, and responsible for the full scope of your environment.

A managed service provider, or MSP, is a contracted firm that manages a defined scope of technology services on your behalf. Most MSP agreements cover reactive support (helpdesk tickets, break-fix), proactive monitoring (patching, alerting, backup verification), and a set of managed tools such as endpoint protection and email security. Per-seat monthly fees are the most common pricing model in the mid-market. The MSP retains responsibility for service delivery within the contract scope; work outside that scope is typically billed separately.

Co-managed technology is an arrangement where an MSP supplements but does not replace an internal function. Your organization employs at least one internal technology resource who handles strategy, vendor management, and escalation ownership. The MSP handles day-to-day helpdesk operations, monitoring, and defined infrastructure management. Responsibilities are divided by a clear contract: each side owns specific obligations, and the internal resource serves as the primary accountability point for the organization.

This is distinct from a fractional CIO or advisory-only engagement, where an external advisor provides strategic input without owning operational delivery. For companies weighing those options alongside managed services, the Seven Roots services page explains how advisory and operational models interact.

The decision by company size

The framework below assumes a typical mid-market company: one that generates between $25 million and $300 million in revenue, operates in a standard office or hybrid environment, and does not produce software as its primary product. Industry-specific factors are covered in the next section.

Under 50 employees, the answer is almost always a managed service provider. At this scale, a full-time internal technology hire requires you to find and retain someone who can cover helpdesk, infrastructure, security, project management, and vendor negotiations. That combination is expensive to hire for and usually underutilized at low headcount. An MSP provides the same breadth at a fraction of the cost, typically $50 to $150 per seat per month for a comprehensive agreement.

Between 50 and 150 employees, the tipping point begins. Tool complexity grows. Projects multiply. Your MSP starts handling things that require context about your business that it doesn't have. This is when a part-time technology director or internal technology lead begins to make economic sense, even if you keep the MSP for day-to-day support. The internal resource owns vendor relationships, project prioritization, and strategic decisions. The MSP remains the operational engine.

Between 150 and 300 employees, co-managed is usually the right answer. The internal technology function should own strategy, policy, security governance, and vendor accountability. The MSP should own the helpdesk, endpoint management, and infrastructure monitoring. Both sides operate under a clear agreement defining who handles what. This model scales better than a pure in-house team at this size, because the MSP handles reactive volume without requiring you to staff for peak demand.

Above 300 employees, most companies move toward a primarily in-house function. The volume of users, the complexity of the environment, and the strategic importance of technology decisions typically justify dedicated internal staff across multiple disciplines. Security operations, project management, architecture, and vendor management often require separate ownership. Specialist MSPs or co-managed security arrangements commonly supplement internal teams in specific areas.

These bands shift based on industry, compliance posture, and M&A activity. The thresholds above are a starting framework, not a fixed rule.

Comparing the three models: what each delivers

The table below compares the three models across the dimensions that matter most to a company in the 100 to 300 employee range evaluating the decision for the first time. Cost estimates are mid-market approximations and vary by region, MSP, and internal compensation levels.

In-house technology vs MSP vs co-managed at a glance
Dimension In-house MSP Co-managed
Cost structure Fixed payroll, benefits, recruiting Predictable monthly fee (per seat or all-in) Internal salary + reduced MSP monthly fee
Breadth of coverage Limited by headcount and specialization Broad but defined by contract scope Broad across operations; strategic depth owned internally
Strategic capacity High, if staffed for it Low, unless a vCIO service is added High, owned by internal resource
Flexibility Low (headcount decisions are slow) Medium (contract scope expands gradually) High (internal and MSP scope can both adjust)
Vendor accountability Internal (you own the relationship) MSP-mediated (they manage their stack) Split: internal resource owns strategy and contracts
Typical monthly cost, 200-person company $25,000–$40,000+ (salary and overhead) $12,000–$25,000 (per-seat MSP) $18,000–$32,000 (salary and reduced MSP)

The dimension worth examining first is strategic capacity. Most organizations that shift from a pure MSP model to co-managed do so because they've hit a ceiling on project throughput and strategic direction. The MSP is competent at what the contract covers. It is not designed to own your technology roadmap, and most contracts don't ask it to.

Industry and complexity factors that shift the framework

Several factors push the threshold for in-house or co-managed coverage earlier than the size-based framework would suggest.

Regulated industries move the threshold. Healthcare-adjacent companies, financial services firms, and manufacturers with operational technology or industrial control systems frequently need in-house ownership of technology governance before headcount would otherwise call for it. Compliance frameworks such as HIPAA, SOC 2, and the NIST Cybersecurity Framework require a named internal owner for security policies and controls. An MSP can support the work, but the organization needs someone internally who owns the accountability relationship with auditors and regulators. An MSP cannot fill that chair.

M&A-active companies need in-house strategic ownership earlier for the same reason. Technology due diligence, integration planning, and post-close systems work require a person inside your organization who can move quickly and who has full context about the deal. An MSP relationship doesn't provide that, and a co-managed model only functions well if the internal resource was in place before the deal closed.

Private equity-backed portfolio companies often operate co-managed by design. PE sponsors require standardized technology management across portfolio companies, with documented visibility into costs and risks. Co-managed arrangements, with a technology director who can interface directly with the sponsor's operating team, typically satisfy that requirement better than either a pure in-house team or a pure MSP model at portfolio scale.

Security-sensitive environments push toward co-managed specifically to avoid giving the MSP administrative control over the full environment. When one vendor holds all keys, your security posture depends entirely on theirs.

The hybrid and remote-first questions

When people ask whether they can do a hybrid model, the answer is that co-managed is the hybrid model. The question usually comes from organizations that want the cost structure of an MSP but are starting to recognize the strategic gaps it creates. Co-managed is the structured version of that instinct: the MSP handles the volume, and an internal resource owns the direction.

Remote-first companies sometimes assume that in-house technology is harder to justify because many of the traditional on-site advantages disappear. That's partly right. Physical security management and on-site desktop support no longer favor an in-house model when your workforce is distributed. But the strategic leadership argument still holds: someone inside the organization needs to own vendor relationships, make technology decisions, and maintain the security posture. Remote-first companies often find that MSP and co-managed arrangements work well for their environment, since those models already deliver services remotely and don't depend on geographic proximity.

The one area where geography still matters is compliance. If your industry requires on-site security controls, audit access, or documented physical safeguards, you may need an internal resource regardless of where the rest of your team works.

Signals the current model no longer fits

Knowing when to shift models is harder than choosing the right model to start with. These are the concrete signals that your current arrangement has reached its limit.

Reactive volume is exceeding the contract. When your MSP is consistently billing for out-of-scope work, or ticket volume is growing faster than the agreement can absorb, the model has outgrown the contract. The fix is not always a larger contract: sometimes it is an internal resource who reduces ticket volume through better systems and user training.

The MSP has become the de facto technology decision-maker. This is a governance problem. When purchasing decisions, vendor negotiations, and architecture choices are effectively being made by the MSP without internal review, the organization has outsourced accountability along with operations. That exposure tends to surface during audits, security incidents, or acquisitions.

The internal team is underwater and cannot get ahead of the backlog. When your technology staff spend every day in reactive mode with no capacity for projects or strategy, the model is wrong-sized for the organization.

Leadership is asking for strategic technology input the current arrangement cannot deliver. When the board or CEO wants a technology roadmap, a budget defense, or an AI strategy and neither the MSP nor the internal team can provide it, the gap is at the leadership level.

If any of these describe where you are, that's the right moment for an honest outside read. Heartwood is an advisory panel for exactly that kind of decision.