Ask your IT leadership two questions at the next meeting. How many distinct AI tools did our staff use last month, and which of them can read company data. Then wait. If what comes back is an estimate rather than a list, the interesting part is not the gap itself — it is that nothing in the way IT is scoped, contracted, or measured was ever designed to produce that list.
Stated as opinion, because it is one: that gap is the clearest way to understand what a managed services provider is for in 2026. The traditional scope — devices, patches, uptime, tickets — describes a company shaped the way companies were shaped when the scope was written. The work moved. The contract did not.
The agreement counts endpoints. The incident starts in a consent screen.
Open your current IT agreement and read what it enumerates. Almost certainly workstations, servers, perhaps network gear, priced per seat or per device. That structure was sound when the boundary of the business was a building with a firewall at the edge and company-owned laptops inside it.
Consider where an incident actually begins now. A user approves a sign-in prompt they did not initiate. Somewhere in the tenant, a third-party application holds a consent grant nobody reviewed. Two years ago an engineer created a service principal for an integration, and its permissions have not been examined since. Session tokens get replayed from unfamiliar countries. None of that touches the endpoint in the way endpoint tooling expects, and none of it appears on a device inventory.
The practical consequence for an executive: a Conditional Access policy now does more to set your blast radius than any firewall rule, and it appears nowhere on an invoice. Identity is the perimeter. Non-human identities — service accounts, API keys, app registrations, integration tokens — are the part of that perimeter with no manager, no offboarding date, and nobody who notices when one goes quiet. If your organization has counted its own, you are ahead of the conversation, because a device-priced agreement would never produce that count. A provider whose cybersecurity scope is defined by agents installed on hardware is defending the version of your company that existed a decade ago.
Availability is the floor, not the product
Pro Link Systems publishes its service metrics and stands behind them: a 24/7 help desk that is in-house and US-based, calls answered live with no phone tree and no hold queue, an average ticket first-response time of 15 minutes, 90% first-contact resolution, and average resolution under an hour. Those figures are real and measured. They are also the floor. Responsiveness is what a provider owes you before the conversation about value begins — necessary, easy to measure, and not the reason to hire one in 2026.
What is genuinely scarce is judgment applied consistently. Somebody has to decide what Microsoft 365 Copilot is permitted to index, which requires understanding that an assistant of this kind answers inside the permission model it inherits. It grants no new access. Instead it makes existing access efficient. Suppose a SharePoint site was over-shared years ago because sharing was faster than structuring. A well-phrased question will now surface that content to anyone already entitled to ask. Nothing is attacked. No control fails. The system does precisely what it was configured to do, and sensitive material walks into a summary.
That is not a product defect. It is a governance decision nobody owned, discovered a year and a half late.
Shadow AI is a procurement failure before it is a security failure
The instinct when shadow AI comes up is to reach for blocking. Analysis, drawn from how every previous wave of consumer-grade software entered the enterprise: blocking on its own does not hold, because the tool arrives on a personal card and a browser tab, and the person using it is trying to finish their work faster.
Watch the actual mechanism of loss. Nobody exfiltrates anything. An employee pastes a client contract into a general-purpose assistant to get a plain-language summary. Finance uploads a payroll export to build a forecast. A sales manager connects a note-taking tool to the calendar and grants it permission to read every invitation, attachment, and attendee list in the tenant. Each of those actions is reasonable in isolation. Together they form a stack of consent screens no governance process ever saw.
The response that works is unglamorous: a sanctioned path that says yes quickly. Maintain a short list of approved tools with enterprise data terms. Publish an intake process with a real turnaround time. Control, at the tenant level, which third-party applications can be granted access to company data without an administrator in the loop. Governance that only says no gets routed around, and then the exposure is unchanged with less visibility than before.
Five renewal questions that reveal which decade a provider works in
If you want an honest read on where your provider actually operates, the renewal meeting is the place to find out. Five questions, and the quality of the answer matters more than the answer.
- Who owns our identity control plane, and what can change in it without my approval? If nobody can describe the change process for Conditional Access, there is not one.
- What is our inventory of non-human identities? Service accounts, API keys, app registrations, integration tokens. A shrug here marks your largest unmanaged attack surface.
- If ransomware landed tonight, what proves the backups are immutable, and when was a restore last tested end to end? A backup that has never been restored is a belief, not a capability. Ask to see the disaster recovery test record with a date on it.
- What is the approval path for a new AI tool, and how many business days does it take? That number is the speed at which shadow AI stops being necessary.
- Which of our SaaS tenants has no active administrator? Every application bought by a department rather than by IT is a candidate. The ones still holding live data are worth finding first.
Notice what none of these questions ask about. Ticket volume does not appear. Neither does uptime percentage, nor the count of devices under management. Those figures describe effort, and effort was never the thing you were buying.
What you are actually buying now
Here is the honest description of a modern managed IT relationship: accountable ownership of a control plane you cannot see, exercised by people who make the same decision the same way every time, and who can explain that decision to an insurer, an auditor, or a board.
That is a different purchase than labor by the endpoint. It changes who you should be talking to at the provider, what belongs in the quarterly review, and what belongs in the agreement itself. If your reviews are dominated by ticket counts and hardware refresh schedules, the relationship is competently serving a version of your business that has already been replaced.
The companies that handle the next few years well will not be the ones running the most tools. They will be the ones where a named person is accountable for the decisions those tools encode, and where the executive team knows who that person is.
Pro Link Systems has run IT for Los Angeles businesses from Woodland Hills since 1999. If your agreement still measures devices instead of decisions, our approach to managed IT services is worth twenty minutes of your time.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.