A strong MSP proposal reads like a contract draft. A weak one reads only like a sales document.

You have a proposal in front of you. It runs thirty to eighty pages, a signature date is approaching, and most of it is template: a capability narrative at the front, named tooling and certifications in the middle, a few case-study summaries and team bios, and a commercial section at the back. The question underneath the page count is simple and uncomfortable: is this actually right, and what is hidden in the parts nobody has time to read as a contract?

Start where the risk usually hides
The short answer

A strong proposal reads the same way backwards and forwards. The scope schedule names inclusions and exclusions with equal specificity. The service levels are defined with measurement method, exclusions and customer remedies. The operating model names who is accountable. The transition-out clause is a real deliverable, not a placeholder. A weak proposal is legible only as a sales document, persuasive at the front and silent exactly where the operational risk lives. This page sets out where to look, what good looks like in each place, and the evidence to ask for before you sign.

Scope and exclusions

Scope is defined by what is explicitly included and what is explicitly excluded.

The most common scope pattern in weak proposals is inclusions by narrative and exclusions by silence. The capability section describes what the provider does in attractive terms, and there is no matching schedule listing what is specifically out of scope.

The stronger pattern is a named scope schedule with two columns, inclusions and exclusions, listed with equal specificity. "Microsoft 365 backup" becomes "Exchange Online mailboxes, OneDrive for Business, SharePoint sites and site configuration," with retention and restore testing stated.

The single most under-read section of any proposal is the assumptions and exclusions appendix — and the single most dangerous exclusions are the ones not listed there because they were never raised in the capability narrative at all.
Service levels

Headline SLA numbers are almost always strong. The fine print is where the real commitment lives.

A 99.9% uptime SLA is near-meaningless without a definition of what counts as downtime, how it is measured, what exclusions apply, and what remedy exists if the SLA is missed.

The operational value of a service level is set by variables that rarely appear in the headline:

  • Severity classification — and who decides it
  • Response versus resolution — which one is actually committed
  • Measurement method — and reporting cadence
  • Exclusions — the events that pause the clock
  • Remedies — what the customer actually gets when the SLA is missed
  • Tier criteria — the definitions behind each severity level
Incident response deserves particular scrutiny, because it is where the gap between capability and delivery most often surfaces. ACSC managed service provider guidance is explicit that incident-notice commitments should be timed in hours, not described as "prompt" or "as soon as practicable."
Security evidence

Certifications are a prerequisite, not evidence.

The security section of most proposals is dominated by certifications and partnerships: ISO 27001, Essential Eight aligned, Microsoft Solutions Partner, vendor gold tiers. These are legitimate prerequisites, but they describe what a provider is entitled to do, not what they actually do in a live environment.

ACSC guidance is specific about the evidence a buyer should expect: incident-notice requirements timed in hours, least-privilege and attributable support access, and defined log retention. The test that separates strong providers from weak ones is whether they can produce sample evidence from a current managed environment, redacted where necessary and with permission.

A provider who cannot produce a sample Essential Eight self-assessment, a sample incident report, or evidence of how privileged access is controlled is asking to be trusted on the strength of a logo.
Operating model

The test is whether you can name who does what when something goes wrong at 2am.

The operating-model section usually describes capability, team structure and tooling. It rarely describes the mechanics of how work actually gets done. A capable proposal names the senior engineer accountable for the account and describes the RACI for a Severity 1 incident: who is responsible, who is accountable, who is consulted, who is informed.

Named accountability matters because the quality of judgement in managed services compounds with familiarity. A senior engineer who has run a specific environment for six months makes better decisions than a fresh engineer working from a ticket. The weak pattern is the team-pool model, where "the team" handles everything and no individual is accountable for knowing your environment well.

The operational test is simply whether the proposal can name the person who will be paged at 2am — and whether that person will already understand what they are looking at.
Onboarding

Onboarding quality is the strongest early predictor of steady-state service.

Onboarding is where a provider either takes the environment seriously or does not. The value of that work compounds over the whole relationship: the engineer who builds the initial runbook is the same engineer paged when something breaks eighteen months later, and the asset inventory built in week one is what makes the day-500 incident fast to resolve.

A strong onboarding produces:

  • an asset inventory
  • a network discovery
  • a risk and remediation register
  • a baseline security-posture assessment
  • a documented runbook
The proposal test is whether onboarding is described as a project with named phases, deliverables and timeframes, or as a brief administrative prelude to service commencement. "Onboarding takes approximately two weeks" with no named deliverables is a signal that the environment will never be properly documented.
Commercial structure

Headline monthly fees are simple. The cost visibility behind them usually is not.

Most proposals quote a headline monthly fee per user or per device, with optional add-ons. The structure is easy for executives to compare across proposals, which is exactly the problem: two proposals at a similar headline rate can hide very different inclusions, exclusions and margins.

The stronger pattern:

  • An unbundled price book — each service priced individually even when a bundled rate is offered
  • Microsoft 365 licensing passed through at cost — with a documented margin
  • Add-ons priced before they are needed — rather than discovered later
Renewal mechanics matter more than most buyers realise at signature. ACCC unfair contract term enforcement has documented the recurring patterns to watch for: automatic renewal without a reminder obligation, unilateral price-change rights, and notice windows long enough to trap a customer into another term. The same mechanics drive vendor lock-in more broadly.
Transition-out

“Reasonable assistance at then-current rates” is not a transition-out commitment.

The transition-out section of a weak proposal is typically one undefined paragraph near the end of the schedule. The language is permissive and vague: transition assistance provided on a reasonable basis, at then-current rates.

The stronger pattern is a pre-agreed transition-out schedule that sits in the contract as a named deliverable, listing specific items to be handed over: tenant and subscription inventory, domain and DNS inventory, a backup inventory with restore validation, documentation, and credentials.

The principle underneath is simple. Transition-out is the most important clause in the contract for the customer, because it is the clause that decides whether the relationship is genuinely optional or quietly captive. Providers who take transition-out seriously are signalling that they intend to be retained on merit.
A useful test

Open the proposal at the transition-out clause. If it reads "reasonable assistance at then-current rates", you have found the page most worth negotiating before you sign.

Bring in an independent view →
Weak signals

No single signal is disqualifying. Clusters are.

Every proposal carries template language somewhere. What matters is pattern: where weak signals cluster, and whether the provider addresses them with specific, evidence-backed language when raised, rather than offering to "clarify in conversation." The signals below are drawn from ACCC unfair contract term enforcement, ACSC managed service provider guidance, ASBFEO small-business dispute patterns, and documented handover failures.

01
"Reasonable transition assistance at then-current rates."
02
Scope described by capability narrative only, with no exclusions schedule.
03
Headline SLA numbers with no fine print on measurement, exclusions or remedies.
04
Security posture described via certifications only, with no operational evidence.
05
A team-pool operating model with no named accountable engineer.
06
Bundled pricing with no unbundled price book behind it.
07
Automatic renewal with no reminder obligation.
08
Unilateral price-change rights.
09
Provider-held admin and registrar control, with no customer ownership.
10
Onboarding compressed to a brief administrative prelude.

Three or more clustered in one proposal — especially in the transition-out, commercial or operating-model sections — is the threshold for getting an independent view before you sign.

If three or more of these signals cluster in the transition-out, commercial or operating-model sections, that is the threshold for an independent view before you sign — a senior-led review of the specific proposal in your hand, with findings documented whether or not you keep the incumbent.

Get an independent view
Inlight IT view

The pre-signature hour is the highest-leverage hour you will have.

The leverage curve is steep. Before signature, you can require specific wording, specific evidence and specific deliverables. At renewal, amendment is possible but harder. After signature, remediation is partial and usually depends on provider cooperation you no longer have the commercial leverage to command. Every hour invested in reading the proposal as a contract pays back in far more leverage than the equivalent hour spent after the fact.

That is where an independent view helps. A senior-led review of the specific proposal in your hand, against the domains, weak signals and evidence requirements on this page, with the findings documented whether or not you keep the incumbent, and a written recommendation any competent engineering team could execute.

The point is not to talk you out of a provider. It is to make sure the written commitment matches the operational reality before it becomes the thing you live with.

Common questions

FAQs about reviewing an MSP proposal.

Which sections most often hide risk?
The transition-out clause, the assumptions and exclusions appendix, and the SLA fine print. These are the least-read sections and the ones where weak commitments do the most damage.
What evidence should I request before signing?
Sample evidence from a current managed environment, redacted and with permission: an Essential Eight self-assessment, a sample incident report, and evidence of how privileged access is controlled and logged. Certifications alone do not answer the question.
How should I evaluate SLAs?
Ignore the headline number and read the six variables behind it: severity classification and who decides it, response versus resolution, measurement method and reporting, exclusions, remedies, and the criteria for each tier.
What does a weak transition-out clause look like?
"Reasonable assistance at then-current rates," with no named deliverables. A strong one pre-agrees a transition-out schedule as a contract deliverable, item by item.
Is this different from legal review?
Yes, and they are complementary. Legal review tests enforceability and liability. This tests technical and operational reality: whether the scope, security, operating model and exit actually work in practice.
When should I get an independent review?
Before signature, and especially when three or more weak signals cluster in the transition-out, commercial or operating-model sections.
Practical next step

Is there a proposal on the table right now?

An independent senior view before you sign is faster and cheaper than the relationship that follows a signature made on incomplete information — findings documented regardless of the outcome.

Get an independent view