What is a managed service provider, and what does an MSP actually do?

A managed service provider (MSP) is an outside company that runs some or all of a client's IT under an ongoing contract, usually for a recurring monthly fee: help desk, monitoring, patching, backup, security, and cloud or Microsoft 365 administration. Unlike a break-fix shop, an MSP is paid to prevent problems, not only to repair them.

Managed service provider definition

A managed service provider (MSP) is an outside company that takes ongoing responsibility for some or all of a client's IT under a contract, usually for a recurring monthly fee. Typical scope covers help desk support, device monitoring and patching, backup, security tools, Microsoft 365 or Google Workspace administration, and network management.

The defining feature is the commercial model, not the tools. A break-fix technician is paid when something breaks; an MSP is paid to keep things running, so it earns better margins when problems are prevented. Most MSPs run two core platforms: a remote monitoring and management (RMM) tool for endpoints and servers, and a professional services automation (PSA) tool for tickets, contracts and billing. Senior staff often act as a virtual CIO (vCIO), meeting the owner in quarterly business reviews to plan budgets, renewals and projects.

What does an MSP do day to day?

ServiceWhat the MSP handlesWhat it can see as a result
Help deskTickets, password resets, onboarding and offboardingWhich systems staff rely on
Monitoring and patchingEndpoints and servers through the RMM toolThe age of servers and legacy applications
Backup and recoveryBackup jobs, retention settings, restore testsHow far back archives go
Microsoft 365 or Google WorkspaceLicenses, mailboxes, retention policiesInactive mailboxes and archive size
SecurityEndpoint protection, email filtering, multi-factor authenticationWhere sensitive systems sit
vCIO and planningRoadmaps, quarterly reviews, budgetsUpcoming migrations and system retirements

Look at the right-hand column: systems, dates, retention settings and sizes. That metadata is what makes MSPs good at spotting licensing candidates. The content inside those systems belongs to the client and stays off limits.

How MSPs price their services

Pricing modelHow it is billedWhere it fits
Per userMonthly fee per employee coveredOffice-heavy businesses where people use several devices
Per deviceMonthly fee per endpoint or serverEnvironments with shared or specialized machines
Tiered bundlesPackaged levels with rising scopeClients who want a simple choice
All-inclusiveOne flat monthly fee for a defined scopeClients who want predictable IT spend
Co-managed ITFee for the functions the MSP covers alongside internal ITCompanies with an IT manager who needs tools or overflow help
Block hoursPrepaid hours drawn down over timeSmaller or project-heavy needs

Co-managed IT deserves a note of its own. The client keeps an internal IT team, often a manager and a technician or two, and the MSP supplies tooling, after-hours coverage, security monitoring or project capacity. Responsibilities are split in a written matrix, which also settles who has authority over which systems.

MSP vs IT consultant, MSSP and break-fix

ProviderRelationshipPaid forScope
MSPOngoing contractKeeping IT runningBroad IT operations
Co-managed MSPOngoing, shared with internal ITDefined functionsAgreed slices of IT
IT consultantProject or advisoryAdvice, design, projectsSpecific initiatives
MSSPOngoing contractSecurity monitoring and responseSecurity only
Break-fix shopAd hocHours when something breaksWhatever failed
Value-added resellerTransactionalMargin on hardware and softwareProcurement and installation

Why MSPs spot data-licensing candidates early

Owners call their MSP when systems change: a Google Workspace to Microsoft 365 move, a tenant consolidation during post-merger integration, a legacy server due for retirement, a help desk platform being replaced, or a round of software cuts. Each of those moments decides whether years of tickets, chat history, project files and email survive.

Good candidates are US clients that reached 50+ full-time employees at peak (contractors excluded), have operated and documented their work for several years, keep records in many systems (strong companies often run 10-15+), own the rights to those records and have an owner or executive willing to explore a license. Seat counts in the PSA include contractors and shared mailboxes, so ask the owner for peak full-time headcount rather than reading it off a license report. The who qualifies page lists the full baseline.

The rule: introduce, never touch client content

An MSP may tell an owner that data licensing exists and, with the owner's permission, introduce them to SourceX. It never opens, exports, samples, screenshots or describes client content for a referral, even though its admin credentials make that technically possible.

The reasons are contractual and legal as well as ethical. Master services agreements usually carry confidentiality terms. MSPs serving clinics or health plans often sign business associate agreements, covered in the explainer on HIPAA business associates. And California's privacy law requires a business that discloses personal information to a service provider or contractor to have a written agreement limiting its use to specified purposes (Cal. Civ. Code § 1798.100); a referral is not one of those purposes. This is general information, not legal, tax or financial advice, so check your own contracts with counsel.

  • Raise the idea in a quarterly review or vCIO meeting, not inside a ticket.
  • Get the owner's permission before sharing the company's name.
  • Share only basic fit information: industry, peak headcount, years in business, systems in use.
  • Keep exports, samples and screenshots out of every conversation with SourceX.
  • Let the company run its own data inventory once it engages.

How the introduction and reward work

  1. You register, then send the owner your referral link, which takes them to sourcex.si/apply with your code attached, or you submit the company through the referral form.
  2. SourceX qualifies the company with its owner, CEO, CFO or another authorized sponsor.
  3. The company completes its data inventory and chooses who on its own side does that work.
  4. Price and terms are agreed, AI labs and data buyers review, and the deal closes with delivery under agreed redaction rules after an executed agreement.
  5. The company is paid, and only then is your reward paid.

Credit works differently from vendor deal registration: it goes to the first valid referrer whose introduction leads to a verified company application within the attribution window. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee. The reward comes out of SourceX's fee, never out of what the client receives, and no reward is guaranteed.

Next step

Start with the MSP partner overview, test one client against the company fit checker, which gives an early screen that commits no one, then register as a partner.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

What is the difference between an MSP and an internal IT department?

An internal IT department is staff on the company's payroll; an MSP is an outside firm under contract. Many mid-sized companies use both in a co-managed arrangement, where the internal team owns priorities and relationships while the MSP supplies tooling, round-the-clock monitoring, security operations or project capacity. The written responsibility matrix decides who does what.

Do MSPs have access to client data?

Technically, often yes, because administering mailboxes, servers and backups requires privileged credentials. Contractually, that access is limited to delivering the agreed services. That is why an MSP referring a client for data licensing works only from what it knows about systems and timelines, never from the content of email, files, tickets or databases.

What is co-managed IT?

Co-managed IT is an arrangement in which a company keeps its own IT staff and hires an MSP to cover defined functions, such as monitoring, patching, security or after-hours support. It suits companies that have outgrown a fully outsourced model but cannot staff every specialty in house. Responsibilities, escalation paths and system authority are set out in a shared matrix.

Can an MSP itself be a candidate for data licensing?

Possibly. An MSP or IT services firm with 50+ full-time employees at peak (contractors excluded) and years of its own tickets, runbooks, project records and engineering history can fit the baseline. Because much of that history concerns client environments, client contracts and redaction needs must be reviewed first, and some material may have to be left out.

Should an MSP tell the client about a referral reward?

Being open about it is good practice: tell the owner you may receive a referral reward from SourceX if a deal closes, and that it comes out of SourceX's fee rather than their proceeds. Check your master services agreement, any vendor-neutrality commitments you have made and any rules that apply to your firm before making the introduction.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment