List the recurring work
Include monitoring, patching, vulnerability response, backup checks, restore tests, certificate renewal, log review, account review, capacity planning, and incident communication. State frequency and the system of record for completion.
Management must also define the application boundary. A healthy operating system does not mean a failing application is supported.
- Task owner
- Trigger or schedule
- Evidence retained
- Escalation target
Verify outcomes
Ask for a sample patch record, failed-backup alert, restore result, incident timeline, and access review. Reporting should show exceptions, not only green summaries.
Retain customer access to configuration and backups so a provider failure does not remove the recovery path.
Select one managed claim and produce the dated evidence that proves the task happened and the exception path works.