ChecklistManaged Services
Running a managed service week to week: a governance checklist
A contract describes a service; governance keeps it that way. Without regular forums, clear decision rights and change control, a managed service drifts from what was signed, and AI-run work drifts faster because a prompt or threshold edit can change outcomes overnight. This checklist covers three governance tiers, a decision-rights matrix, change control for AI configuration, improvement tracking and exit readiness.
On this page
- Why managed services drift between contract and daily work
- Tier 1, operational: daily and weekly checks
- Tier 2, monthly service review: the pack and the decisions
- Tier 3, quarterly executive review: outcomes and direction
- Decision rights between client and provider
- Change control for models, prompts, thresholds and tool access
- Continuous improvement: who claims a benefit and who signs it off
- Exit readiness, reviewed every quarter
- Hypothetical governance calendar for a customer-service managed service
- Questions and answers
- Sources
Why managed services drift between contract and daily work
The contract is fixed on the day it is signed; the work changes every day after. Volumes shift, policies change, systems are upgraded, staff turn over and, in an AI-run service, the configuration itself moves. Small adjustments pile up: an exception rule added to clear a backlog, a confidence threshold lowered to hit a speed target, a report quietly dropped. Each makes sense locally. Together they change the service you bought.
Governance makes those changes visible and puts each decision with the right party. ColdAI's model treats Operate and Optimize as continuing phases rather than a hand-off1, and service management standards such as ISO/IEC 20000-1 describe the same idea as a managed cycle of planning, delivery and improvement2. The checklists below turn that into forums you can actually run.
Tier 1, operational: daily and weekly checks
Tier 2, monthly service review: the pack and the decisions
Tier 3, quarterly executive review: outcomes and direction
Decision rights between client and provider
| Decision | Client | Provider | Forum |
|---|---|---|---|
| Adding or removing processes | Approves | Proposes and prices | Monthly review recommends; executive review decides |
| Priorities within scope | Sets them for the period | Allocates people and automation | Weekly call resolves conflicts |
| Policy exceptions, such as paying without a purchase order | Decides, or delegates within written limits | Executes and logs each one | Reported monthly |
| AI changes that alter decisions or customer-facing output | Approves on evidence | Proposes with re-validation results | Change board |
| AI changes that do not alter outcomes | Informed | Approves and logs | Reported monthly |
| Spend beyond agreed volume bands | Approves | Flags in advance | Quarterly review |
| Incident messages to customers or regulators | Decides and sends | Supplies facts and timeline | Post-incident review |
Adapt the rows to your contract. The test is that every recurring decision has exactly one approver.
Change control for models, prompts, thresholds and tool access
This is the release process inside the service. Approval tiers and confidence thresholds for individual actions an agent takes belong to the agent's own design, covered in human-in-the-loop approvals.
Classify the change
Model or model-vendor version, prompt or instruction edit, confidence threshold, new tool permission or new data source. Give each class a default risk level so routine changes do not queue behind risky ones.
Assemble the evidence
Run the new configuration on a regression set of past items with known right answers and compare it with the current one. For new tool permissions, attach the access review.
Approve at the right level
The provider approves changes that leave outcomes untouched; the client approves anything that alters decisions or customer-facing output.
Release with a way back
Release in stages where volumes allow, raise sampling for a defined period and keep the previous configuration ready to restore.
Record the result
Log versions, approver, evidence and what the post-release samples showed, so an auditor can reconstruct any decision later.
Continuous improvement: who claims a benefit and who signs it off
In the Optimize phase, improvement ideas come from root-cause data, process mining and the people doing the work. Give each backlog item an expected benefit, the measure that will show it and an owner. When the item ships, the provider claims the benefit, but someone on your side, usually the process owner or finance, signs it off against the baseline. Where a gainshare applies, that sign-off is what releases payment.
Exit readiness, reviewed every quarter
Hypothetical governance calendar for a customer-service managed service
Questions and answers
How many governance meetings does a managed service need?
Enough that every recurring decision has a forum, and no more. Most services work with a short daily or weekly operational check, a monthly service review, a quarterly executive review and a change board that meets as often as changes require. If two forums review the same pack, merge them.
Who should chair the monthly service review?
The client's service owner, because the review exists to hold the service to account. The provider's service lead presents the pack and the actions. Chairing from the client side keeps the agenda on outcomes you care about rather than on the provider's own reporting choices.
What happens when the client and provider disagree about whether a target was missed?
Settle the facts before the argument. Both sides should work from the same raw data and the calculation method written into the service schedule, so the first step is a joint reconciliation of the disputed figures. If the disagreement is about what a measure means rather than what it shows, fix the definition through change control instead of litigating each month. Only unresolved commercial disputes should climb to the executive review and then to the contract's formal dispute process.
Should prompt edits really go through change control?
Yes, when they can alter decisions or what customers see. A prompt is part of the service's logic, and a small wording change can shift outcomes at volume. Routine edits that do not affect outputs can follow a light path, but they still belong in the change log.
Sources
- Managed Services: six-phase methodology — ColdAI
- ISO/IEC 20000-1:2018 — Service management system requirements — International Organization for Standardization · checked 10 October 2026