Managed IT Service Terms
Managed IT is in open beta, limited to three founding clients. These terms say what is built and what is not, hold your rate for 24 months, and make sure your documentation and credentials are always yours, so you could walk to another provider on day one if you ever needed to.
Table of Contents
- The Agreements You Sign
- Scope & Status
- What Is Built and What Is Not
- The Free Audit
- The Services
- Response Targets
- Fees & the Beta Rate
- Your Responsibilities
- Access, Remote Support & Data
- Documentation & Ownership
- Data Processing, Regulated Data & Incidents
- Confidentiality
- Term, Exit & No Lock-In
- Warranties & Liability
- Changes to These Service Terms
- Contact
1. The Agreements You Sign
Every Managed IT engagement is made official by one signed document, written in plain English with a one-line summary under every heading. There are two versions:
- Founding Client Agreement: the full version for clients new to us: the agreement plus schedules for your plan and rate (A), response targets (B), build status with initials per row (C), contacts (D) and beta acknowledgements (E). Fifteen pages.
- Simple Client Agreement: the short version for businesses we already know personally and who need it in writing to make it official. Same protections, nine pages, one initial and five tick-boxes.
If you handle regulated data, one of these attaches to the agreement and controls for that data: the HIPAA Business Associate Agreement, the PCI DSS Responsibility Addendum, the CJIS Security Addendum, or the FERPA Student Data Addendum. Ending an engagement uses the Termination & Hand-over Notice, which records the notice, the ground, and a checklist of everything returned.
Both are blank templates you may read before the audit. The copy you actually sign is sent through the Client Portal, which records the signer's name, email, drawn signature, IP address and timestamp: the evidence that makes an electronic signature binding under ESIGN and Florida's UETA. A signed agreement controls over these Service Terms where they differ.
2. Scope & Status
These Managed IT Service Terms ("Service Terms") govern managed IT services provided by SentinelGrid, operated by Mason Collier, a sole proprietor based in the State of Florida ("we," "us"), to a client organisation ("you") during the open beta. They supplement the Terms of Service, Privacy Policy and Acceptable Use Policy. A signed service agreement or statement of work overrides these Service Terms where they conflict.
Managed IT is in open beta, limited to three founding clients, delivered by a small team. That is a deliberate constraint, since three is what can be supported properly, and it shapes everything below: the honesty about what is built, the held beta rate, and the absence of lock-in.
3. What Is Built and What Is Not
As of the date above:
- Live: Helpdesk and ticketing (support.sentinelgrid.us), including email-to-ticket; the Client Portal (portal.sentinelgrid.us); monitoring, alerting and status pages (status.sentinelgrid.us) including per-client private status pages and heartbeat monitors; remote support and device management on enrolled endpoints.
- Designed, not built: automated off-site backups with scheduled restore testing; single sign-on and identity management. Until these are marked live on the build status board, they are not part of the service and you must not rely on them. We will not bill for a capability that does not exist.
- Manual in the meantime: where a capability is not yet automated we may deliver it by hand (for example, configuring and verifying a backup product you already own). The statement of work records what is manual.
The build status board is kept accurate. "Planned" means not built.
4. The Free Audit
Joining the beta list entitles you to a free infrastructure audit: we map your machines, accounts, servers, subscriptions, network and the undocumented things only one person knows how to restart, and give you the written findings. There is no charge and no obligation to sign anything afterward. The audit document is yours to keep and to hand to any other provider.
During the audit you will give us read access to systems and accounts. We treat everything we see as confidential, we do not change anything without asking, and we delete our working copies if you do not proceed.
5. The Services
A Managed IT engagement covers, as specified in the statement of work:
- Monitoring & alerting: servers, sites, endpoints and network gear checked automatically; tickets and alerts are taken 24 hours a day, seven days a week, and worked every day, weekends included; a P1 outage gets a best-effort response within two hours at any hour; on-site visits run Monday to Friday, 3pm to 8pm Eastern, and at weekends by arrangement.
- Backup & recovery: on the roadmap and not part of the service yet. Until it ships, backing up your systems stays your responsibility. Where we check a backup product you already own, by hand, the statement of work says so.
- Endpoint management: inventory and remote support for every laptop and desktop; lost machines locked out. Managed patching is on the roadmap, and automated encryption enforcement and a standard build are in build; none of them is part of the service yet.
- Identity & access: MFA, joiner–mover–leaver handling; single sign-on once live.
- Network & infrastructure: we do not provide a VPN or private network access service. Firewall configuration and server and hypervisor care are on the roadmap and not part of the service yet.
- Helpdesk: a real person, a real ticket queue, and a response target you can hold us to.
Our process is audit → stabilise → take over → improve. The goal after take-over is fewer tickets every quarter, not more billable hours.
6. Response Targets
Response targets are stated in the statement of work and published on the managed IT site. During the beta, targets are for response (a human has looked and replied), not resolution. Tier 1 incidents (a production system down for the whole business) are handled on a best-effort basis at any hour through on-call alerting. We publish, in our monthly report, how we actually did against the targets.
7. Fees & the Beta Rate
- Fees are a flat monthly amount stated in the statement of work, calculated from the published beta rate schedule at sentinelgrid.us/it-services/pricing and your seat and device counts as confirmed at the audit. As of the date above the schedule is: Watch US$149 per month for up to 10 devices plus US$9 per additional device; Support US$45 per user per month, US$195 monthly minimum, no servers included; Manage US$79 per user per month, US$395 monthly minimum, one server included; Operate US$129 per user per month, US$995 monthly minimum, up to three servers included; additional servers US$99 per month; Personal Device Support, an optional add-on for your staff's own devices (section 9), included on Manage and Operate with one remote fix per covered person per month, US$3 per covered person per month on Support with the same allowance, and US$29 for each further fix or for any fix on Watch, with hardware pickup in Central Florida at US$25 per round trip or counted against Operate's included on-site hours; project and out-of-scope work US$95 per hour, quoted and approved in advance; the audit and onboarding at no charge during the beta. Fees are billed monthly in advance and payable within 14 days by the method stated on the invoice.
- Beta rate, held: your per-user, per-device and minimum rates are fixed for the first 24 months of service from your start date, regardless of what we price at afterward. Your monthly total changes within that period only when your own counts change, so a new hire or a new server is added at the same held unit rate, and a leaver comes off the bill from the next month.
- Third-party costs we incur on your behalf (licences, hardware, cloud usage) are passed through at cost unless the statement of work says otherwise, and always with your approval first.
- Late payment may result in suspension of non-critical services after 14 days' written notice. We will never deliberately withhold access to your own data, credentials or documentation over a billing dispute.
- Taxes are your responsibility where applicable.
8. Your Responsibilities
- Name a primary contact with authority to approve changes and spending.
- Give us accurate information about your environment and tell us when it changes.
- Tell your staff that devices are managed and that support conversations are logged; obtain any consent your jurisdiction requires.
- Keep the access we need (admin accounts, physical access where relevant) current, and tell us promptly when someone leaves so access can be removed.
- Hold your own licences for software you use; we will tell you if you are out of compliance but cannot license it for you.
- Comply with the Acceptable Use Policy, particularly the sections on remote access and monitoring.
9. Access, Remote Support & Data
We will access your systems only for the purpose of delivering the Services, using the least privilege that works, and we log remote sessions. Where we need a change that carries risk we will tell you first unless it is an emergency, in which case we tell you immediately afterward. We act as your data processor for data in your environment and will follow your lawful instructions; the Privacy Policy describes the tooling and what it collects.
Credentials we create for your environment are stored in a password manager and belong to you. We keep our own copy only for as long as we are providing the Services.
Personal devices. If you add Personal Device Support, we help the people you cover with their own laptops and phones. You choose who is covered, and you are billed for it. Each session is remote, is started by the employee through a one-time link, and leaves no agent behind; the employee can watch it and end it at any time. We open only what the fix needs. We do not copy or keep the employee's files, and we do not report what is on the device to you: you see how many tickets each person opened, not what they were about. We do not offer backups, so the employee is responsible for their own data, and we stop for their written agreement before any step that could erase it, such as a reset or reinstall. Hardware repairs are referred to a repair shop that bills the employee directly. If we come across what appears to be child sexual abuse material we stop, keep no copy and report it as the law requires. Our liability for this add-on is limited to the fees paid for the ticket concerned.
10. Documentation & Ownership
Everything we document about your environment (network diagrams, runbooks, inventories, credential lists, the audit itself) is yours. We keep it current as part of the service and hand it over in a usable format on exit. Scripts and tooling we write specifically for your environment are licensed to you perpetually; our general-purpose tooling and platforms remain ours.
11. Data Processing, Regulated Data & Incidents
For personal data in your environment you are the controller and we are your processor. Consistent with the processor duties in the GDPR and the U.S. state privacy laws in force in 2026, we will: process personal data only on your documented instructions and for the engagement; keep it confidential and bind our contractors to the same duty; implement the security measures on the Subprocessors & Security Billing & Payments page; help you respond to individuals' requests and to any security or privacy assessment you must perform; return or delete the data at the end of the engagement, as you instruct, within 30 days; list every subprocessor that handles your data and give you email notice, with a right to object, before a new one does; and make available the information you reasonably need to verify all of this. If we believe an instruction would break the law, we will tell you before acting on it.
Regulated data. If you are subject to HIPAA, PCI DSS (currently v4.0.1), the FBI CJIS Security Policy, FERPA, ITAR or similar rules, tell us before we start. Those regimes require their own signed addendum (section 1); until it is signed, keep that category of data out of systems we operate for you. The addendum allocates responsibilities between us. It does not make you compliant, and your own policies, training and assessments remain your job.
Security incidents. If we become aware of a security incident affecting your data or systems we will notify your primary contact without undue delay and in any case within 72 hours of confirming it, with what happened, what was affected, what we have done and what we recommend. We will cooperate with any notification you must make, for example to individuals and the Florida Department of Legal Affairs within 30 days under the Florida Information Protection Act, to HHS under HIPAA, or to a card brand under PCI DSS, and give you a written post-incident summary.
12. Confidentiality
Each party will keep the other's non-public information confidential and use it only for the engagement. For us that covers everything we learn about your business, systems and people; for you it covers our pricing, methods, unreleased work and any vulnerability we disclose to you before it is fixed. This obligation survives the end of the engagement indefinitely for credentials, personal data and security information, and for three years for everything else.
13. Term, Exit & No Lock-In
- The engagement runs month to month from the start date. There is no minimum term.
- Either party may end it with 30 days' written notice. We may end it immediately for non-payment after the notice in §7, for a material breach of the Acceptable Use Policy, or if continuing would be unlawful.
- If we make a material adverse change to these Service Terms, you may exit without notice period and without penalty within 30 days of the change.
- Hand-over. On exit we provide current documentation and credentials, remove our access and agents from your systems, transfer or delete the data we hold for you as you instruct (within 30 days), and give your incoming provider reasonable help for the notice period. We do not charge an exit fee.
- The beta rate is a commitment from us to you, not a lock-in: it does not bind you to stay.
14. Warranties & Liability
We warrant that the Services will be performed with reasonable skill and care by competent people. Beyond that, and except where the statement of work states a specific service level, the disclaimers and limitation of liability in the Terms of Service apply. For Managed IT the liability cap is the fees you paid us in the twelve months before the event giving rise to the claim. We carry no warranty for capabilities marked "planned," for third-party products, or for problems caused by changes you or a third party made without telling us.
We strongly recommend you maintain cyber-liability insurance; our services reduce risk but do not transfer it. On request we will tell you in writing what insurance we carry.
15. Changes to These Service Terms
We may update these Service Terms with 30 days' notice by email to your primary contact. During the beta we expect to, as the service definition firms up, and as a founding client your feedback goes into that definition before it is finalised.
16. Contact
SentinelGrid Managed IT, operated by Mason Collier, sole proprietor, Florida
Email: support@sentinelgrid.us
Tickets: support.sentinelgrid.us · Status: status.sentinelgrid.us · Portal: portal.sentinelgrid.us