A new internal IT hire usually gets a laptop, a login, and a vague sense that “the MSP handles the rest.” That’s how responsibility matrices quietly fall apart within the first quarter. The businesses that get this right treat the first week as a formal handover, not an afterthought: the new hire needs a working responsibility matrix, provisioned access, and direct contact with the MSP before their first ticket lands, not after.
What a new internal IT hire needs to know on day one
Three things need to happen before a new hire’s first working day, not during it: their DMS and Apple Business access should already be provisioned, they should have a copy of the current responsibility matrix, and they should have a named contact at the MSP, not a generic support inbox. If any of these three are missing on day one, the new hire will spend their first weeks guessing at boundaries that should already be written down. We’ve covered what a responsibility matrix should actually contain elsewhere; the point here is narrower: it needs to exist and be handed over, not reconstructed from memory once the new hire is already three weeks in.
How Apple Business and DMS access is provisioned for a new internal hire
New hires should receive their own role-scoped Managed Apple Account within the existing Apple Business tenant. They should never inherit a predecessor’s credentials. Reusing logins might seem fast, but it breaks the audit trails required for Cyber Essentials and leaves the new hire with permissions that don’t match their specific role.
Should the MSP run a formal briefing session, or is documentation enough?
Documentation alone is rarely enough. Reading a responsibility matrix without context leads to interpretation gaps and informal drift. A brief 30-minute session with the MSP account manager in the first week allows the new hire to clarify the details that a document can’t always capture.
How the responsibility matrix gets communicated and enforced during the transition
The matrix should be reviewed together, function by function, to ensure the hire and the MSP are aligned. After that, enforcement is about habit: resolve the first “grey-area” incident according to the matrix to set a clear precedent for how the partnership works.
What happens if the previous internal IT person didn’t leave clear documentation
If documentation is missing, the MSP should be able to help. Since the MSP has likely been involved since the start, they hold the institutional knowledge needed to rebuild the matrix. A joint session in the first fortnight can reconstruct the documentation from known processes rather than relying on guesswork.
What’s the risk window before the new hire is fully up to speed?
The highest risk is the first 30 days, before the escalation path has been tested and before the hire understands where boundaries sit in practice. The first complex incident is the real test of whether the handover was successful.
If you’re bringing an internal hire into a co-managed setup, we can facilitate the matrix walkthrough and provisioning to ensure a structured start.
Related articles
- Co-Managed IT for Mac Fleets: How DMS (Formerly MDM), Apple Business, and Jamf Licensing Work When Two Teams Share the Fleet
- Moving from Fully Outsourced to Co-Managed IT: What the Transition Actually Involves for a Mac-First Business
- Co-Managed IT: Who Actually Owns What? A Responsibility Matrix for Mac-First Businesses
FAQs
What should a new internal IT hire receive before their first day in a co-managed arrangement?
They should have their own named, role-scoped DMS and Apple Business access already provisioned, a copy of the current responsibility matrix, and a named contact at the MSP. Arriving without these means spending the first weeks guessing at boundaries that should already be documented.
Should a new IT hire inherit the previous employee's login credentials?
No. Reusing a departing employee’s account breaks the audit trail Cyber Essentials assessors expect and gives the new hire permissions scoped to someone else’s role. They should receive their own named account within the business’s existing Apple Business tenant instead.
How long does it take to fully onboard a new internal IT hire into co-managed IT?
Around 90 days for a proper handover. The first week covers access and a matrix walkthrough, independent first-line ticket handling begins by day 30, and the first formal review of the responsibility matrix happens around day 90.
What if the previous internal IT person left no documentation behind?
This is common and recoverable. The MSP usually holds enough institutional knowledge to rebuild the responsibility matrix jointly with the new hire in the first two weeks, rather than the new hire having to reconstruct it alone from old tickets.



















































