A managed access control service agreement should clearly define what systems and sites are covered, which services are included in the monthly fee, who can request changes, support and escalation expectations, remote versus on-site work, customer and dealer responsibilities, cybersecurity considerations, pricing, renewal and what happens when the service relationship ends.
For security dealers moving from project work into recurring managed services, getting these details right is just as important as choosing the technology.
Key Takeaways
- Define exactly what the monthly managed service includes before the account goes live.
- Separate response targets from resolution targets so customers understand what your team is actually committing to.
- Establish who is authorized to request credential, schedule and access-level changes.
- Clearly separate remote support, field service, hardware repair and customer network responsibilities.
- Document responsibilities for administrative accounts, customer data, cybersecurity and third-party systems.
- Build your agreement around a service model your team can realistically support as the number of managed customers grows.
- If you want to sell managed access control without operating the hosting infrastructure yourself, the hattrix Managed Services Dealer model provides another path.
Why Do Managed Services Need Clearer Agreements Than Project Work?
Traditional project work has a relatively clear beginning and end.
A customer approves a quote. Your team installs the system. The equipment is commissioned. Training is completed. Any warranty or maintenance obligations are defined, and the project moves into regular service.
Managed access control is different.
The installation may finish, but the service relationship continues.
The customer may expect your team to help with:
- adding and removing users
- credential questions
- access-level changes
- holiday schedules
- door schedules
- reporting
- remote troubleshooting
- mobile or web administration
- system changes
- after-hours issues
- network-related troubleshooting
- hardware problems
If nobody defines which of those requests are included, the monthly service can slowly become “call us whenever anything related to access control happens.”
That is where managed-service margins disappear.
One customer asking for an extra ten-minute task is rarely a problem.
Fifty managed customers regularly asking for work that was never accounted for can become a staffing problem.
A strong managed access control agreement is therefore not about creating a wall between the dealer and the customer.
It is about making the relationship predictable.
The customer should know:
What am I paying for?
The dealer should know:
What are we responsible for delivering?
And both sides should know:
What happens when something falls outside that scope?
That clarity is what allows managed access control to become a scalable recurring service instead of an unlimited support promise attached to a monthly invoice.
What Should Be Included in a Managed Access Control Service Agreement?
Every dealer will structure its managed services differently, but there are several areas that should be addressed before the customer goes live.
A practical managed access control agreement should define:
- The systems, sites and doors covered
- The services included in the recurring fee
- Who is authorized to request changes
- How support requests are submitted
- How priorities are classified
- Response and resolution expectations
- Business-hours and after-hours coverage
- Remote versus on-site service
- Hardware, wiring and third-party system boundaries
- Customer responsibilities
- Cybersecurity, data and account responsibilities
- Termination and transition responsibilities
The wording itself should ultimately be reviewed by qualified legal counsel. The goal here is to help security dealers identify the operational questions the agreement needs to answer.
1. Which Systems, Sites and Doors Are Covered?
Avoid vague descriptions such as:
“Managed access control services for the customer’s system.”
That may sound sufficient when the customer has one small location.
It becomes much less clear when the same customer acquires another building, adds ten doors, installs an intrusion integration or asks your team to support a warehouse that was never part of the original project.
Define the environment being managed.
Depending on the account, that may include:
- customer name
- site locations
- number of doors or controlled openings
- access control platform
- specific systems included
- relevant integrations
- managed-service tier
- start date
For multi-site customers, consider maintaining a separate site schedule or service schedule that can be updated as locations are added or removed.
That lets the core agreement define how the relationship works while the schedule defines where it applies.
The same approach can make growth easier.
If the customer adds a new branch, the dealer may be able to add that site to the existing managed-service framework instead of renegotiating the entire agreement.
2. What Does the Monthly Managed Service Actually Include?
This should be one of the clearest sections of the agreement.
“Managed access control” can mean very different things depending on the dealer.
One dealer may primarily provide hosted access control.
Another may include hosting, remote administration and reporting assistance.
A more comprehensive package may include regular user administration, schedule changes, remote troubleshooting and ongoing account reviews.
Potential recurring services can include:
- hosted access control
- remote system access
- standard technical support
- user and credential administration
- access-level administration
- schedule and holiday changes
- reporting assistance
- remote troubleshooting
- account reviews
- system health review
- defined escalation support
My Managed Security’s existing RMR guidance already outlines how services such as hosting, remote administration, user management, reporting and support can become recurring revenue opportunities for dealers.
The service agreement should take the next step and establish which of those services a particular customer is actually buying.
Avoid Unlimited Language
Be careful with phrases such as:
“All user administration included.”
What does “all” mean?
Five changes per month?
Fifty?
Five hundred?
For a small office, it may not matter.
For a customer with high employee turnover, a poorly defined promise can create significant administrative workload.
Dealers can address this in different ways.
You might offer:
- unlimited routine administration within a clearly defined scope
- a monthly allowance
- tiered service packages
- included administration with certain complex changes billed separately
- customer self-administration for routine tasks with dealer support for advanced changes
There is no universal answer.
The important point is that the operating model should be intentional.
3. Who Is Authorized to Request Access Changes?
This is one of the most important questions in managed access control.
Imagine your service desk receives this email:
“Hi, can you give Chris access to the executive offices and warehouse after hours?”
Can your team make that change?
Who sent the email?
Does that person have authority to grant access?
What if the request comes from a department supervisor instead of the designated security administrator?
What if a technician receives the request as a text message?
Managed access control is not simply technical administration.
It involves making changes that affect who can physically enter customer spaces.
The agreement and onboarding process should therefore establish authorized requestors.
That could include:
- primary security administrator
- facilities manager
- HR representative
- operations manager
- designated backup administrator
- other customer-approved contacts
For sensitive changes, the customer may want additional approval rules.
Examples could include:
- executive areas
- server rooms
- medication storage
- warehouse cages
- after-hours access
- high-security areas
The dealer does not need to create the customer’s access policy.
The dealer needs to know who has authority to instruct the dealer to change it.
This is also why customer onboarding matters so much.
The customer should know from day one who can request changes and how those requests should be submitted.
4. How Should Customers Submit Support Requests?
Managed services become difficult to scale when every customer has a different way of reaching the dealer.
One customer emails the service desk.
Another calls the office.
Another texts the technician who originally installed the system.
Another sends a Teams message to the salesperson.
Another waits until something becomes urgent and then calls three people.
Define the proper support channel.
Depending on the dealer, that could be:
- dedicated support email
- helpdesk or ticketing portal
- business-hours phone number
- emergency support number
- managed-service request form
The objective is not to make support inconvenient.
It is to ensure requests can be tracked, prioritized and assigned.
A support request sitting in one technician’s personal text messages is difficult for the rest of the company to see.
A properly documented request can become part of the account history.
That history becomes extremely useful as the managed-service relationship grows.
It can tell you:
- what the customer requests most frequently
- which locations generate the most support
- whether additional training is needed
- whether certain hardware is creating repeat issues
- whether the current service tier still fits the account
That information can later support better customer reviews and more accurate service pricing.
5. How Should Access Control Issues Be Prioritized?
Not every access control request has the same urgency.
Consider these examples:
Request A:
“Please add our new employee before Monday.”
Request B:
“Our holiday schedule needs to be changed for next week.”
Request C:
“One employee’s card is not working at the staff entrance.”
Request D:
“Our main employee entrance is not allowing anyone into the building.”
Those requests should not necessarily enter the same support queue with the same expectations.
Create simple priority definitions.
For example:
Routine Administrative Request
Examples:
- new cardholder
- scheduled employee removal
- report request
- future schedule change
Standard Service Issue
Examples:
- individual credential problem
- isolated door issue
- non-critical configuration question
High-Priority Operational Issue
Examples:
- multiple employees unable to access an important area
- controller communications affecting several doors
- unexpected system behaviour with operational impact
Emergency or Security-Impacting Issue
Examples:
- critical opening cannot be secured
- significant access-control outage
- suspected unauthorized access
- another situation your company specifically defines as emergency service
The dealer should decide what these categories mean operationally before promising them to customers.
What Is the Difference Between Response Time and Resolution Time?
These terms are often treated as interchangeable.
They are not.
Response Time
Response time is how quickly the dealer acknowledges, reviews and begins handling the request.
Resolution Time
Resolution time is how long it takes to completely resolve the underlying issue.
That distinction matters because a dealer can control its response process more easily than it can control every cause of a service issue.
Consider a customer whose access control controller stops communicating.
The dealer receives the ticket at 9:15 a.m.
At 9:30 a.m., a technician begins remote diagnostics.
The technician determines that the customer has lost network connectivity at that location because a network switch has failed.
The dealer responded in 15 minutes.
The dealer cannot necessarily resolve the customer’s failed network switch.
A service agreement that promises a specific resolution time for every access control issue may unintentionally make the dealer responsible for circumstances outside its control.
A better structure defines response expectations and then explains how resolution depends on the type of problem.
An illustrative framework might look like this:
| Priority | Example | Possible Response Target | Resolution |
| Routine | Add a cardholder | Next business day | Based on request scope |
| Standard | Individual access issue | Same business day | Based on diagnosis |
| High | Multiple affected doors | Accelerated response | Based on cause |
| Emergency | Critical security-impacting issue | Defined emergency process | Based on technical and site conditions |
These are examples only.
A dealer should set service targets based on its actual staffing, geography, operating hours and support capacity.
Do not promise a one-hour response because it sounds competitive if your company cannot consistently provide it.
A realistic service promise that is consistently met creates far more trust than an aggressive SLA that is regularly missed.
6. What Does After-Hours Support Actually Mean?
“24/7 support” can mean several very different things.
Does it mean:
- someone will answer the phone?
- someone can remotely review the system?
- someone can make user changes?
- someone will dispatch a technician?
- someone will arrive on site within a guaranteed period?
- emergency administration is available?
- the platform itself is available 24/7?
These are not interchangeable.
Define what the customer receives.
For example, a dealer may provide standard administrative support during normal business hours and a separate emergency escalation path for critical issues.
Another dealer with a larger support operation may provide expanded remote administration after hours.
A third may provide emergency field service but bill after-hours dispatch separately.
All of those can work.
Problems start when the brochure says 24/7 managed support but nobody has defined what happens when the customer calls at 2:00 a.m.
Clarity protects both parties.
7. Which Access Control Issues Are Remote and Which Require a Technician?
Remote management is one of the major advantages of hosted access control, but not every problem can be solved from a browser.
Kantech currently positions hattrix as a hosted and managed access control solution designed to reduce the need for on-site infrastructure and support flexible remote management.
That can give dealers more opportunities to diagnose or resolve problems without immediately sending a truck.
Common remote or remote-first issues may include:
- cardholder status
- credential permissions
- access-level questions
- schedule changes
- holiday changes
- reporting
- operator permissions
- configuration review
- certain communication diagnostics
Other issues may still require physical service:
- damaged readers
- failed locking hardware
- power problems
- broken wiring
- door alignment
- failed physical components
- certain communications or network issues that cannot be isolated remotely
The agreement should explain how field service is handled.
For example:
- Is on-site labour included?
- Is there a discounted managed-customer rate?
- Is all field service billable?
- Are certain visits included each year?
- Is after-hours field service billed differently?
- Who authorizes a truck roll?
Do not let the monthly service fee accidentally become an unlimited on-site maintenance agreement unless that is intentionally what you are selling.
8. Where Does Hardware Responsibility Begin and End?
Managed access control still relies on physical equipment.
Your agreement should distinguish the managed service from:
- readers
- controllers
- locking hardware
- door operators
- power supplies
- batteries
- cabling
- network switches
- customer internet service
- third-party integrations
If a customer’s internet provider experiences an outage, that is different from a hosted platform outage.
If a strike fails mechanically, that is different from an access-level configuration problem.
If a customer’s IT department changes firewall settings without telling the security dealer, the resulting communications issue should not automatically be treated as a failure of the managed platform.
That does not mean the dealer refuses to help.
It means everyone understands which part of the system needs attention and how that work is billed.
9. What Responsibilities Should the Customer Have?
Managed service does not mean the customer has no responsibilities.
Typical customer responsibilities may include:
Maintaining Accurate Employee Information
The dealer cannot remove a former employee’s credential if nobody tells the dealer the employee has left.
Using Authorized Requestors
Access changes should come from approved people.
Providing Site Access
If a technician needs to inspect a physical door, the customer must provide reasonable access to the location.
Maintaining Customer-Controlled Networks
Where the access control system relies on customer networking, responsibilities should be clear.
Communicating Third-Party Changes
If an IT provider replaces networking equipment, a contractor modifies a door or another security company changes part of the system, those changes can affect ongoing support.
Protecting Customer Administrator Accounts
Customer administrators should use appropriate account security and follow the agreed access-control process.
The objective is shared accountability.
Managed access control works best when the dealer and customer both understand the role they play.
10. What Cybersecurity Responsibilities Should Be Defined?
This is becoming increasingly important as physical security systems become more connected.
Cloud services create shared responsibilities across the customer, service provider and other technology partners.
The Canadian Centre for Cyber Security specifically recommends that managed cloud-service agreements clearly delineate account-management responsibilities among the parties involved. Its guidance also addresses areas including identity and access management, remote administration, logging, incident management and related cloud security controls.
For a security dealer, that means the managed access control agreement should at least answer questions such as:
- Who approves administrator accounts?
- Who creates dealer administrator accounts?
- Who removes access when an administrator leaves?
- Who is responsible for customer network security?
- Who controls access to the hosted environment?
- How are remote administrative privileges managed?
- How are important security incidents communicated?
- What happens if credentials are suspected of being compromised?
- Who is responsible for third-party integrations?
- What information is retained when the account ends?
- Who handles platform-level versus customer-level security responsibilities?
The Canadian Cyber Centre’s broader managed-service guidance also emphasizes the importance of clearly defining service provider responsibilities and deliverables in managed-service contracts.
This does not mean the access control dealer needs to become the customer’s cybersecurity provider.
It means connected physical security requires clearer responsibility boundaries than a traditional standalone lock-and-key service.
Do Not Promise “Compliance”
Be especially careful with compliance language.
A hosted environment may provide controls or independent assurance that help customers meet their own security requirements.
That does not automatically make every customer “compliant.”
My Managed Security has separately discussed its 2026 SOC 2-certified environment for enterprise and compliance-sensitive deployments.
That can be a valuable part of a dealer’s infrastructure story, but the customer’s own configuration, policies, access-management practices and regulatory obligations still matter.
Operational note: This article provides business and service-structure guidance for security dealers. Final contract language should be reviewed by qualified legal counsel familiar with your business, jurisdiction and service model.
11. Should You Offer Different Managed Access Control Service Tiers?
Not every customer needs the same service.
A smaller customer may primarily want hosted access control and occasional support.
A multi-site organization may want significantly more administration.
Rather than forcing every account into one package, dealers can consider service tiers.
For example:
Hosted
Potentially includes:
- hosted access control
- platform access
- standard support
- basic account maintenance
Supported
Potentially adds:
- defined remote technical support
- administrative assistance
- schedule support
- reporting assistance
- faster service targets
Managed
Potentially adds:
- expanded user administration
- ongoing access-level support
- regular account reviews
- defined reporting services
- broader remote administration
- enhanced escalation process
These are examples, not prescribed Kantech or MMS packages.
The dealer should create tiers based on:
- customer demand
- staff capacity
- support cost
- customer size
- number of sites
- number of doors
- frequency of changes
- desired margin
The goal is to connect price to actual service value.
That is the natural next step after deciding to use cloud access control as an RMR strategy.
12. How Should Pricing Work as the Customer Grows?
A managed-service agreement should also account for growth.
Imagine a customer signs with:
- one location
- 12 managed doors
- 80 cardholders
Two years later they have:
- four locations
- 48 managed doors
- 600 cardholders
Should the monthly price still be the same?
Probably not.
The agreement should establish how material changes affect the recurring service.
Potential pricing models include:
Per Door
Simple and scalable.
The monthly fee grows as the managed system grows.
Per Site
Useful where each location creates meaningful administrative or support overhead.
Tiered Door Bands
For example:
- small
- medium
- multi-site
- enterprise
This can be easier for customers to understand than calculating every small change individually.
Base Fee Plus Usage
A core monthly service plus additional costs for services or volumes above the included scope.
Custom Managed Package
Appropriate for larger organizations where support requirements vary substantially from a standard customer.
There is no universal best structure.
The existing MMS RMR guidance discusses why cloud access control can turn hosting, administration and support into recurring revenue.
The agreement’s job is to make sure the price can continue to support the service as the customer’s environment changes.
13. What Should Be Defined When the Service Relationship Ends?
Managed-service agreements should explain the exit process before anyone wants to exit.
Questions to address include:
- How much notice is required?
- When does billing stop?
- What happens to dealer administrator access?
- What customer information can or should be provided at transition?
- What documentation belongs to the customer?
- Who coordinates a transition to another provider?
- What happens to dealer-controlled credentials?
- What happens to hosted information according to the applicable service arrangement?
- Is transition assistance included or billable?
- What happens to physical equipment owned by either party?
The exact answer depends on how your service is structured.
The important part is that the customer is not discovering the process for the first time on the day they cancel.
A professional exit process can also protect the dealer’s reputation.
Managed services are built around long relationships, but no customer relationship lasts forever.
How Does Your Hosting Model Affect the Service Agreement?
The promises you make to customers are connected to the infrastructure supporting those promises.
If your managed service depends on a server in your own office, then your company needs to consider who is responsible for:
- infrastructure
- maintenance
- backups
- software environment
- security
- availability
- recovery
- updates
- technical support
- capacity as the customer base grows
That may be the right model for some integrators.
But it is not the only model.
Kantech currently distinguishes between two hattrix partnership approaches.
A Managed Services Provider owns the software, private-cloud environment and customer database.
A Managed Services Dealer can instead partner with a third-party hattrix Managed Services Provider and avoid taking on the infrastructure investment itself.
That creates an important strategic decision for a security integrator:
Do you want to operate the cloud infrastructure, or do you want to operate the managed customer relationship?
For dealers primarily interested in:
- selling access control
- installing systems
- retaining customer ownership
- providing service
- building RMR
- supporting customer administration
the MSD model can allow the dealer to focus on those functions while working with an established hattrix provider for the hosted layer.
This is why the service agreement and the infrastructure model should be considered together.
You should only promise customers a service your company and its partners are prepared to deliver consistently.
Build the Agreement Before You Sell the Package
One of the easiest mistakes when launching a managed service is building the agreement after the first customer says yes.
Instead, define the operating model first.
Before selling your first or next managed access control package, answer these questions internally:
Scope
- What does the monthly fee include?
- What is explicitly outside the recurring service?
Administration
- Which customer requests will we handle?
- Who can authorize them?
- How should they be submitted?
Support
- What are our normal support hours?
- What is our emergency process?
- What response targets can we actually meet?
Field Service
- When do we dispatch?
- Who authorizes the dispatch?
- How is the visit billed?
Customer Responsibilities
- What information must the customer provide?
- What systems remain under customer or IT control?
Cybersecurity
- Who controls administrative access?
- How are accounts added and removed?
- What responsibilities belong to the customer, dealer and hosting provider?
Growth
- What happens when doors or locations are added?
Exit
- How will the account be transitioned if the service ends?
If your team cannot answer those questions internally, the customer agreement will probably not answer them clearly either.
Frequently Asked Questions
What should be included in a managed access control service agreement?
At minimum, define the systems being managed, included services, authorized requestors, support process, response expectations, remote and on-site service boundaries, customer responsibilities, cybersecurity and administrative responsibilities, pricing, renewal and termination. The agreement should describe the actual service your company is operationally prepared to provide.
What is the difference between an access control SLA response time and resolution time?
Response time measures how quickly the dealer acknowledges and begins addressing a request. Resolution time measures how quickly the underlying issue is completely resolved. Resolution can depend on factors outside the dealer’s control, including hardware failures, customer networks, third-party providers and site access.
Should truck rolls be included in a managed access control monthly fee?
They can be, but they do not have to be. Dealers may include a defined number of visits, offer discounted field-service rates or bill on-site labour separately. The important thing is to define the model before the customer assumes every future service call is included in the monthly fee.
Who should be allowed to request access control changes?
The customer should identify authorized requestors during onboarding. These may include facilities, security, HR or other approved administrators. Changes affecting physical access should not be made simply because anyone at the customer organization asks. The dealer should know who has authority to approve each type of request.
What happens if the customer’s internet or network fails?
The agreement should distinguish between the managed access control service and infrastructure controlled by the customer or its IT provider. The security dealer may assist with diagnosis, but restoration of customer-owned networking or internet services may remain outside the dealer’s responsibility unless specifically included.
Should after-hours support be included in a managed access control agreement?
If after-hours support is offered, define exactly what it includes. A phone response, remote technical review, emergency administration and guaranteed on-site dispatch are different services. Dealers should only promise coverage that their staffing and service operations can consistently provide.
Who is responsible for cybersecurity in managed access control?
Cybersecurity is generally shared across the environment. Customers control internal policies and parts of their network, dealers manage areas such as deployment and administration within their scope, and hosting or platform providers manage responsibilities defined for their environment. The specific division should be documented rather than assumed.
Should the service agreement cover what happens when the customer leaves?
Yes. Define notice, final billing, administrative access, information or documentation transition, hosted account handling and any transition assistance. Setting expectations at the beginning helps prevent confusion if the customer later changes providers or brings the system under a different management model.
The Strongest Managed Service Agreement Is One You Can Actually Deliver
The purpose of a managed access control agreement is not to create pages of exclusions.
It is to define a service that both sides understand.
The customer should know what they are receiving each month.
Your service team should know what it is responsible for.
Your sales team should know what it can promise.
And your pricing should reflect the real work required to support the account.
Once those pieces are defined, recurring access control becomes much easier to scale.
The next question is what you want your company to own behind that service.
Some integrators want to become Managed Services Providers and operate their own hosted environment.
Others would rather focus on the dealer side of the relationship while partnering for the infrastructure.
My Managed Security helps Kantech dealers deliver managed hattrix access control without having to build the entire private-cloud environment themselves.
That allows the dealer to focus on the customer relationship, installation, service and recurring managed offering while using an established managed-services infrastructure behind it.
Interested in building or refining your managed access control offering? Talk to My Managed Security about becoming a Managed Services Dealer.
Recommended Internal Links
Add contextual internal links to:
- Cloud Access Control RMR for Dealers in the sections discussing recurring services and pricing.
- MMS Is Introducing a SOC 2-Certified Environment in 2026 in the cybersecurity/hosting section.
- Transitioning From On-Premise to Cloud-Managed Access Control when discussing the hosted operating model.
- Taking Over an Existing Kantech EntraPass System: A Security Integrator’s Audit Checklist when discussing how inherited accounts move into a managed-service agreement.
- The Managed Access Control Customer Onboarding Guide when discussing authorized requestors and support processes.
- The future Remote Support Playbook when discussing remote versus field-service boundaries.