Skip to content
Client login

Free Audit

IT consulting & support

Support and maintenance: what you buy when you buy time

It is the only family in the pillar sold by time. Everything turns on a sentence nobody asks for: the moment the clock starts.

Published on 23 May 2026 — Algeria Agency

The three pages below this one — support, buying hardware, repair — are the easiest to sign in the whole IT pillar. They deliver something tangible: somebody comes, a machine goes back, an invoice matches an object.

They nonetheless have a feature the other families do not: what is sold here is neither an object nor software, it is time. A response window, a number of hours, an availability.

And a window cannot be verified the way a machine can. It is defined in writing, and the definition is almost always more generous to the seller than a buyer imagines. The words "two hours" mean nothing until somebody has said two hours from what.

This article handles that question, the supplier paid by the hour for a problem that lasts, and the figure we will not quote because it is worked out over the faults that were reported — that is to say, not the expensive ones.

The only family sold by time

In the pillar’s four other families you buy a thing: a server, a cable, a camera, a firewall. It exists, it can be shown, and if it does not work that is established in five minutes.

Here, what you buy is a promise of presence. Somebody will answer, somebody will come, somebody will repair — within a certain window, a certain number of times, at certain hours. None of it exists at the moment of signature.

The consequence is that the quality of a support contract is read in its definitions, not in its price. Two contracts at the same monthly rate can differ by a factor of three in service actually delivered, and the gap sits in three or four sentences.

Those sentences are always the same: when the clock starts, what is included and what is billed on top, what happens outside working hours, and how many on-site visits are covered before the counter starts again.

The rest of the document is standard. Spend ten minutes on those four points and you will have done the substance of the comparison work, including between proposals that look identical.

The moment the clock starts

It is the most profitable sentence in this whole pillar, and it fits on one line: from which precise event do the promised two hours run?

Three answers circulate and they are not worth the same. From your call — the best and the rarest. From the ticket being logged — that is, when somebody at the supplier entered it. Or from acceptance, meaning when a technician decided to take it on.

The third wording empties the promise of content, because the supplier itself controls the moment the clock starts. A two-hour window beginning at acceptance is a two-hour window after an undefined one.

What the window promises has to be specified too: a first contact, a diagnosis, or a return to service. Those are three very different things, and "response within two hours" almost always means the first, which is the least useful of the three.

The wording we agree to sign, and that you should demand of anybody: the clock starts at the call or the message, it stops when a competent person is working on the problem, and it runs over working hours defined in the contract. Three specifics, one line, and the document changes character.

The most expensive fault has no ticket

At this point in the article you expect a figure: an average resolution time, an average downtime, a share of incidents handled within the window. We will quote none, and the reason differs from every one our other articles have given.

The problem is not that these figures are foreign, or old, or produced by a seller. The problem is that the population they are worked out over is defined by the very thing being measured: they cover the incidents that became tickets.

And the faults that cost most never become tickets. The printer that only prints from one machine and that somebody has been getting up to visit ten times a day for eight months. The package that crashes on one specific operation everybody has learned to avoid. The file copied by hand because the synchronisation stopped working.

Nobody calls about that, because it is no longer a fault: it has become how the work gets done. Added up over a year and across fifteen people, it is by far the heaviest item in this family, and it is invisible in every statistic.

So the honest figure is one to produce at your own premises and it costs half a day: ask five people what they work around every day. What we usually get from that question is a list of six to ten workarounds none of which was ever reported, and two of them are fixed in an hour.

Three things sold under one word

The word "maintenance" covers three different services, with three different economics, and confusing them is what produces the contracts nobody is happy with.

The first is break-fix: you call when something is broken, you pay for the visit. It is reactive, it is honest, and it suits a business with under ten machines and no critical line-of-business package perfectly well.

The second is preventive maintenance: regular visits to check what degrades slowly. It makes sense on things that genuinely degrade — backups, disks, power protectors, filters — and none at all on things that do not, which is most workstations.

The third is managed service: the supplier takes responsibility for things working, with monitoring and a commitment. It costs the most and it is the only one that genuinely moves risk, but it only makes sense past a certain size and with an up-to-date inventory.

The choosing rule is simple and it contradicts what most quotations propose: take break-fix while you do not know what to watch, and move to a regular contract once an audit has told you what actually degrades at your premises. The reverse order is what the market sells, and it produces quarterly visits that look at nothing.

The hourly rate and what it encourages

The problem has to be stated without imputing motives, because it is not a moral one: a supplier paid by the hour is paid in proportion to how long the problem lasts. Nobody needs to be dishonest for that structure to have its effects.

Its effects show in one precise place: the faults that come back. A recurring fault handled by the hour generates regular revenue; the same fault handled at the root generates one invoice and removes the following ones. No conscious decision is needed for the first to win, it is enough never to think about it.

The correction is not suspicion, it is changing the unit for the cases where it is wrong. A fault that has happened three times moves to a fixed price: a set amount for it not to come back, however long that takes.

That wording has a useful side effect: it tells you immediately whether the supplier knows how to handle it. Resistance to a fixed price on a recurring fault is almost always information about the diagnosis rather than about the price.

The hourly rate stays the right unit for everything else: a one-off request, an installation, a question. It is a good tool, misused on a single case — and that case is precisely the one that costs most over a year.

What can be fixed remotely, and what cannot

Remote support is faster, cheaper and immediately available. It settles a large share of routine requests, and a supplier who travels for everything is not more serious, it is slower.

It has a limit foreign documentation rarely mentions, though, because it matters less elsewhere: remote support requires the line to work. And in a large share of the incidents we handle, the line is precisely what is not working.

That is a structural asymmetry. The problems that get fixed remotely are the ones that irritate; the problems that stop the business are the ones that cut the connection, and those get fixed on site by definition. A contract that is entirely remote therefore covers the small well and the serious badly.

The practical consequence bears on the number of visits included. That is not an incidental line: it is the part of the contract that applies to lost days. A contract generous on remote work and mean on visits is built backwards against your risks.

And there is distance itself, which appears on no quotation. A supplier forty minutes away has a floor of forty minutes, whatever they write. Ask for their address, not just their window — it is this section’s one check that costs nothing and cannot be argued with.

The estate nobody counted

A support contract is priced by number of machines. That is logical, and it assumes the number is known — which it almost never is, and the gap runs systematically the same way.

What we find when we actually count: more machines than management states, and fewer than the supplier bills. Both errors coexist, because the two sides count different things without saying so.

What escapes: personal laptops used for work, the workshop machine driving a device, the old computer left switched on for one package, the meeting-room tablets, and the phones business mail arrives on.

What the supplier sometimes bills in excess, symmetrically: machines written off two years earlier and never removed from the list, a machine duplicated after a replacement, or equipment that never needed support at all.

The correction is the audit article’s and it earns its own paragraph here: one line per machine, with who uses it, before signing a per-machine contract. Without that list you are not negotiating a price, you are negotiating an assumption.

Preventive maintenance that is worth something

A preventive visit can be a real service or a courtesy call with an invoice. The difference sits in what gets checked, and the list of things that genuinely degrade is short.

Four points make it up. A file restored from the backup, performed rather than looked at. The state of the power protector’s battery, which dies within a few years signalling nothing. The disk space left on the server and on the machines that fill up. And the disks’ error logs, which announce a failure weeks ahead.

Those four points take an hour and they cover the substance of what degrades slowly. Everything else — clearing temporary files, defragmenting, running an antivirus by hand — belongs to a past era and fills a report without preventing anything.

A fifth point belongs to this country and it is worth the other four: the physical state of the filters and fans, in premises exposed to dust. It is the commonest cause of accelerated ageing we meet, and it is treated with a blower.

The test to put any visit report through: does it contain a restore result, a measurement, and a date? If it contains only ticked boxes, it describes a visit rather than a check, and it is worth what the box is worth.

Parts, and waiting

A fast response window is worth nothing if the part needed arrives in three weeks. That is the constraint that genuinely decides how long an outage lasts here, and it appears in no standard support contract.

The mechanism has nothing technical about it: a part not available locally has to be ordered, imported, cleared and delivered. Each of those steps is incompressible and none depends on the supplier, which is why they are never promised.

The consequence is an inversion of priority compared with what is read elsewhere: here, what decides availability is not the technician’s speed, it is what is already on a shelf. An identical spare power supply is worth more than a four-hour promise.

That applies first to what breaks most and costs least: power supplies, disks, fans, injectors, cables. A stock of common parts for the critical equipment is a modest sum and removes half the long waits.

It also imposes a purchasing rule the hardware page develops: prefer few identical models to many different ones. A homogeneous estate makes every spare usable everywhere, and turns an out-of-service machine into a parts store.

What the contract has to contain

Six lines, and they replace reading the rest. A contract carrying all of them is signable even if it is dearer; a contract missing two is one to renegotiate before comparing prices.

The clock’s starting point, worded as in section 2. What the window promises — contact, diagnosis or return to service. The hours and days covered, with what happens outside them and at what rate.

The number of visits included, kept distinct from the number of remote interventions. The scope: which machines, which software, and above all what is explicitly excluded, because a written exclusion beats a misunderstanding in use.

Finally, and it is the line we see least often: handing back. What happens at the end of the contract, who holds the administrator passwords, within what period the documentation is returned and in what format. That is the next section’s subject and it gets settled at the start.

A seventh line is optional but it changes everything: a quarterly hour, with the list of incidents and what was fixed at the root. Without that appointment, a support contract is a sequence of visits with no memory, and the same faults come back every year.

Changing supplier without being held hostage

The question only arises when the relationship deteriorates, which is the worst moment to handle it. So it gets prepared at the start, and the preparation sits in three things you hold rather than in a clause.

The first is the list of administrator accesses, in your name, as the audit article describes. A supplier holding the accesses alone does not need to hold you: the situation does it for them, and changing becomes a project instead of a decision.

The second is minimal documentation: one page per system, saying what is installed, where the data sits, and where the backup points. Ask for it every six months rather than at the end — documentation requested at the end of a relationship arrives late, incomplete, or never.

The third is the intervention history, including the attempts that led nowhere. It is the document that stops the next supplier repeating the same experiments, and it is the easiest part to obtain while everything is going well.

What a change really costs has to be said too, because it is not nothing: the new supplier spends two to three weeks discovering your installation, and that period is billed or built into a higher price. Changing for fifteen per cent of savings does not pay back; changing because the same faults keep returning does.

What we do, and what we will refuse to do

What we will refuse: billing by the hour for a fault that has happened three times. From the third, it moves to a fixed price, because carrying on hourly would amount to being paid for it to continue.

We will refuse to sign a per-machine contract without having counted the machines with you, and to promise a window without writing down which event it runs from. A promise whose definition stays vague is a promise we would judge, and that is not a role we want.

We will refuse to bill a preventive visit containing no performed restore, no measurement and no date. A ticked box is not a check, and a report with no measured result proves only the journey.

What we do: the clock starting at your call; the list of daily workarounds built by asking your people rather than by reading our own tickets; the four checks that cover what genuinely degrades; common parts held in reserve for what is critical; administrator access in your name from day one; and a quarterly hour that handles recurrences at the root.

And what you can do this week without us: ask five people what they have been working around every day for more than a month. None of it is in your tickets, and that is almost always where this family’s money is.

Frequently asked questions

What does "response within two hours" mean?

Nothing until the contract says which event the window runs from — your call, the ticket being logged, or acceptance — and what it promises: contact, diagnosis, or return to service. Demand both specifics in writing.

Do we need a maintenance contract or pay per visit?

Pay per visit while you do not know what genuinely degrades at your premises. Move to a regular contract once the inventory is done. The reverse order produces quarterly visits that check nothing measurable.

What should a preventive visit contain?

A restore actually performed, the state of the power protector’s battery, disk space left, the disks’ error logs, and in dusty premises the state of the filters. A report with no measured result and no date describes a visit, not a check.

Why does a repair take three weeks?

Because the part has to be ordered, imported, cleared and delivered, and none of those steps depends on the supplier. That is why a stock of common parts beats a promised window, and why a homogeneous estate beats a varied one.

Is remote support enough?

For routine requests, yes, and it is faster. But it requires the line to work, and the line is often what has failed on the day the business stops. So look at the number of visits included, and at the supplier’s address.

How do we change supplier without breakage?

By holding three things from the start: administrator access in your name, one page of documentation per system, and the intervention history. Ask for them every six months. Allow two to three weeks of discovery for the next one as well.

Where we come in

What five people have worked around every day for a month never reaches you: each has got used to it, and nobody thinks to report it.

  • We put each workaround into minutes per day per person.
  • We start the clock at your call, not at our availability.
  • We date every preventive visit by a restore actually performed.

From the third occurrence of the same fault we stop billing by the hour: if it keeps coming back, we did not fix it.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy