Coverage and response
Stated hours, not implied availability, because a commitment is only worth what somebody can plan around.
Any arrangement advertised as round-the-clock support is either staffed by a rota nobody has met or it is a phrase. Naming the actual hours is less impressive and considerably more useful, because a commitment is worth exactly what somebody else can plan around it.
Coverage windows are written into the engagement, not implied by tone. What hours, which days, and what counts as urgent enough to interrupt them — all three stated, so the business can decide what other arrangements it needs.
Severity is defined by consequence instead of by adjective. A site returning errors to every visitor and a misaligned heading are not the same event, and agreeing that distinction in advance prevents it being negotiated during the incident by whoever is most agitated.
Response time and resolution time are separated and stated separately. Acknowledging a report quickly is a commitment that can be honored; resolving an arbitrary fault in a fixed window is not, and promising the second is how a support arrangement starts producing arguments.
There is a written first response for total unavailability, because that is the case where improvisation is most expensive and least likely to go well: confirm the scope, check the deploy history, check the platform's own status, then work outward.
Incidents get a short written record afterwards — what happened, what caused it, what was changed. Not a formality: the same fault recurring twice is normal, and the second occurrence is only cheap if somebody wrote down the first.
Work outside the agreed scope is quoted rather than absorbed silently. Absorbing it seems generous and reliably ends with an unstated expectation that is discovered by disappointing somebody.
Where a business genuinely needs coverage beyond what is offered, saying so is part of the work. A business whose revenue depends on a system being available at three in the morning needs an arrangement that reflects that, and pretending otherwise to keep an engagement serves nobody.
Everything above is unremarkable, and the reason to publish it is that the alternative — leaving availability to be inferred — reliably produces a disappointment neither side agreed to.
What this does not cover.
- Round-the-clock or same-day guarantees that could not be honored consistently.
- Resolution-time commitments for faults of unknown cause.
- Absorbing out-of-scope work without quoting it.
Managed Services & Infrastructure
Releasing changes
The commit that was built is verified by its identifier, and the release is verified against the live address instead of against a build status.
Backup and recovery
A backup nobody has restored is a belief; recovery time is measured by performing it, not estimated from the size of the file.
Environments
A non-production environment earns its cost by being wrong in the same ways production is.
Monitoring
Watching the things a business would actually notice losing, rather than the things that are easy to graph.
Keeping software current
Few enough third-party components that keeping them current stays possible three years after launch.
Ownership and access
The domain, the payment account and the cloud accounts are the client's; handover is a transfer of access, not a negotiation.