VeritGuard Managed IT Services: Scope of Support Matrix
Explore VeritGuard's Managed IT Services support matrix to understand the range and depth of IT support available for your business.
Table of Contents
VeritGuard Managed IT Services: Scope of Support Matrix
Client reference document | Effective July 2026
1. Purpose and how to use this article
This article defines what Verito Technologies manages under VeritGuard Managed IT Services, what falls outside that scope, and which responsibilities are shared between your firm and Verito.
It is written to answer three questions directly:
- What does Verito own and monitor on our behalf?
- What must our firm continue to own, or keep another vendor in place for?
- Which items depend on our firm granting or confirming access?
Use Section 3 for a quick answer, Sections 4 and 5 to confirm what your specific plan includes, and Sections 6 through 8 to identify coverage gaps before any prior provider is disengaged.
Service delivery model
VeritGuard is delivered entirely remotely. Verito does not dispatch technicians to client locations and does not manage, repair, or replace physical hardware or network infrastructure at your office.
This model is intentional. It allows us to maintain 24/7 coverage and a consistent security baseline across every managed device, regardless of location.
2. The three scope categories
Every item in this article falls into one of three categories. Understanding the difference prevents assumptions during onboarding and during an incident.
| Category | Definition |
|---|---|
| Verito managed | Verito owns the configuration, monitoring, maintenance, and remediation of this item. No action is required from your firm beyond normal use. |
| Shared responsibility | Verito performs the work, but the outcome depends on an action, approval, or access grant from your firm. If the client side action does not happen, the service cannot be delivered. |
| Out of scope | Verito does not manage this item under VeritGuard. Your firm must retain an existing vendor, engage a separate provider, or accept the risk knowingly. |
3. Scope summary at a glance
The table below is a high level orientation. Plan specific availability is confirmed in Section 5.
| Managed by Verito | Shared responsibility | Out of scope |
|---|---|---|
|
|
|
4. In scope: what VeritGuard manages
Availability of individual services depends on your plan. An asterisk indicates a service that cannot be activated until Microsoft 365 or Google Workspace administrative access has been granted to Verito.
4.1 Endpoint management and security
| Service | What it covers | Availability |
|---|---|---|
| Remote monitoring and management | Continuous health monitoring of managed workstations and laptops, remote administration, automated alerting, and asset inventory tracking for compliance reporting. The agent runs silently in the background. | All plans |
| Endpoint detection, response, and antivirus | Next generation antivirus with behavioural threat detection, active response and remediation, and DNS level filtering on managed endpoints. | All plans |
| Patch management | Automated deployment of Windows and supported third party application updates on managed endpoints, on a designated weekly patch schedule. | All plans |
| Endpoint backup | Image based backup of the physical local drives on each managed device, with 90 day grandfather, father, son retention, and full machine restore capability. | All plans. Storage: 250 GB, 500 GB, or 1 TB by plan |
| Remote PC tune ups | Scheduled proactive maintenance on each managed device to clear performance degradation. | Annual, bi-annual, or quarterly by plan |
| Mac support | Endpoint detection and response, antivirus, backup, and compliance monitoring are supported and managed on macOS devices. | All plans |
An important backup clarification
Endpoint backup captures the physical local drives on the device, for example the C: drive. It does not capture mapped or virtual network drives, for example a Z: drive presented by a document management platform, because that data resides in the platform that owns it and is protected by that platform.
If your firm relies on a mapped drive for working files, please raise it with your Customer Success Engineer so the correct protection path can be confirmed.
4.2 Support
| Service | What it covers | Availability |
|---|---|---|
| 24/7 technical support | Unlimited remote helpdesk requests by phone, email, or chat, at any hour, including tax season weekends. Calls are answered by a live technician. No phone trees and no offshore handoff. | All plans |
| Monthly reporting | Monitoring and patch, endpoint detection and response, and endpoint backup status reports. Additional reports are available on request. | All plans |
4.3 Identity, access, and email
| Service | What it covers | Availability |
|---|---|---|
| NordLayer VPN | Business VPN providing encrypted remote access for staff working outside the office. Tier scales with plan. | All plans. Lite, Core, or Premium by plan |
| 1Password | Enterprise password manager. Verito provisions the account, assists with vault structure, and supports your users. | Add-on with Essentials, included with Pro and Elite |
| Email anti-phishing and threat protection * | Inbound email filtering with phishing, impersonation, and advanced threat protection applied before mail reaches the inbox. | Pro and Elite |
| Microsoft 365 and Google Workspace administration * | Day to day account administration: user creation, permission changes, license assignment, and staff onboarding and offboarding. | Pro and Elite |
4.4 Compliance and training
| Service | What it covers | Availability |
|---|---|---|
| WISP assistance | Guidance and documentation support for your firm Written Information Security Plan, as expected under IRS Publication 4557 and the FTC Safeguards Rule. | Pro and Elite |
| FTC Safeguards audit | A structured review of your managed environment against the FTC Safeguards Rule, with findings and recommended remediation. | Annual with Pro, bi-annual with Elite |
| Employee cybersecurity training | Short security awareness modules and simulated phishing exercises for your staff. | Pro and Elite |
4.5 Advanced monitoring and cloud data protection
| Service | What it covers | Availability |
|---|---|---|
| 24/7 SOC monitoring | Security operations centre monitoring of managed endpoints, with a live analyst team reviewing and acting on detections around the clock. | Elite |
| Dark web credential monitoring | Monitoring for firm credentials appearing in known breach and dark web data sets, with alerting when a match is found. | Elite |
| SaaS backup * | Backup of Microsoft 365 or Google Workspace data, including mail, calendar, contacts, and files, with one year retention. | Elite |
| SaaS monitoring * | Alerting on abnormal sign in activity, suspicious mailbox rules, and account level security events in your Microsoft 365 or Google Workspace tenant. | Elite |
Services marked with an asterisk require administrative access
Email anti-phishing, Microsoft 365 and Google Workspace administration, SaaS backup, and SaaS monitoring cannot be deployed without global administrative access to your Microsoft 365 or Google Workspace tenant.
Until that access is granted and confirmed, these services remain pending and your firm is not protected by them. If access has not yet been provided, please reply to your onboarding thread or contact itsupport@verito.com so we can complete activation.
5. Plan availability matrix
Each VeritGuard tier is inclusive of the tier below it. Use this table to confirm exactly what your firm is entitled to.
| Service | Essentials | Pro | Elite |
|---|---|---|---|
| Remote monitoring and management | Included | Included | Included |
| Endpoint detection, response, and antivirus | Included | Included | Included |
| Patch management | Included | Included | Included |
| 24/7 technical support | Included | Included | Included |
| Inventory management | Included | Included | Included |
| Endpoint backup storage | 250 GB | 500 GB | 1 TB |
| Remote PC tune up frequency | Annual | Bi-annual | Quarterly |
| NordLayer VPN tier | Lite | Core | Premium |
| 1Password | Available as add-on | Included | Included |
| Email anti-phishing * | Not included | Included | Included |
| Microsoft 365 and Google Workspace administration * | Not included | Included | Included |
| Employee cybersecurity training | Not included | Included | Included |
| WISP assistance | Not included | Included | Included |
| FTC Safeguards audit | Not included | Annual | Bi-annual |
| 24/7 SOC monitoring | Not included | Not included | Included |
| Dark web credential monitoring | Not included | Not included | Included |
| SaaS backup, one year retention * | Not included | Not included | Included |
| SaaS monitoring * | Not included | Not included | Included |
1Password, NordLayer VPN, dark web monitoring, email security, SaaS backup, SaaS monitoring, and SOC monitoring are also available as standalone add-on purchases on any plan. Contact your Customer Success Engineer for current pricing.
6. Out of scope: what VeritGuard does not manage
The following are not managed by Verito under VeritGuard. Each requires your firm to retain an existing vendor, engage a separate provider, or accept the item as an unmanaged risk. Please review this section carefully before disengaging a prior IT provider.
| Area | What this means in practice | Recommended coverage |
|---|---|---|
| On premise Active Directory and on site servers | Verito does not administer on premise Active Directory, physical domain controllers, or file servers located at your office. As a remote only provider we cannot support on site hardware. | Retain a local provider, or discuss migrating identity to Microsoft Entra ID |
| Firewalls and network appliances | Ongoing administration of firewalls, firewall firmware, routers, switches, and site to site VPN tunnels is not included. Verito can request temporary access to complete a specific task, but continuous management is out of scope. | Retain your existing network vendor or firewall provider |
| Tenant level Microsoft 365 and Google Workspace configuration | Verito handles day to day administration but not the underlying tenant security architecture. This includes Conditional Access policy design, group policy, and security baseline configuration. | Engage a project based engagement or specialist consultant |
| Domain registrar and DNS management | Verito does not manage registrar accounts, domain renewals, DNS records, or web hosting records. | Retain your registrar account and web vendor |
| On site services and physical hardware | No on site visits, cabling, wiring, hardware installation, hardware repair or replacement, or printer hardware repair. Printer drivers and printing software can be troubleshot remotely. | Retain a local hands on provider for physical work |
| Hardware and software procurement | Verito does not purchase hardware or resell third party software licences, including tax and accounting application licences. | Purchase directly, or ask us for specification guidance |
| Cloud application hosting and server backups | Hosting of Drake Tax, UltraTax, QuickBooks, and other accounting applications, together with nightly server backups, is not part of VeritGuard. | Covered by VeritSpace. See Section 9 |
7. Capabilities not included in VeritGuard
These are capabilities that a previous provider may have delivered, and that VeritGuard does not include at any tier. They are listed explicitly so that any gap can be identified and discussed before a prior provider tools are removed.
- Device level multi-factor authentication at Windows login. VeritGuard does not enforce multi-factor authentication on the local login of a client workstation. Verito is evaluating an endpoint multi-factor solution; no delivery date is committed at this time.
- Annual risk assessments. Verito does not perform formal firm wide risk assessments. The FTC Safeguards audit available on Pro and Elite reviews the managed environment; it is not a substitute for a full risk assessment.
- Penetration testing and vulnerability scanning.
- Privileged access management with elevation approval workflows.
- Standalone compliance summary documents beyond the WISP assistance and FTC Safeguards audit described in Section 4.4.
8. Shared responsibilities
These items require coordination. Verito performs the work, but delivery depends on an action from your firm.
| Item | Verito responsibility | Your firm responsibility |
|---|---|---|
| Agent deployment | Install and validate monitoring, endpoint protection, and backup agents remotely. | Ensure devices are powered on, connected, and reachable during the deployment window. Coordinate with staff to wake dormant machines. |
| Administrative access handover | Request, document, and secure the access required for each service. | Provide and confirm Microsoft 365 or Google Workspace global administrator access, and domain administrator credentials where applicable. |
| Prior tool removal | Remove prior provider agents from devices that are online at the time of the removal window. | Confirm which tools are to be removed and identify any device that was offline so it can be revisited. |
| Password manager migration | Provision 1Password, configure the vault structure, and support your users. | Existing users export current credentials and import them into the new vault. Verito cannot extract data from a third party password tool. |
| Device and user inventory | Maintain the inventory of record from what is discovered and reported. | Notify Verito when a device or staff member is added or removed so billing and protection stay accurate. |
| Security awareness training | Assign modules and report completion. | Ensure staff complete assigned training within the stated window. |
| Change approval | Recommend and execute changes affecting access or security posture. | Provide an authorised approver for changes affecting user access, permissions, or licensing. |
9. Where other Verito services apply
Several items listed as out of scope for VeritGuard are covered by a different Verito service. If a requirement below applies to your firm, raise it with your Customer Success Engineer.
| Requirement | Verito service |
|---|---|
| Hosting for Drake Tax, UltraTax, QuickBooks, or other accounting applications, with nightly server backups and a secure remote desktop environment | VeritSpace, our cloud hosting platform, billed per user |
| A complete Written Information Security Plan document for firms that are not on a VeritGuard Pro or Elite plan | VeritShield, our standalone WISP offering |
| Both managed IT for local devices and cloud hosting for applications, under a single service | VeritComplete, which bundles VeritGuard and VeritSpace |
10. Requesting work that falls outside this scope
If your firm needs something listed in Section 6 or Section 7, the correct path is a conversation rather than a support ticket. Contact your Customer Success Engineer, and our team will confirm whether the work can be delivered as a scoped project, whether it belongs with another Verito service, or whether a third party is the right route.
We will always tell you plainly when something is outside what we can support. Ambiguity about scope is the most common cause of an unprotected gap, and it is the situation this article exists to prevent.
11. Support contacts
| Service | Phone | |
|---|---|---|
| VeritGuard Managed IT | itsupport@verito.com | 844-629-9899 |
| VeritSpace cloud hosting | support@verito.com | 844-917-9399 |
| VeritComplete | Use the address matching the issue type | Either line, routed by issue type |
For a suspected security incident, telephone 844-629-9899 immediately rather than sending email.
This article describes the standard scope of VeritGuard Managed IT Services. Where a signed service agreement or a documented exception applies to your firm, that agreement takes precedence. Verito reviews this article periodically and will notify clients of material changes to scope.
Table of Contents