VeritGuard Shared Responsibility Matrix: Verito and Your Firm
Learn how Verito and your firm can collaborate effectively through a shared responsibility matrix for enhanced security and clarity.
Table of Contents
Shared Responsibility Matrix: Verito and Your Firm
Effective September 2026 | Last Updated on 16th September | Published by Parnav Dagar
1. Purpose and how to use this article
This article sets out who is accountable for each function involved in running and securing your IT environment under VeritGuard. It is written to be used directly in a vendor risk file, in your Written Information Security Plan, and in the vendor oversight record the FTC Safeguards Rule expects your firm to keep.
Read it once during onboarding and refer back to it whenever a question comes up about who owns a particular task. It answers three things:
- What does Verito perform and hold the record for?
- What stays with your firm, and why?
- Where do both sides have to act for the outcome to work?
A function listed as your firm is not a gap in service. Verito is a fully remote provider and does not hold ownership of your tenant, your physical network, or your hardware. Those boundaries are deliberate and they are what makes the division of accountability auditable.
2. How to read the owner column
| Owner | What it means |
|---|---|
| Verito | We perform the work and hold the record. You do not need to do anything beyond raising a ticket where one is needed. |
| Your firm | Accountability sits with you. We will advise, and in many cases walk you through it, but we do not perform the work or own the outcome. |
| Shared | Both sides have a defined task. The outcome fails if either side does not act. |
| Not provided | Not part of any VeritGuard plan. Listed so there is no ambiguity about whether it is covered. |
Your plan determines coverage
Some functions below are available only on specific plans. Where that is the case, the plan is named in the notes column. If a function is marked Verito but your plan does not include the underlying service, the function is not active for your firm. Check your plan before relying on any row.
3. Endpoint management and security
| Function | Owner | Notes |
|---|---|---|
| Deploy monitoring, detection, and backup agents | Verito | Devices must be powered on and reachable for deployment to complete. |
| Make devices available for agent deployment | Your firm | You coordinate with staff so machines are online during the rollout window. |
| Continuous endpoint monitoring and health alerting | Verito | All plans. |
| Endpoint detection, response, and antivirus | Verito | All plans. |
| Operating system patching | Verito | Weekly cycle. Tuesday is the scheduled patch day. |
| Third party application patching | Not provided | Updates to applications installed on the device, including tax and accounting software, are not deployed by Verito. Keeping those current sits with your firm. |
| Leave devices powered on and locked on patch day | Your firm | A machine that stays powered off for several weeks misses security updates and becomes a compliance exposure. |
| Emergency patching for actively exploited vulnerabilities | Verito | Applied immediately and documented within 24 hours. |
| Remote performance tune ups | Verito | Frequency set by plan. Annual on Essentials, bi-annual on Pro, quarterly on Elite. |
| Maintain the device register | Shared | Verito maintains the register. You tell us when a device is added, replaced, or retired. |
| Procure, replace, and dispose of hardware | Your firm | Verito does not supply, own, or physically handle hardware. |
| Decide and apply disk encryption policy | Your firm | Verito can enable BitLocker on Windows Professional edition. It is not available on Home edition. |
| On site technician work | Not provided | All support is delivered remotely under every plan. |
4. Identity, Microsoft 365, and Google Workspace
The functions in this section marked Verito require administrative access to your tenant. Without that access they cannot be delivered, regardless of plan.
| Function | Owner | Notes |
|---|---|---|
| Provide and maintain administrative access to the tenant | Your firm | Several services in this article depend on it. |
| User account creation, change, and removal | Verito | Pro and Elite. Day to day administration. |
| Password resets and MFA re-registration | Verito | Pro and Elite. |
| Enable and enforce MFA on tenant user accounts | Verito | Pro and Elite. Requires admin access. |
| MFA at Windows device sign in | Not provided | Verito does not deploy multi factor authentication at the device login layer. |
| License assignment from your existing pool | Verito | Pro and Elite. |
| License procurement | Shared | We can purchase and manage your licenses on your behalf if you would like us to handle it. If you prefer to buy direct, procurement stays with you. |
| Tenant ownership | Your firm | The tenant remains your firm property regardless of who purchases the licenses. |
| Security group membership and mailbox permissions | Verito | Pro and Elite. Standard changes. |
| Conditional Access design and configuration | Your firm | Tenant level security architecture sits outside VeritGuard. |
| Tenant governance, security baselines, and directory administration | Your firm | Verito can advise on the impact of a proposed change. |
| Administrative role assignments | Your firm | Who holds admin rights in your tenant is your decision to make and record. |
| Application registrations and directory consent | Your firm | Third party application approvals remain with the tenant owner. |
| Joiner, mover, and leaver notification | Shared | You notify us of the change. We execute the account work. |
5. Email security
| Function | Owner | Notes |
|---|---|---|
| Deploy and maintain the email anti-phishing layer | Verito | Pro and Elite, add-on on Essentials. Requires admin access. |
| Mail flow and inbound filtering configuration for that layer | Verito | Covers the protection layer we deploy, not your tenant mail policy as a whole. |
| Publish the domain records required for mail authentication | Shared | Verito specifies the records. You or your DNS provider apply them. |
| Domain registrar and DNS administration | Your firm | Not managed by Verito. A transition can stall entirely if DNS cannot be changed. |
| Report suspected phishing that reaches an inbox | Your firm | Your staff report it. We investigate and tune the filter. |
| Security awareness training and phishing simulations | Verito | Pro and Elite. We assign the training and report on completion. |
| Require staff to complete assigned training | Your firm | Completion rates are your evidence for the training control in your WISP. |
6. Backup and recovery
| Function | Owner | Notes |
|---|---|---|
| Endpoint backup, storage, and retention | Verito | The first backup captures a full image of the device. After that, incremental backups run every two hours. Retention is 90 days on a grandfather father son rotation. Storage is sized by plan and held in the United States. |
| Protect backup data from deletion | Verito | Backup data is immutable and cannot be altered or deleted by a compromised administrator account. It is not reachable from your side. |
| Monitor backup health and integrity | Verito | A backup report is issued to you on the first of each month. |
| Perform restores | Verito | You raise the request. We perform the restore. There is no client side restore console. |
| Save work to locations covered by backup | Your firm | Files saved to mapped or virtual drives are not captured by endpoint image backup. Save locally or to an officially synced folder. |
| Backup of Microsoft 365 or Google Workspace data | Verito | Elite only, with one year of retention. Not included on Essentials or Pro. On other plans, mailbox recovery depends on your provider native retention. |
| Restore test with a written report | Shared | You nominate the device and the files. We perform the restore and issue the report. |
| Define retention beyond the standard schedule | Your firm | Extended retention is a contractual change, not a configuration change. |
7. Network and infrastructure
Verito does not manage physical network equipment or on premise infrastructure. These functions stay with your firm or with a vendor you appoint.
| Function | Owner | Notes |
|---|---|---|
| Firewall, router, and switch administration | Your firm | Verito may request temporary access to complete a specific task. |
| Wireless network and access points | Your firm | |
| Internet service and circuit management | Your firm | |
| Printer and peripheral hardware | Your firm | Verito does support printer connection, mapping, and driver issues from a managed workstation. |
| On premise servers and Active Directory | Your firm | |
| NordLayer VPN provisioning and support | Verito | Tier set by plan. Lite on Essentials, Core on Pro, Premium on Elite. |
| IP allow listing on Verito hosted resources | Shared | You supply the approved addresses. We apply and maintain the list. |
8. Credentials and access management
| Function | Owner | Notes |
|---|---|---|
| 1Password provisioning and support | Verito | Included on Pro and Elite, add-on on Essentials. |
| Vault structure, sharing rules, and credential hygiene | Your firm | We advise on structure. The decisions and the ongoing discipline are yours. |
| Migrate existing credentials into 1Password | Your firm | We provide the process and support you through it. |
| Review staff entitlements against least privilege | Your firm | We can report current state on request. The review itself is a firm responsibility. |
| Control and review Verito technician access | Verito | Access is role based and reviewed internally. |
| Revoke Verito access at termination | Verito | Completed as part of the offboarding process. |
9. Monitoring, alerting, and incident response
| Function | Owner | Notes |
|---|---|---|
| Endpoint security alerting and response | Verito | All plans. |
| 24/7 security operations monitoring | Verito | Elite only. |
| Alerting on unusual tenant sign in activity | Verito | Elite only, through SaaS monitoring. Requires admin access. On other plans you rely on the native alerting in your Microsoft 365 or Google Workspace license. |
| Dark web credential monitoring | Verito | Elite only. |
| Report a suspected incident to Verito | Your firm | Call the managed IT support line immediately. Do not wait to raise a ticket. |
| Containment and recovery on managed endpoints | Verito | All plans. |
| Maintain your firm incident response plan | Your firm | Verito should be named in it as your IT security contact. |
| Regulatory, client, and IRS breach notification | Your firm | We support the process and supply the technical record. The notification obligation is the firm. |
| Notify you of an incident affecting your data at Verito | Verito | Per the terms of your service agreement. |
10. Logging and evidence
| Function | Owner | Notes |
|---|---|---|
| Retain operational logs | Verito | Minimum one year. Covers remote support sessions, VPN and remote access, endpoint security events, and change records. |
| Retain security incident logs | Verito | Minimum three years. |
| Provide log exports on request | Verito | Returned within 24 to 48 hours at no charge. |
| Direct access to monitoring and endpoint security consoles | Not provided | Export on request is the supported route. |
| Microsoft 365 audit log retention | Your firm | Set by Microsoft according to your license tier. We can confirm your tenant setting once we have admin access. |
| File the monthly reports as compliance evidence | Your firm | Verito issues monitoring, endpoint security, and backup reports on the first of each month. Filing them each month builds a continuous record. |
11. Compliance and documentation
| Function | Owner | Notes |
|---|---|---|
| FTC Safeguards audit | Verito | Annual on Pro, bi-annual on Elite. Not included on Essentials. |
| Written Information Security Plan assistance | Verito | Pro and Elite. We support the documentation. |
| Author and adopt the WISP policy content | Your firm | The WISP is your firm document and your firm adopts it. |
| Designate the Qualified Individual under the FTC Safeguards Rule | Your firm | The rule requires a named individual at your firm. |
| Annual risk assessment | Not provided | Verito does not perform risk assessments. |
| Penetration testing and vulnerability scanning | Not provided | Not included under any VeritGuard plan. |
| Supply Verito security documentation for your vendor file | Verito | Available on request. |
| Maintain your vendor oversight file | Your firm | This article is written to sit directly in it. |
12. Onboarding, change, and termination
| Function | Owner | Notes |
|---|---|---|
| Baseline assessment of your current environment | Shared | We conduct the assessment. You supply access, credentials, and answers. |
| Remove a prior provider tools and agents | Shared | Agents can only be removed from devices that are online and reachable. |
| Obtain administrative credentials from a prior provider | Your firm | The commercial relationship is yours and the handover has to come from you. |
| Approve non routine changes | Shared | We raise the change request. You approve anything that affects your environment. |
| Return of your data at termination | Shared | Scope, format, and timing are set by your service agreement. |
| Remove Verito agents at termination | Verito | Completed as part of offboarding. |
13. Cloud hosting
This article covers managed IT under VeritGuard. If your firm also uses Verito cloud hosting, the hosted server environment, data center facilities, hosted application management, server side backup and recovery, hosted session controls, and availability commitments are covered by a separate responsibility matrix. Ask your account contact for it.
Your agreement always governs
Anything named specifically in your service agreement takes precedence over this article. Where the two differ, the agreement is the authority. If you spot a difference, tell us so we can correct the article.
Table of Contents