Keep Control of Your IT Access

Prevent vendor lock-in and make renewals and support easier. Book a Fit Check to verify your license ownership, admin access, and recovery controls, then get a clear list of any gaps.

Last updated

April 29, 2026

Reviewed by

Reviewed by: IT Service Delivery Lead

Speakable Summary

When a vendor says “it’s not us” you needevidence and a clear escalation path. This playbook keeps ownership clear andshortens downtime.

Opening

“It’s not us” usually means the vendor does nothave enough evidence to own the problem. It can also mean the issue is sharedacross systems and each party is protecting their boundary.

Most SMB downtime stretches out because theoffice becomes the messenger between vendors. Calls get repeated, details getlost, and no one owns the timeline.

This playbook shows what to do in the firsthour, what evidence to collect, what to say, and how to escalate without makingthe problem worse.

Direct Answer

When a vendor says “it’s not us” respond withtimestamps, symptoms, and a clear request for next steps. Escalation worksfaster when one ticket tracks evidence and ownership.

LINK: IT Support page
LINK: Managed IT Services
LINK: Managed IT Pricing

What’s included vs what’s usually extra

Typically   included in escalation support

Usually   extra as a project

Opening cases and tracking case numbers

Switching vendors or replacing systems

Evidence collection and incident notes

Major architecture redesign to remove the   vendor dependency

Coordinating multiple vendors and timelines

Full network rebuild or new office buildout

Status updates and internal communication

Large remediation after repeated outages

●    
Open one internal ticket and assign one owner

●    Capture evidence before makingchanges

●    Document the final root cause andprevention step

Included means running the escalation processand keeping the timeline clean. Extra means vendor replacement and largeredesign work that needs a separate scope.

Escalation playbook

Step 1: Confirm impact and open one ticket
Confirm who is impacted and what workflow is down. Create one internal ticketthat becomes the system of record.

Step 2: Freeze random changes and captureevidence
Stop uncontrolled troubleshooting that destroys proof. Capture screenshots,error messages, and timestamps first.

Step 3: Identify the boundary and the likelyowner
Decide whether the issue smells like ISP, firewall, DNS, Microsoft 365, VoIP,or the line of business vendor. Record the current best guess and why.

Step 4: Open the vendor case and demand a casenumber
Open the case with the correct vendor and record the case number. Ask for thecurrent SLA target and the next update time.

Step 5: Provide proof and request a specificaction
Share the evidence and ask for one specific next step. Examples includechecking outage dashboards, reviewing logs, or validating account status.

Step 6: Escalate with a clear request anddeadline
If the vendor refuses ownership, request escalation to a supervisor. Ask forwritten confirmation of what they checked and what they need next.

Step 7: Close the loop and document prevention
Confirm resolution with users and log the fix. Document what caused the issueand what will prevent repeats.

Who owns what

Role

Responsible   for

Office Manager

Confirming business impact and priority

IT Support Owner

Running the ticket and escalation timeline

Vendor Support

Investigating their service boundary

Decision Maker

Approving vendor changes and project work

If you only do one thing this week

●    Build a vendor map with contacts,portals, and escalation paths.

●    Confirm credential ownership andMFA for every vendor portal.

●    Require vendor incidents to betracked in tickets with closeout notes.

Common failure points and fixes

●    Multiple people call the vendorand fix it by assigning one owner and one caller.

●    Evidence is missing and fix it bycapturing timestamps and screenshots first.

●    Changes destroy proof and fix itby freezing changes until logs are captured.

●    Vendor refuses escalation and fixit by requesting supervisor review and written checks.

●    Portal access is missing and fixit by enforcing credential ownership and vaulting.

●    No closeout notes exist and fix itby requiring root cause and prevention notes.

Situation MFA rule Exception handling
Admin account  Required No expectations without owner approval and end date 
Finance roles Required Required
All users Required Required
Legacy app Replace or isolate Required

Get My 15 Minute Fit Check

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.