An illustrative situation · 4 chapters
Your MSP client needs compliance help. Who does the work?
You manage the client's IT. Now their buyer wants security evidence or a SOC 2 report. Before adding compliance to the proposal, agree what the client needs and which work your team, Sythe Labs, and the client will own.
Chapter 01
Start with one client's actual request.
A client forwards a security questionnaire and asks whether your managed service covers it. Read the questions before quoting a compliance package. Some answers concern systems you operate; others concern hiring, vendor decisions, or policies only the client can approve. If the request is for SOC 2, confirm the service and report type with the buyer and an independent CPA. Agree the boundary of the work in writing.
01 / Scope · the client, service, and buyer requirement
Chapter 02
Name the people who can supply and approve the evidence.
For a production access review, your MSP may export the accounts. The client must decide whether those people still need access. The person removing accounts then records the change. Agree where Sythe's delivery team supports collection and review, and where the client's decision is required. A managed IT contract doesn't automatically assign responsibility for every compliance control.
02 / Ownership · collection, client decisions, and implementation
Chapter 03
Make the first evidence package reviewable.
Before uploading evidence, confirm you're in the correct client organization and that access is limited to the authorized delivery team and reviewers. In Sythe Labs, evidence records connect supporting material to controls and an assigned approver. Identify the period, attach the material, and have the reviewer check what it proves. An export alone doesn't establish that an access review happened. Keep the client's decisions and follow-up work with the record; never pool different clients' evidence in a shared folder.
03 / Review · supporting material and a recorded decision
Chapter 04
Agree ongoing delivery before offering it to more clients.
After the first package, decide who handles new requests, changed policies, and evidence that needs refreshing. Sythe's compliance platform and delivery team can support that work alongside an MSP. Discuss the client scope and commercial arrangement with us before promising a reseller service. Branding, pricing, support responsibilities, and any response commitments need agreement; this example doesn't establish those terms. The independent CPA remains responsible for the SOC examination and report.
04 / Delivery · agreed responsibilities beyond the first package
What you leave with
A scoped client engagement with named owners and a repeatable evidence-review process.
Have a similar task on your team's list? Book a call to discuss how this workflow would fit your systems and who would need to be involved.