Open download
PDF version of this guide, no email gate, share freely.
The question is rarely ‘should we use managed hosting or do it ourselves’. The question is ‘where should the boundary sit between us and a managed-hosting partner’. This guide is about how to draw that line for your estate.
Who this is for
The IT or operations leader who is accountable when Maximo is unavailable at seven in the morning, and who has to justify the cost of avoiding that. It is a decision about the operating model, not about the software. If the deployment pattern is still open as well, read MAS SaaS versus managed OpenShift alongside this.
Three honest patterns
In practice, organisations end up in one of three places.
Pattern A: Fully internal
The client runs the whole stack: infrastructure, OpenShift platform, MAS application operations, application support. Suits organisations with mature platform engineering teams, multiple workloads on the same platform, and strong Maximo-specific skills already in-house.
Pattern B: Partner-managed end-to-end
The partner runs infrastructure, platform, application operations and application support. The client owns the data, the configuration decisions and the relationship. Suits organisations that want to focus internal capability on the maintenance and asset management work, not the platform engineering.
Pattern C: Hybrid
Some of each. Common patterns include client-owned infrastructure with partner-managed application operations; or partner-managed platform with internal application support; or partner-managed normally and on-call for incidents only. Hybrid works when the boundary is clear and the responsibility map is unambiguous.
The wrong answer is unclear boundaries. That is where outages live.
Decision criteria
Do you already run platform engineering at scale?
If yes, fully internal or hybrid both work. If no, partner-managed end-to-end is usually the better call. Building a platform team for one workload is rarely a good investment.
Is Maximo a strategic in-house capability or a supporting platform?
For some organisations, EAM expertise is a core capability that should live in-house. For others, EAM is a supporting platform that should free internal teams to focus on the operational work itself. Be honest about which one Maximo is for you. Both answers are legitimate.
How critical is response time on incidents?
Partner-managed hosting with a strong SLA and named engineers usually beats internal teams on response time, especially out of hours. Internal teams can match this only if you fund them to do so, which is rarely the cheapest answer.
How does your audit and security regime treat third-party operations?
Some regulated environments restrict third-party access to operational data. This pushes towards internal or onshore-only managed hosting with explicit access controls. Modern managed-hosting practices accommodate this; it just needs designing in.
What is the right balance of fixed versus variable cost?
Internal teams are largely fixed cost. Managed hosting is largely variable / subscription cost. Neither is universally right; it depends on how predictable your estate’s growth is.
Costs: the comparison that matters
Realistic comparison includes:
- Internal: platform engineers, Maximo administrators, application support specialists, on-call rota, recruitment cost, retention cost, training cost, infrastructure
- Managed: subscription / managed-services fee, residual internal coordination time, infrastructure (if not bundled)
The mistake organisations make is comparing ‘managed-hosting fee’ against ‘salary of one Maximo administrator’. The fair comparison includes the full team needed to cover platform, application, on-call and absence, usually three to five FTEs minimum to do this properly internally for a single estate of any meaningful size.
What a good managed-hosting service looks like
If you are evaluating managed hosting, the test is not the brochure. The test is:
- Named engineers on your account, not a rotating queue
- An SLA you can read and that connects to penalties you would actually invoke
- Direct access to your engineers, not through a generic service desk
- Transparent change records so you can see what changed and why
- Application support and minor change available under the same roof, not a hand-off
- Hosting on enterprise-grade cloud with documented security controls and sensible region choice
- Clear backup, restore and DR with regular tested recovery, not just documented procedures
The test that settles it: one incident, step by step
Ask any candidate supplier, and ask your own team, to walk through the same night. Batch integration to the ERP has stopped at 02:40 and work orders are queuing.
- What raises it. A monitor on the interface queue depth, not a user phoning at eight. If the first signal is a person, the operating model has already failed. Our own monitoring layer for this is MaxIron Sentinel.
- Who is woken, and by name. Named engineers on a rota, with a documented escalation after a fixed number of minutes. “The service desk raises a ticket” is not an answer to this question.
- What they are allowed to do without asking. Restart a pod, drain a queue, replay messages. The pre-approved actions should be written down and rehearsed. Everything else needs a human decision with a record.
- Where the record lands. A change record and an incident record in the same system your auditors read, produced as the work happens rather than reconstructed the next afternoon.
- Who tells the business, and when. Before the seven o’clock shift briefing, in language a supervisor can use.
- What changes afterwards. A permanent fix, a monitor that would have caught it earlier, or an accepted risk with a date. If nothing changes, the same night happens again next quarter.
Whether the answers come from your team or a partner matters less than whether they exist and are rehearsed. Most estates that have a bad year have a gap at step three or step six.
What stays yours whichever pattern you choose
- Configuration decisions. A partner can advise and implement. What your business process should be is yours.
- Data quality. Nobody can outsource the judgement about which of two duplicate asset records is real.
- The named internal owner. Someone has to hold the roadmap and say no to changes that do not belong. Operations can move out; accountability cannot.
- The regulatory relationship. Your regulator and your auditors deal with you. A partner provides evidence; you present it.
- The decision to leave. Whichever model you pick, write down what an exit looks like at the start. It is a project either way, and it is cheaper to plan when nobody is annoyed.
Bring your last three incidents to the first conversation
Our managed-hosting practice runs MAS on enterprise-grade cloud with named engineers, transparent change tooling, and the option to bundle application support into the same relationship. We are equally happy taking over an existing estate from another supplier or hosting from day one of a new implementation.
The fastest way to make this decision concrete is to walk through the last three incidents on your estate: what raised them, who was woken, what they were allowed to do, and what changed afterwards. Bring those and your current on-call arrangement, and thirty minutes will tell you where the boundary should sit.
Book a 30-minute review, or see how the operated service is put together on MaxIron Cloud.
Where this guide leads
The pages below are the delivery side of the decision this guide covers.