Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Managed Security Provider Onboard a New Client Without Missing Devices, Log Sources or Contacts?
Problems We Solve

How Does a Managed Security Provider Onboard a New Client Without Missing Devices, Log Sources or Contacts?

MSSP onboarding stalls when agents, log sources and contacts are tracked in spreadsheets. We build onboarding tracking that shows what is live for every client.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Onboarding drags because it depends on the client deploying agents, connecting log sources and supplying contacts, and progress is tracked in a spreadsheet that does not know what is actually reporting in. We build an onboarding tracker that compares the client's agreed asset list with what your EDR and SIEM can actually see, lists what is missing, chases the client, and confirms the service is fully live before monitoring is declared started.

Live on paper, partly live in practice

A new managed client signs. The contract covers a set number of endpoints and servers, their Microsoft 365 tenant, their firewall logs and a couple of cloud workloads. Your onboarding engineer sends a deployment guide and an agent installer. The client's IT team deploy it over a few weeks, in between their other work.

The onboarding spreadsheet shows ticks: agent deployed, firewall connected, 365 connected. The kick-off call is done. Monitoring is declared live. Two months later, during an investigation, the analyst discovers that a group of servers never got the agent, the firewall is sending only some of its logs, and the out-of-hours escalation contact is someone who left the client in the spring.

Nobody did anything wrong. The spreadsheet recorded what people said, not what your tools could see.

Onboarding is also the first real experience the client has of your service. A drawn-out, confusing onboarding sets expectations for everything that follows.

Why onboarding leaves gaps

  • The client does the deployment, on their own timetable, and reports progress in general terms.
  • The agreed asset list is a document, not compared with what reports into your tools.
  • Log sources can be connected but incomplete, which looks the same as connected on a checklist.
  • Escalation contacts are collected once and not verified.
  • 'Live' is declared on a date rather than on evidence.

What gaps cost

GapConsequence
Devices without agentsNot monitored, though the client thinks they are
Incomplete log sourcesInvestigations lack data
Wrong escalation contactsCritical calls go nowhere
Onboarding drags onService fee billed before service is complete, or not billed
No evidence of what was liveDifficult conversations later

The worst of these surface at the worst time: during an incident, when the client assumes every device was covered and your analyst discovers it was not. That conversation is far harder than the one you could have had during onboarding, when the gap was simply a task on a list.

The onboarding tracker we build

  1. The client's agreed scope is recorded as a list: endpoint and server counts or names, log sources, cloud tenants, and contacts by role.
  2. Your EDR platform and SIEM are queried by API each day for what is actually reporting in for that client: agents checking in, log sources sending data, and data volumes.
  3. The tracker compares the two and shows coverage: devices expected but not seen, sources connected but quiet, and anything reporting in that was not in the agreed list.
  4. Missing items are sent to the client's IT lead as a clear list, with a chaser on a schedule you set.
  5. Contacts are verified by sending each a short confirmation request, so wrong or out-of-date contacts are caught before they are needed.
  6. Monitoring is declared live when the coverage and contacts meet the threshold you set, with a record of what was live on that date, signed off by the client.

After onboarding, the same comparison keeps running, so a device that stops reporting or a new server without an agent is flagged, not discovered during an incident.

Onboarding with the tracker running

The onboarding engineer sees real coverage each morning, not ticks in a sheet. The client's IT team gets a precise list of what is left to do. Go-live is based on evidence, and both sides have a record of what was covered from day one.

Account leads also get a clear view of scope versus reality, which is useful when the client's estate grows and the contract needs to grow with it.

Consider a typical week three. The tracker shows most laptops reporting, a batch of servers at a second site with no agent, the firewall connected but sending only a fraction of the expected volume, and one escalation contact whose email bounced. The client's IT lead receives those four items as a short list. By the end of the week the servers are done and the firewall logging is fixed, and a new contact has confirmed. Monitoring goes live on evidence, and both sides know exactly what it covers.

Is your onboarding like this?

  • Onboarding progress is tracked in a spreadsheet.
  • You have found unmonitored devices months after go-live.
  • Log sources are marked connected without checking what they send.
  • Escalation contacts are never verified.
  • Go-live is a date rather than a coverage check.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Which tools does it check?

Your EDR and SIEM platforms, and cloud tenants where they offer APIs. We check yours before scoping.

Can it deploy agents for the client?

No. Deployment stays with the client or your engineers. The tracker shows what has actually been deployed and is reporting.

What counts as fully live?

You decide the threshold per service. The tracker shows coverage against it and records the sign-off.

Does it keep checking after onboarding?

Yes. The same comparison runs daily to catch devices or sources that stop reporting.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →