Live on paper, partly live in practice
A new managed client signs. The contract covers a set number of endpoints and servers, their Microsoft 365 tenant, their firewall logs and a couple of cloud workloads. Your onboarding engineer sends a deployment guide and an agent installer. The client's IT team deploy it over a few weeks, in between their other work.
The onboarding spreadsheet shows ticks: agent deployed, firewall connected, 365 connected. The kick-off call is done. Monitoring is declared live. Two months later, during an investigation, the analyst discovers that a group of servers never got the agent, the firewall is sending only some of its logs, and the out-of-hours escalation contact is someone who left the client in the spring.
Nobody did anything wrong. The spreadsheet recorded what people said, not what your tools could see.
Onboarding is also the first real experience the client has of your service. A drawn-out, confusing onboarding sets expectations for everything that follows.
Why onboarding leaves gaps
- The client does the deployment, on their own timetable, and reports progress in general terms.
- The agreed asset list is a document, not compared with what reports into your tools.
- Log sources can be connected but incomplete, which looks the same as connected on a checklist.
- Escalation contacts are collected once and not verified.
- 'Live' is declared on a date rather than on evidence.
What gaps cost
| Gap | Consequence |
|---|---|
| Devices without agents | Not monitored, though the client thinks they are |
| Incomplete log sources | Investigations lack data |
| Wrong escalation contacts | Critical calls go nowhere |
| Onboarding drags on | Service fee billed before service is complete, or not billed |
| No evidence of what was live | Difficult conversations later |
The worst of these surface at the worst time: during an incident, when the client assumes every device was covered and your analyst discovers it was not. That conversation is far harder than the one you could have had during onboarding, when the gap was simply a task on a list.
The onboarding tracker we build
- The client's agreed scope is recorded as a list: endpoint and server counts or names, log sources, cloud tenants, and contacts by role.
- Your EDR platform and SIEM are queried by API each day for what is actually reporting in for that client: agents checking in, log sources sending data, and data volumes.
- The tracker compares the two and shows coverage: devices expected but not seen, sources connected but quiet, and anything reporting in that was not in the agreed list.
- Missing items are sent to the client's IT lead as a clear list, with a chaser on a schedule you set.
- Contacts are verified by sending each a short confirmation request, so wrong or out-of-date contacts are caught before they are needed.
- Monitoring is declared live when the coverage and contacts meet the threshold you set, with a record of what was live on that date, signed off by the client.
After onboarding, the same comparison keeps running, so a device that stops reporting or a new server without an agent is flagged, not discovered during an incident.
Onboarding with the tracker running
The onboarding engineer sees real coverage each morning, not ticks in a sheet. The client's IT team gets a precise list of what is left to do. Go-live is based on evidence, and both sides have a record of what was covered from day one.
Account leads also get a clear view of scope versus reality, which is useful when the client's estate grows and the contract needs to grow with it.
Consider a typical week three. The tracker shows most laptops reporting, a batch of servers at a second site with no agent, the firewall connected but sending only a fraction of the expected volume, and one escalation contact whose email bounced. The client's IT lead receives those four items as a short list. By the end of the week the servers are done and the firewall logging is fixed, and a new contact has confirmed. Monitoring goes live on evidence, and both sides know exactly what it covers.
Is your onboarding like this?
- Onboarding progress is tracked in a spreadsheet.
- You have found unmonitored devices months after go-live.
- Log sources are marked connected without checking what they send.
- Escalation contacts are never verified.
- Go-live is a date rather than a coverage check.