Operational Diligence: What Your PSA and RMM Say About You

Ticket data, SLA performance, patch compliance, and license true-ups: what your own tools already reveal to a buyer, and how to read them first yourself.

Operational Diligence: What Your PSA and RMM Say About You

Your P&L says what you earned. Your PSA says how. Somewhere in the middle of diligence, after the accountants have had their turn, an operationally serious buyer asks for access to your ticketing system and your RMM, and this is the exam most sellers never saw coming, because nobody thinks of their own tools as testimony. They are. Years of ticket data, monitoring history, and license records constitute a diary of how the business actually runs, written contemporaneously by people with no reason to lie, and buyers who operate MSPs themselves (we’re one) can read it fluently.

Here’s what gets read, and what it says.

The ticket queue: your service reality on the record

The PSA pull answers questions the interview stage can only gesture at. Volume and mix first: tickets per endpoint per month, reactive versus proactive versus project time, and the trend lines. A shop drowning in reactive noise is priced as one, whatever the marketing says about being “proactive partners.” Response and resolution times against whatever your contracts promise come next, and here’s a wrinkle sellers miss: buyers check your SLA performance against the SLAs you actually signed, which means the aggressive four-hour-response clause your 2019 self put in the anchor client’s MSA is about to be graded, retroactively, with exhibits.

Then the texture reads. Escalation patterns show whether the bench is real: if 40% of tickets touch one senior engineer, the org chart’s key-person risk has a name and a queue history. Time-entry hygiene shows whether your margins are measurements or vibes: tickets closed in zero minutes, techs logging 11-hour days of billable time, or whole clients with no time recorded tell a buyer your gross margin by client (a number they care about intensely) can’t be computed from your own records. And the notes themselves get sampled. Sparse, copy-pasted, or unprofessional resolution notes read as a culture signal, because they are one.

None of this is pass/fail. It’s calibration: the buyer is deciding how much of your story to believe, and the queue is the most honest witness available.

The RMM: the environments you’re accountable for

The monitoring stack testifies about risk. Patch compliance across the fleet is the headline: endpoints that report current, agents actually deployed everywhere the contracts say they should be, and no graveyard of stale devices nobody offboarded. Backup health is its adjacent exhibit: job success rates, last-verified restores, and whether the failed-backup alerts from March were resolved or just acknowledged. A buyer inheriting your client base is inheriting liability for the environments in it, and an RMM full of red is a remediation bill they will estimate, generously, and subtract.

Alert hygiene gets read too. Ten thousand unacknowledged alerts mean the monitoring is theater, and monitoring-as-theater means the real incident record lives in whichever tickets clients opened when things broke, which loops the reader back to the queue with sharper questions.

Licensing: the true-up nobody budgeted

The third pull is the least glamorous and the most likely to produce an actual invoice: license reconciliation. Your M365 tenant counts versus what you bill each client. Your RMM, AV, and backup agent counts versus your vendor commitments. Per-tech tools versus actual headcount. Three findings recur at MSP scale: clients being billed for fewer seats than deployed (margin you’re donating), vendors being paid for more than deployed (shelfware, an easy EBITDA addback conversation if documented), and, most seriously, deployment exceeding entitlement anywhere, which is a compliance exposure the buyer will insist gets cured, priced, or indemnified. Contract assignability rides along in this pass: which vendor agreements and client MSAs actually transfer, the question that quietly shapes the whole closing timeline.

Run the exam on yourself first

Everything above is visible to you today, with admin rights you already have, and that’s the practical point of this post. Six months before any process, spend a week being your own operational diligence team. Pull tickets-per-endpoint, SLA attainment, and escalation concentration. Export patch and backup compliance and fix what’s red. Reconcile every license count in both directions. Offboard the stale endpoints, close the zombie tickets, and start enforcing time entry like the numbers matter, because they’re about to.

Two payoffs. The obvious one is that findings you cure can’t be priced against you, and findings you can’t cure yet become disclosures you control the framing of, which the financial diligence post already established as the trust-preserving move. The quieter one is that the exercise usually improves the business you still own: the license reconciliation alone often finds real monthly dollars, and the SLA review has saved more than one shop from a contract it should never have signed.

A buyer who runs an MSP is going to look at yours the way a mechanic looks at an engine: not hostile, just informed. The sellers who do well in that inspection aren’t the ones with perfect queues. Nobody has perfect queues. They’re the ones who plainly know their own shop, red flags included, because operational self-knowledge is the thing the whole exam was ever testing for.

See every diligence stage mapped