Flamingo Raises $4.5M Seed Round

You know the feeling. Month-end close arrives and you stare at the P&L, wondering how a business that bills $2.5 million can leave so little on the table. The answer is hiding in two lines that most MSP owners never isolate: the tools you rent and the repetitive work your people redo.

This is not a bad quarter. It is the structure of the modern MSP business model. According to the Acronis 2025 MSP Benchmark Guide, the traditional 40/20/40 rule allocates 20% of revenue to external technology alone, but real-world tool sprawl pushes that figure closer to 29% once you count every RMM seat, PSA license, security stack, backup agent, and documentation platform. Layer on the labor spent re-keying tickets, chasing alerts across nineteen consoles, and manually patching what automation should handle, and you lose another 24% of revenue to repetitive work. On a $2.5M shop, that is roughly $730,000 in tool costs and $600,000 in rework, a combined $1.33 million that exits the business before you pay rent, before you pay yourself, and before you invest in growth.

The good news: both lines are now movable. The bad news: they only move if you understand exactly what sits inside each one. This teardown walks the math, cites the sources, and hands you a 90-day plan to reclaim margin without betting the business.

Scope and Definitions: What Counts as Tools, What Counts as Repetitive Work

Before we open the spreadsheet, we need to agree on terms. Confusion here is how vendors sell you savings that never appear.

The 29% tools line includes every external technology cost billed per seat, per endpoint, per user, or per month: RMM, PSA, EDR, SIEM, backup, identity, documentation, and the growing list of AI copilots now metered per ticket or per token. It does not include internal infrastructure like your own servers or office software. According to the Acronis 2025 MSP Benchmark Guide, the traditional benchmark allocates 20% to external technology, but that figure predates the security stack explosion and the AI metering wave. Real-world audits now land closer to 29%.

The 24% repetitive-work line is a subset of total labor, not the whole payroll. It covers only the hours spent on tasks that are identical or near-identical across tickets: password resets, patch verification, alert triage, onboarding checklists, and the manual re-keying that happens when nineteen tools do not talk to each other. If your margins are consistently falling below 40%, it typically indicates a "leaky" service model, either your technicians are spending too much time on manual, repetitive tasks, or your software licensing costs are scaling too fast in proportion to your revenue. The 24% figure isolates the repetitive portion, not the skilled engineering, project work, or client-facing advisory that should remain human.

Why the distinction matters: if you automate repetitive work, you free capacity for higher-margin services. If you confuse repetitive work with total labor, you think the only lever is layoffs, and you miss the real opportunity.

The Model: Walking a $2.5M P&L Line by Line

Let us build the model. A $2.5 million MSP with 10 technicians, 1,560 managed endpoints, and 85 client accounts is a common profile in the ASCII Edge audience.

Revenue: $2,500,000

Tools (29%): $725,000. This includes RMM at roughly $4 per endpoint ($75K), PSA at $150 per tech per month ($18K), EDR and SIEM at $8 per endpoint ($150K), backup at $6 per endpoint ($112K), identity and MFA at $3 per user ($56K), documentation at $2 per user ($37K), and the remaining $277K spread across network monitoring, remote access, compliance, and the new AI copilots that bill per interaction. The total lands at 29% of revenue.

Repetitive Labor (24%): $600,000. With 10 technicians averaging $85K fully loaded, total tech labor is $850K. The 24% of revenue figure ($600K) represents roughly 70% of that labor pool spent on repetitive tasks. By automating routine tasks and standardizing processes, MSPs can reduce the risk of human error and streamline their operations. This not only saves time and resources but also improves the quality and consistency of services provided to clients.

Remaining Costs: $875,000 (35%) covers sales, admin, facilities, insurance, and owner compensation.

Net Margin: $300,000 (12%). This aligns with most successful providers aiming for a 60% gross margin on managed services, which ensures that after administrative and sales costs, the business maintains a healthy 15-20% net profit. The 12% in our model sits at the low end because the tools and repetitive-work lines are unoptimized.

The two bills together consume 53% of revenue. Move either one by 5 points and you double net margin.

The Four-Column Tool Audit: Mapping Every Dollar to a Decision

The first lever is owning your stack. That starts with a four-column audit.

Tool CategoryCurrent Annual CostOpen-Source or Consolidated AlternativeHonest Switching Cost
RMM$75,000Tactical RMM or consolidate to single-vendor suite$15K migration + 60 days
PSA$18,000ERPNext or native PSA in consolidated suite$10K migration + 90 days
EDR/SIEM$150,000Wazuh + Velociraptor$25K migration + 120 days
Backup$112,000Restic + cloud storage or single-vendor BDR$20K migration + 90 days
Identity/MFA$56,000Authentik or consolidate to M365 native$8K migration + 45 days
Documentation$37,000BookStack or consolidate to PSA wiki$5K migration + 30 days
Other (monitoring, remote, compliance, AI)$277,000Consolidate to 3-4 vendors max$30K migration + 120 days

The honest-costing column is critical. Open-source is not free; it trades license fees for implementation labor and ongoing maintenance. Vendor consolidation is a growing trend among MSPs as they seek to streamline operations and improve margins. The goal is not to eliminate every paid tool but to reduce from nineteen consoles to four or five, eliminate duplicate telemetry, and stop paying three vendors to watch the same endpoint.

A realistic target: cut the tools line from 29% to 22% over 18 months, saving $175K annually on a $2.5M shop.

The Automation Ladder: From Manual to Autonomous in Five Rungs

The second lever is letting agents take the routine. But automation is not binary. It is a ladder with five rungs, each with different risk profiles.

Automation RungExample TasksRisk Level
1. AlertingNotify tech of failed backup, high CPU, or login anomalyMinimal: human still decides
2. EnrichmentAuto-attach device history, recent tickets, and KB articles to new ticketLow: adds context, no action
3. Guided ActionSuggest remediation steps, pre-fill commands, require human approvalLow-Medium: human confirms
4. Supervised AutonomyExecute approved runbook, log every step, escalate on exceptionMedium: human reviews after
5. Full AutonomyResolve ticket end-to-end without human touch, within defined guardrailsHigher: requires robust safeguards

In our AI and automation reader survey, 71% of MSPs reported using automation for routine tasks like patch management and backups. Ticketing tasks (58%) and marketing activities (46%) followed closely behind. Most MSPs are stuck on rungs one and two. The margin unlock happens at rungs three and four, where repetitive work shifts from technician hours to agent cycles.

"But that momentum is outpacing readiness. Fewer than half of surveyed MSPs feel fully confident guiding customers on AI tools, particularly autonomous agents, where the gap between hype and hands-on deployment is widening." The safeguard is scope: start with low-risk, high-volume tasks like password resets and patch verification, prove the guardrails, then expand.

A realistic target: move 40% of repetitive work from human to supervised-autonomous within 12 months, freeing $240K in capacity that can be redeployed to higher-margin services or absorbed as margin.

Who Owns the Telemetry Owns the Margin

Here is the trap: you automate a workflow, reduce labor, and then the vendor bills you for the AI tokens that made it possible. The savings get clawed back because the vendor owns the telemetry.

As SMBs adopt more tools, MSPs are being asked to manage mounting complexity. Expensive licensing, steep learning curves, and vendor sprawl top the list of customer frustrations. In response, demand for bundled, integrated security offerings is rising.

Nineteen tools with nineteen copilots means nineteen separate AI meters, each charging per ticket, per query, or per token. The only way to break the cycle is to consolidate telemetry onto a data layer you control, then run your own agents against that layer.

This is not a call to build everything in-house. It is a call to audit where your data lands and who profits when you act on it. If your RMM vendor charges you to run an AI query against your own endpoint data, you are renting your own information. The alternative is to export telemetry to a data lake you own, whether that is a self-hosted time-series database or a cloud bucket under your account, and run open-weight models against it.

The math: if AI copilot fees add 2-3% of revenue ($50-75K on a $2.5M shop), and you can replicate 80% of that functionality on owned infrastructure for $20K in compute, the delta funds the migration.

The Roll-Up Is Already Pricing Your Market

If you are wondering why this matters now, look at the private equity activity in the MSP space. Profitability is polarizing (10% unprofitable, 16%+ at high margins). Deal sizes are compressing (41% of MSPs at $25,000+ annually, down from 75%).

Roll-ups operate at software margins because they consolidate tools, centralize NOCs, and automate at scale. They are not buying your revenue; they are buying your client relationships and then running them on a different cost structure. If your tools line is 29% and theirs is 18%, they can undercut your pricing and still make more money.

The data: 16% of MSPs report difficulty hiring skilled technicians, up from 9% in 2025. Meanwhile, according to CompTIA's IT Industry Outlook, more than half (52%) of channel companies report experiencing a workforce shortage and have difficulty finding job candidates with the skills their organization needs. The roll-up solves this by spreading talent across a larger base and automating the repetitive layer. If you do not do the same, you are competing with one hand tied.

The strategic response is not to sell early. It is to operate at the same efficiency so you can choose whether to sell, merge, or stay independent from a position of strength.

The 90-Day Monday-Morning Plan

Theory is cheap. Here is the action plan you can start this Monday.

Days 1-30: Audit

  • Export every vendor invoice from the last 12 months into a single spreadsheet.
  • Tag each line with tool category, billing model (per seat, per endpoint, flat), and contract end date.
  • Calculate your actual tools percentage of revenue. If it is above 25%, you have room to move.
  • Run a time study: have each tech log hours by task type for two weeks. Identify the top five repetitive tasks by volume.

Days 31-60: Prioritize

  • Rank tools by cost, overlap, and contract flexibility. Identify the top three candidates for consolidation or replacement.
  • Rank repetitive tasks by volume and risk. Identify the top two candidates for automation at rung three or four.
  • Build a business case for each move: cost to switch, time to value, and annual savings.

Days 61-90: Pilot

  • Launch one tool consolidation pilot (e.g., move documentation into PSA wiki).
  • Launch one automation pilot (e.g., password reset via supervised-autonomous agent).
  • Measure: hours saved, errors introduced, client impact.
  • Decide: scale, iterate, or abandon.

The gold standard is 350 fully managed endpoints per technician, although that number can vary based on the complexity of services and the technology stack. By maintaining this ratio, MSPs can ensure efficient operations and high service quality. If your current ratio is closer to 156 endpoints per tech, the 90-day plan is how you close the gap without hiring.

Safeguards for Autonomous Action

Automation without guardrails is how you brick a client's domain controller at 2 AM. The safeguards are non-negotiable.

Scope limits: Define exactly which actions an agent can take. Password reset yes, domain admin password reset no. Patch workstation yes, patch domain controller only with human approval.

Audit trails: Every autonomous action must be logged with timestamp, target, action taken, and outcome. If you cannot explain what happened, you cannot defend it.

Rollback capability: Any change made by an agent must be reversible within a defined window. If the agent patches a workstation and the patch breaks an application, you need a one-click rollback.

Exception escalation: Define the conditions under which an agent must stop and escalate to a human. Unknown device type, high-value client, or any action that touches compliance-sensitive data.

Regular review: Audit agent actions weekly for the first 90 days, then monthly. Look for drift, unexpected patterns, or near-misses.

The goal is not to eliminate human judgment. It is to reserve human judgment for the decisions that require it and let agents handle the rest.

Conclusion

The squeeze is structural, not a bad quarter. A $2.5M MSP that pays 29% to tools and 24% to repetitive work is left with a 10-15% net margin and no room to invest in growth, weather a downturn, or compete with roll-ups operating at software margins.

But both lines are movable. The tools line moves through a disciplined four-column audit, honest costing of alternatives, and consolidation from nineteen consoles to four or five. The repetitive-work line moves through the automation ladder, starting with low-risk tasks and expanding as you prove the guardrails.

The math is simple: cut tools from 29% to 22% and repetitive work from 24% to 18%, and you add $225K to the bottom line on a $2.5M shop. That is nearly doubling net margin without adding a single new client.

You did not build this business to hand half of it to vendors and rework. The two bills are now visible. The levers are now clear. The only question is whether you pull them.

Michael Assraf

Founder and CEO

Hey everyone, I'm Michael - founder and CEO of Flamingo. Before this, I built Vicarius, a cybersecurity company focused on vulnerability remediation, where I raised over $60M in funding. Working closely with service providers through that journey, I saw firsthand how MSPs were losing money to vendor payouts and inefficient systems - and that's when the idea for Flamingo clicked. I set out to build an open-source platform that dramatically increases MSP margins while helping them deliver better service to their clients.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.

AI MSP

MSPs use AI to triage and route tickets, cut alert noise, schedule patches, assist L1 security work, and draft client reports. Kaseya's 2025 benchmark found 30% already use it to eliminate tedious tasks, with ticket triage the most common starting point.
Most MSPs start with AI features inside their existing PSA, RMM, and ticketing systems rather than standalone products. Common categories include AI ticket triage, alert correlation, scripting assistants, and AI-native all-in-one platforms like OpenFrame that run intelligence across the whole stack.
Start with a readiness assessment, not a tool purchase. Confirm your ticket history is clean and your RMM, PSA, and monitoring systems connect. Then pick one high-volume, low-risk workflow, usually ticket triage, and pilot it on internal tickets before any client sees it.
Automate high-volume, low-risk tasks first. Ticket triage and alert noise reduction top the list because they run constantly and a human still resolves the underlying issue. Save security approvals, billing changes, and client-facing actions for later, always with a human in the loop.