You know the feeling. Month-end close arrives and you stare at the P&L, wondering how a business that bills $2.5 million can leave so little on the table. The answer is hiding in two lines that most MSP owners never isolate: the tools you rent and the repetitive work your people redo.
This is not a bad quarter. It is the structure of the modern MSP business model. According to the Acronis 2025 MSP Benchmark Guide, the traditional 40/20/40 rule allocates 20% of revenue to external technology alone, but real-world tool sprawl pushes that figure closer to 29% once you count every RMM seat, PSA license, security stack, backup agent, and documentation platform. Layer on the labor spent re-keying tickets, chasing alerts across nineteen consoles, and manually patching what automation should handle, and you lose another 24% of revenue to repetitive work. On a $2.5M shop, that is roughly $730,000 in tool costs and $600,000 in rework, a combined $1.33 million that exits the business before you pay rent, before you pay yourself, and before you invest in growth.
The good news: both lines are now movable. The bad news: they only move if you understand exactly what sits inside each one. This teardown walks the math, cites the sources, and hands you a 90-day plan to reclaim margin without betting the business.
Scope and Definitions: What Counts as Tools, What Counts as Repetitive Work
Before we open the spreadsheet, we need to agree on terms. Confusion here is how vendors sell you savings that never appear.
The 29% tools line includes every external technology cost billed per seat, per endpoint, per user, or per month: RMM, PSA, EDR, SIEM, backup, identity, documentation, and the growing list of AI copilots now metered per ticket or per token. It does not include internal infrastructure like your own servers or office software. According to the Acronis 2025 MSP Benchmark Guide, the traditional benchmark allocates 20% to external technology, but that figure predates the security stack explosion and the AI metering wave. Real-world audits now land closer to 29%.
The 24% repetitive-work line is a subset of total labor, not the whole payroll. It covers only the hours spent on tasks that are identical or near-identical across tickets: password resets, patch verification, alert triage, onboarding checklists, and the manual re-keying that happens when nineteen tools do not talk to each other. If your margins are consistently falling below 40%, it typically indicates a "leaky" service model, either your technicians are spending too much time on manual, repetitive tasks, or your software licensing costs are scaling too fast in proportion to your revenue. The 24% figure isolates the repetitive portion, not the skilled engineering, project work, or client-facing advisory that should remain human.
Why the distinction matters: if you automate repetitive work, you free capacity for higher-margin services. If you confuse repetitive work with total labor, you think the only lever is layoffs, and you miss the real opportunity.
The Model: Walking a $2.5M P&L Line by Line
Let us build the model. A $2.5 million MSP with 10 technicians, 1,560 managed endpoints, and 85 client accounts is a common profile in the ASCII Edge audience.
Revenue: $2,500,000
Tools (29%): $725,000. This includes RMM at roughly $4 per endpoint ($75K), PSA at $150 per tech per month ($18K), EDR and SIEM at $8 per endpoint ($150K), backup at $6 per endpoint ($112K), identity and MFA at $3 per user ($56K), documentation at $2 per user ($37K), and the remaining $277K spread across network monitoring, remote access, compliance, and the new AI copilots that bill per interaction. The total lands at 29% of revenue.
Repetitive Labor (24%): $600,000. With 10 technicians averaging $85K fully loaded, total tech labor is $850K. The 24% of revenue figure ($600K) represents roughly 70% of that labor pool spent on repetitive tasks. By automating routine tasks and standardizing processes, MSPs can reduce the risk of human error and streamline their operations. This not only saves time and resources but also improves the quality and consistency of services provided to clients.
Remaining Costs: $875,000 (35%) covers sales, admin, facilities, insurance, and owner compensation.
Net Margin: $300,000 (12%). This aligns with most successful providers aiming for a 60% gross margin on managed services, which ensures that after administrative and sales costs, the business maintains a healthy 15-20% net profit. The 12% in our model sits at the low end because the tools and repetitive-work lines are unoptimized.
The two bills together consume 53% of revenue. Move either one by 5 points and you double net margin.
The Four-Column Tool Audit: Mapping Every Dollar to a Decision
The first lever is owning your stack. That starts with a four-column audit.
| Tool Category | Current Annual Cost | Open-Source or Consolidated Alternative | Honest Switching Cost |
|---|---|---|---|
| RMM | $75,000 | Tactical RMM or consolidate to single-vendor suite | $15K migration + 60 days |
| PSA | $18,000 | ERPNext or native PSA in consolidated suite | $10K migration + 90 days |
| EDR/SIEM | $150,000 | Wazuh + Velociraptor | $25K migration + 120 days |
| Backup | $112,000 | Restic + cloud storage or single-vendor BDR | $20K migration + 90 days |
| Identity/MFA | $56,000 | Authentik or consolidate to M365 native | $8K migration + 45 days |
| Documentation | $37,000 | BookStack or consolidate to PSA wiki | $5K migration + 30 days |
| Other (monitoring, remote, compliance, AI) | $277,000 | Consolidate to 3-4 vendors max | $30K migration + 120 days |
The honest-costing column is critical. Open-source is not free; it trades license fees for implementation labor and ongoing maintenance. Vendor consolidation is a growing trend among MSPs as they seek to streamline operations and improve margins. The goal is not to eliminate every paid tool but to reduce from nineteen consoles to four or five, eliminate duplicate telemetry, and stop paying three vendors to watch the same endpoint.
A realistic target: cut the tools line from 29% to 22% over 18 months, saving $175K annually on a $2.5M shop.
The Automation Ladder: From Manual to Autonomous in Five Rungs
The second lever is letting agents take the routine. But automation is not binary. It is a ladder with five rungs, each with different risk profiles.
| Automation Rung | Example Tasks | Risk Level |
|---|---|---|
| 1. Alerting | Notify tech of failed backup, high CPU, or login anomaly | Minimal: human still decides |
| 2. Enrichment | Auto-attach device history, recent tickets, and KB articles to new ticket | Low: adds context, no action |
| 3. Guided Action | Suggest remediation steps, pre-fill commands, require human approval | Low-Medium: human confirms |
| 4. Supervised Autonomy | Execute approved runbook, log every step, escalate on exception | Medium: human reviews after |
| 5. Full Autonomy | Resolve ticket end-to-end without human touch, within defined guardrails | Higher: requires robust safeguards |
In our AI and automation reader survey, 71% of MSPs reported using automation for routine tasks like patch management and backups. Ticketing tasks (58%) and marketing activities (46%) followed closely behind. Most MSPs are stuck on rungs one and two. The margin unlock happens at rungs three and four, where repetitive work shifts from technician hours to agent cycles.
"But that momentum is outpacing readiness. Fewer than half of surveyed MSPs feel fully confident guiding customers on AI tools, particularly autonomous agents, where the gap between hype and hands-on deployment is widening." The safeguard is scope: start with low-risk, high-volume tasks like password resets and patch verification, prove the guardrails, then expand.
A realistic target: move 40% of repetitive work from human to supervised-autonomous within 12 months, freeing $240K in capacity that can be redeployed to higher-margin services or absorbed as margin.
Who Owns the Telemetry Owns the Margin
Here is the trap: you automate a workflow, reduce labor, and then the vendor bills you for the AI tokens that made it possible. The savings get clawed back because the vendor owns the telemetry.
As SMBs adopt more tools, MSPs are being asked to manage mounting complexity. Expensive licensing, steep learning curves, and vendor sprawl top the list of customer frustrations. In response, demand for bundled, integrated security offerings is rising.
Nineteen tools with nineteen copilots means nineteen separate AI meters, each charging per ticket, per query, or per token. The only way to break the cycle is to consolidate telemetry onto a data layer you control, then run your own agents against that layer.
This is not a call to build everything in-house. It is a call to audit where your data lands and who profits when you act on it. If your RMM vendor charges you to run an AI query against your own endpoint data, you are renting your own information. The alternative is to export telemetry to a data lake you own, whether that is a self-hosted time-series database or a cloud bucket under your account, and run open-weight models against it.
The math: if AI copilot fees add 2-3% of revenue ($50-75K on a $2.5M shop), and you can replicate 80% of that functionality on owned infrastructure for $20K in compute, the delta funds the migration.
The Roll-Up Is Already Pricing Your Market
If you are wondering why this matters now, look at the private equity activity in the MSP space. Profitability is polarizing (10% unprofitable, 16%+ at high margins). Deal sizes are compressing (41% of MSPs at $25,000+ annually, down from 75%).
Roll-ups operate at software margins because they consolidate tools, centralize NOCs, and automate at scale. They are not buying your revenue; they are buying your client relationships and then running them on a different cost structure. If your tools line is 29% and theirs is 18%, they can undercut your pricing and still make more money.
The data: 16% of MSPs report difficulty hiring skilled technicians, up from 9% in 2025. Meanwhile, according to CompTIA's IT Industry Outlook, more than half (52%) of channel companies report experiencing a workforce shortage and have difficulty finding job candidates with the skills their organization needs. The roll-up solves this by spreading talent across a larger base and automating the repetitive layer. If you do not do the same, you are competing with one hand tied.
The strategic response is not to sell early. It is to operate at the same efficiency so you can choose whether to sell, merge, or stay independent from a position of strength.
The 90-Day Monday-Morning Plan
Theory is cheap. Here is the action plan you can start this Monday.
Days 1-30: Audit
- Export every vendor invoice from the last 12 months into a single spreadsheet.
- Tag each line with tool category, billing model (per seat, per endpoint, flat), and contract end date.
- Calculate your actual tools percentage of revenue. If it is above 25%, you have room to move.
- Run a time study: have each tech log hours by task type for two weeks. Identify the top five repetitive tasks by volume.
Days 31-60: Prioritize
- Rank tools by cost, overlap, and contract flexibility. Identify the top three candidates for consolidation or replacement.
- Rank repetitive tasks by volume and risk. Identify the top two candidates for automation at rung three or four.
- Build a business case for each move: cost to switch, time to value, and annual savings.
Days 61-90: Pilot
- Launch one tool consolidation pilot (e.g., move documentation into PSA wiki).
- Launch one automation pilot (e.g., password reset via supervised-autonomous agent).
- Measure: hours saved, errors introduced, client impact.
- Decide: scale, iterate, or abandon.
The gold standard is 350 fully managed endpoints per technician, although that number can vary based on the complexity of services and the technology stack. By maintaining this ratio, MSPs can ensure efficient operations and high service quality. If your current ratio is closer to 156 endpoints per tech, the 90-day plan is how you close the gap without hiring.
Safeguards for Autonomous Action
Automation without guardrails is how you brick a client's domain controller at 2 AM. The safeguards are non-negotiable.
Scope limits: Define exactly which actions an agent can take. Password reset yes, domain admin password reset no. Patch workstation yes, patch domain controller only with human approval.
Audit trails: Every autonomous action must be logged with timestamp, target, action taken, and outcome. If you cannot explain what happened, you cannot defend it.
Rollback capability: Any change made by an agent must be reversible within a defined window. If the agent patches a workstation and the patch breaks an application, you need a one-click rollback.
Exception escalation: Define the conditions under which an agent must stop and escalate to a human. Unknown device type, high-value client, or any action that touches compliance-sensitive data.
Regular review: Audit agent actions weekly for the first 90 days, then monthly. Look for drift, unexpected patterns, or near-misses.
The goal is not to eliminate human judgment. It is to reserve human judgment for the decisions that require it and let agents handle the rest.
Conclusion
The squeeze is structural, not a bad quarter. A $2.5M MSP that pays 29% to tools and 24% to repetitive work is left with a 10-15% net margin and no room to invest in growth, weather a downturn, or compete with roll-ups operating at software margins.
But both lines are movable. The tools line moves through a disciplined four-column audit, honest costing of alternatives, and consolidation from nineteen consoles to four or five. The repetitive-work line moves through the automation ladder, starting with low-risk tasks and expanding as you prove the guardrails.
The math is simple: cut tools from 29% to 22% and repetitive work from 24% to 18%, and you add $225K to the bottom line on a $2.5M shop. That is nearly doubling net margin without adding a single new client.
You did not build this business to hand half of it to vendors and rework. The two bills are now visible. The levers are now clear. The only question is whether you pull them.

Founder and CEO
Hey everyone, I'm Michael - founder and CEO of Flamingo. Before this, I built Vicarius, a cybersecurity company focused on vulnerability remediation, where I raised over $60M in funding. Working closely with service providers through that journey, I saw firsthand how MSPs were losing money to vendor payouts and inefficient systems - and that's when the idea for Flamingo clicked. I set out to build an open-source platform that dramatically increases MSP margins while helping them deliver better service to their clients.
