
A managed retainer keeps live software monitored, patched and improving after launch. Here is what one should include, how it is priced and which phrases to avoid.
A managed software retainer is a monthly agreement in which one named team monitors, fixes, secures and improves software that is already live, and reports on it every month. A real one puts five things in writing: what is monitored, how fast fixes start, how much improvement work you get, when security updates happen and what the monthly report contains.
Key takeaways
- A retainer is not "we'll fix it if it breaks." It is monitoring, fixes, improvements and reporting.
- Insist on response-time targets, a named owner and a monthly report you actually receive.
- If a vendor can't tell you what they watch and how fast they respond, that is your answer.
Why software drifts after launch
The launch is a milestone, not the finish line. The moment software goes live it starts to drift: dependencies age, integrations change, data grows, models get upgraded, and the business it serves keeps moving. Without someone looking after it, software that worked well in month one is struggling by month nine. The usual story is not a dramatic failure but slow neglect, until one day it breaks and nobody remembers how it works.
The five things a real retainer covers
When you read a support proposal, look for these five. If any are missing or vague, push until they are specific.
1. Monitoring
Someone, or something, watches the software around the clock: uptime, errors, queue depth, and for AI, accuracy and cost. You should be able to see a live status, not find out from an angry customer.
2. Fixes with a response-time target
When something breaks, how fast does work start? A real retainer states it: critical issues in hours, minor ones in days. “Best effort” is not a target.
3. Improvements, not just patches
Good partners ship small improvements every month, not only emergency repairs. The software should be a little better in month six than it was at launch.
4. Security and updates
Dependencies and platforms get patched on a schedule, before they become a breach. For AI, that includes re-evaluating after every model upgrade.
5. A monthly report you actually get
One page: what we watched, what we fixed, what we improved, and the metric that matters to you. If you never see a report, you are not really on a retainer.
The test is simple. Ask a vendor: what do you monitor, how fast do you respond, and what will I receive each month? Hesitation is the answer.
| Part | What a clear proposal names | Red flag |
|---|---|---|
| Monitoring | What is watched (uptime, errors, queues, AI answer quality and cost) and who gets the alert | “We check it regularly” |
| Fixes | A response time for each severity level, in writing | “Best effort” |
| Improvements | Hours or items per month, agreed up front | “On request” |
| Security | A patch schedule, plus emergency patches for critical flaws | “When needed” |
| Report | One page a month: incidents, fixes, updates, improvements and one key metric | No report at all |
Weasel words to avoid
“Ad hoc support,” “available on request,” “best-effort maintenance” and “we’ll look at it when we can” all mean the same thing: nobody is actually responsible. They are fine for a brochure site; they are dangerous for software your business runs on. Hourly billing is not the problem. Hourly billing with no response times, no agreed estimate and no report is.
How retainers are priced
A fair retainer is sized to what is being kept live: the complexity of the software, the volume it handles and how fast you need issues resolved. There are two common models. A fixed monthly fee suits stable software with a steady workload. An hourly rate against an agreed monthly estimate suits software that is still changing, provided the rate, the estimate and the response times are agreed in writing and nothing is billed without your approval. Either way, the monthly cost should be predictable, and the value should show up as uptime and saved hours, not just a line of cost.
How Infoloop supports live software
Building software is the easy half. Monitoring, securing and improving it after launch is where the value compounds, or quietly leaks away. That is why we support what we ship instead of handing over files and disappearing.
Infoloop’s application maintenance and support plan covers the five parts above. It includes monitoring around the clock, fixes within response times agreed in writing, security and version updates, monthly improvement hours and a plain-language report every month. Support is billed hourly, with the rate and an estimate of monthly hours agreed in writing first. It covers software other vendors built as well as our own, and we record 99.9% uptime on the software we support. The multi-plant ERP we built for a machinery maker is still live and supported by the engineers who built it.
Running an AI assistant? Read how to ship an AI agent that survives production and the metrics that prove an AI copilot is working. Inherited code nobody understands? Start with our step-by-step legacy modernization plan.
Book a support discovery call to get response times, the rate and an estimate of monthly hours in writing.
Frequently asked questions
What should a managed software retainer include?
A managed software retainer should include monitoring, fixes with a stated response time, monthly improvements, scheduled security updates and a monthly report. Monitoring should run around the clock. The one-page report shows what was watched, fixed and improved. If any of these are missing or vague, push the vendor until they are specific.
How much should a managed software retainer cost?
A fair retainer is a predictable monthly cost, sized to how complex the software is, how much it handles and how fast you need fixes. It can be a fixed monthly fee or an hourly rate against an agreed monthly estimate, as long as the rate, the estimate and the response times are in writing. It should never be a surprise invoice for work you did not approve.
How do I know if a vendor is really offering a retainer?
Ask three questions: what do you monitor, how fast do you respond, and what will I receive each month? A real partner answers with specifics, such as response time targets and a monthly report. Hesitation, or phrases such as best effort and available on request, means nobody is actually responsible.
Co-founder and CTO
Rahul is Infoloop's CTO. He sets the architecture for every client build and leads the engineers who ship and support it.



