Buying signals

Systems-change signals: AI rollouts, vendor switches, and projects before launch

Three public traces that show a firm is changing how its technology works, why each one puts an IT decision on the owner's desk, and what a managed service provider (MSP) should say when it gets there first.

SiteSmith AI outbound system diagram, used here to illustrate how systems-change signals feed an MSP target list

Most MSP prospect lists are built from what a company is: size, industry, location. The lists that produce conversations are built from what a company is doing. This page covers the first group from our guide to the 18 buying signals that show a company is about to change IT providers: the three signals that show a firm is changing its systems. Each one puts a decision about outside IT help on an owner's desk before the firm starts calling providers, and each is slow to spot by hand.

Systems-change signals are public traces that a company is altering how its technology works, and they predict a decision about outside IT support. Three matter most for a managed service provider. First, an AI rollout: a firm moves from staff using AI tools on personal accounts to a company account. That week it needs single sign-on, data retention settings, an acceptable-use policy, and someone to run the rollout. Second, an email or security vendor change: when a firm's email filtering or public sender records change, an IT provider change or a migration is usually under way. Third, an IT project before launch: new remote-access, client-portal, or AI systems often appear in public records before they go live. Each signal is slow to find by hand because the trace is spread across sources that no one person reads. An outbound system can watch for these signals and put the firms showing them at the top of a list built to the provider's ideal-client definition.

1. AI rollout: personal accounts become a company account

AI use inside most small professional firms started unofficially: a paralegal pastes a contract into a chatbot on a personal account. Then the firm makes it official and buys a company account. That decision changes the IT picture in one week. Someone must connect the tool to the firm's login system, set how long prompts and uploaded files are kept. Someone must also write an acceptable-use policy and teach staff what may and may not go into the tool. Few firms of 10 to 60 people have done this before.

Regulators have noticed. The Securities and Exchange Commission (SEC) examination priorities for fiscal year 2026 say examiners will assess whether firms have adequate policies and procedures to monitor or supervise their use of AI. The American Bar Association's Formal Opinion 512 says a lawyer's duties of competence and confidentiality apply to generative AI tools. An owner who opened a company AI account this week is responsible for controls that did not exist last week.

A company standardizing on an AI tool leaves a public trace. The trace is small and spread across every firm in a territory, so a salesperson cannot check it by hand.

2. Email or security vendor change

Every company that sends email publishes a small set of public records that tell other mail servers who may send on its behalf and where its mail should go. Those records change rarely. When they do, something real is happening: the firm moved to a new email platform, changed its filtering service, or brought in a new IT provider who set things up their way.

For an MSP this means one of two things. Either a competitor just won the account, which tells you the firm buys outside IT help and roughly when its agreement comes up again. Or the firm is doing the migration itself, and the hard parts are still ahead. Both are worth a message. The second is worth a call.

Financial firms have a regulatory reason too. The SEC's 2024 amendments to Regulation S-P require covered firms to keep written policies for oversight of the service providers that handle customer information, including due diligence and monitoring. An adviser that just changed vendors has a new provider to document. The records are public and free to read, but a change only shows up when a system is looking for it.

3. An IT project before launch

Firms leave a paper trail before they launch a new system. A client portal, remote access for a second office, an AI assistant for intake: these show up in public records before the launch date, in a regulated firm's filing or in a public announcement. Those filings and announcements are scattered across many sources and nobody reads them for a whole territory, so by the time a salesperson hears about the project it is usually live.

The value of this signal is timing. Once a system is live, the firm has already chosen who built it and who supports it. Before launch, the questions are still open: who runs the security review, who handles identity and access, who is on call in the first week. An MSP that arrives before launch is a candidate for all three. One that arrives after is a candidate for none.

One need sits on the calendar and needs no public trace to see. Microsoft's Extended Security Updates for Windows 10 cost organizations $61 per device for the first year, and the price doubles each year for up to three years. A firm that bought updates instead of replacing machines has a device refresh ahead of it. Ask whether the firm is paying for extended updates, and offer a fixed-price refresh plan before year two doubles the bill.

4. What to say when you reach a firm showing one of these signals

Each signal supports a different first conversation, so do not send the same message to all three.

Governed AI setup (signal 1). Do not sell AI. The firm already bought it. Offer to make it safe to use. That means single sign-on so accounts can be shut off the day someone leaves, retention settings that match the firm's record-keeping duties, a one-page acceptable-use policy, and a short staff training. The owner wants to answer an examiner's question, not hear about the future of work.

Migration (signal 2). Ask what is moving and when. If a competitor is already hired, ask when the agreement ends and offer to be the second opinion then. If the firm is doing it alone, offer a fixed-scope migration review: what will break, what to back up, how to keep mail flowing.

Project (signal 3). Name the project you saw and ask who is handling security and access. Offer a pre-launch review at a fixed price. The support agreement tends to go to whoever is in the room before go-live.

One message per signal. A firm that just opened a company AI account gets the governed-setup note. It does not get a general "are you happy with your IT provider" note. The signal is the reason for the message, so say the reason.

5. Two honest caveats

First, nobody buys the day the event happens. Follow-up runs over weeks, not once, and later messages should point to the same reason for reaching out.

Second, the sharpest signals are low volume. Only a small share of firms in a territory shows one of these signals at a given time. They belong at the top of a list built to the MSP's ideal-client definition. They are not the whole list.

Where to go from here

The next group is people and hiring: a new chief operating officer (COO) or compliance officer, and job posts that show one person carries the firm's whole IT load. Read People and Hiring Signals: New Leaders and Telltale Job Posts. For the system that turns this list into conversations, see our guide to building an MSP outbound system.

Sources and editorial note

SiteSmith publishes practical operating guidance and cites external sources for factual industry and security claims. This article is not legal, regulatory, or cybersecurity advice.

Want to see how the pieces fit your MSP?

We will look at your offer, target accounts, deliverability requirements, and sales handoff before recommending a build.

Book a fit call