Ordering Logic: To scale existing mandates with tiered credits and avoid redundant setup fees, please utilize our Payment Portal. Use this Catalog for new service enrollments and distinct structural orders only. To ensure full fiscal transparency, all hardware, cloud services, and VoIP usage are delivered as pure MSRP pass-throughs.
The Stewardship Model: Provision for a specific number of Personas that evolve with your organization. For your permanent infrastructure, Annual Mandates provide one month of stewardship at no additional cost. Two-Year Mandates extend this advantage to 1.5 months. Monthly Mandates provide on-demand elasticity, serving as a flexible operational buffer for short-term contractors and transitional staff.
Architectural Governance: To enforce consistent security and governance without sacrificing flexibility, your architecture is anchored by a single Identity Provider (Microsoft or Google). From this baseline, you dictate your footprint: drive deep integration within a single-cloud Primary Foundation or provision Multi-Cloud Enclaves for specialized teams. continue reading …
Core Stewardship Mandates (Cloud Personas)
Microsoft 365
$225 per unit / month
with annual commitment
5 users min. on first order
$250 one-time asset hardening / PC
One-time per-org 365 foundation is ordered separately.
Check our Service Blueprints and our detailed Mandates feature list for more information.
Note: Virtual Desktop and Virtual App Delivery available as add-ons (see add-ons section below)Microsoft 365 + Google Workspace (or Zoho Workplace)
$290 per unit / month
with annual commitment
5 users min. on first order
$250 one-time asset hardening / PC
No asset hardening for ChromeOS devices
Macs in a M365 estate, and PCs or Macs in a Google estate need the Outlier mandate.
Any applicable, one-time, per-org ecosystem or hardware foundations are ordered separately.
Check our Service Blueprints and our detailed Mandates feature list for more information.
Note: When you need a secondary collaborative environment strictly to isolate management or sensitive R&D workflows, we also offer The Concierge Cloud Atelier. The Atelier completely air-gaps your data from Big Tech ecosystems and makes your intellectual property immune to AI training scans by encrypting it before it ever reaches a server.
Note: Windows Virtual App Delivery available as an add-on. Virtual Desktop is included natively in the Full Concierge Federated Enterprise mandate.
Google Workspace
$180 per unit / month
with annual commitment
5 users min. on first order
No asset hardening for ChromeOS devices.
PCs or Macs in a Google estate need the Outlier mandate.
Any applicable, One-time, per-org Google Workspace, ChromeOS, or virtualization foundations are ordered separately.
Check our Service Blueprints and our detailed Mandates feature list for more information.
Note: If your firm runs Google Workspace on Windows PCs or Macs, a Managed Outlier mandate is required for hardening, device management and endpoint threat protection.Note: Windows Virtual App Delivery available as an add-on. Virtual Desktop is included natively in the Full Concierge Federated Enterprise mandate.
Microsoft 365 via Virtual Desktop
For a deeper look at the architecture behind virtual desktops and how isolation boundaries enforce compliance, see Why Virtualization?
$190 per unit / month
with annual commitment
5 users min. on first order
Any applicable one-time, per-org ecosystem and virtualization foundations are ordered separately.
Check our Service Blueprints for more information.
Note: Stewardship does not include physical hardware coverage or the 1.20 Readiness Standard for personal computer management.
Multi-Cloud + Virtual Desktop
$325 per unit / month
with annual commitment
5 users min. on first order
$250 one-time asset hardening / PC
No asset hardening for ChromeOS devices
Macs in a M365 estate, and PCs or Macs in a Google estate need the Outlier mandate.
Any applicable one-time, per-org ecosystem, hardware, or virtualization foundations are ordered separately.
Check our Service Blueprints and our detailed Mandates feature list for more information.
Microsoft 365
$60 per unit / month
with annual commitment
5 users min. on first order
Any applicable one-time, per-org ecosystem or virtualization foundations are ordered separately.
Check our Service Blueprints for more information.
Note: This mandate is restricted to mobile and web-only use. Stewardship does not include physical hardware coverage or the 1.20 Readiness Standard for personal computer management.
Note: Desktop as a Service and Virtual App Delivery available as add-ons on any monitor size (see add-ons section below)
Virtual Windows App Delivery
To understand how app streaming achieves Zero-Trust isolation on unmanaged devices, see Why Virtualization?
$115 per unit / month
with annual commitment
10 users min. on first order
$4500 one-time VAD foundation per org.
Check our Service Blueprints for more information.
Note: Includes one primary application. Additional apps: $100/unit/org./m with yearly commitment.Persona Mandate Add-ons
Beyond the stewardship of a regular managed endpoint, this mandate covers the platform-side discipline specific to virtual desktops: image configuration and lifecycle, policy correctness, controlled patching, profile reliability at scale, and response to platform-wide issues that may affect many users at once.
For a deeper look at the architecture behind virtual desktops and how isolation boundaries enforce compliance, see Why Virtualization?
Note: A Virtual Desktop functions as a distinct, enterprise-grade endpoint within your environment. To maintain platform integrity, each instance requires the same security and management posture as a physical workstation. This fee is commensurate with the essential licensing and tooling required to secure and manage this secondary environment.
Note: This mandate is delivered using Azure Virtual Desktop (AVD), Windows 365, or a private VDI environment to meet your firm's governance, security, and data residency requirements. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.
To understand how app streaming achieves data sovereignty and Zero-Trust isolation on unmanaged devices, see Why Virtualization?
Note: This mandate, along with its hardening fee, is entirely waived for auxiliary machines covered under your 20% Spare Device Allowance (up to 20% of your active fleet, capped at ten). Covered spares are provisioned and stewarded to the exact same standard at no cost.
One-time Per-org Tenant Hardening Fees
AVD or Windows 365
Note: This mandate is delivered using either Azure Virtual Desktop (AVD) or Windows 365. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.
Proxmox or Nutanix
Note: This mandate is delivered using either Proxmox or Nutanix. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.
App Session-level Orchestration
Infrastructure Asset Mandates (Managed Assets)
$80 per unit / month
with annual commitment
$250 asset hardening / PC
Check our Service Blueprints for more information.
Note: Managed assets carry the identical remote telemetry, patching, and MDR/SOC licensing burden as a primary endpoint. Because secondary and shared devices often introduce unique vulnerabilities, they demand equal, continuous oversight and hardening.
Note: This mandate, along with its hardening fee, is entirely waived for auxiliary machines covered under your 20% Spare Device Allowance (up to 20% of your active fleet, capped at ten). Covered spares are provisioned and stewarded to the exact same standard at no cost.
$200 per server / month
with annual commitment
$1200 one-time build / hardening
Check our Service Blueprints for more information.
Note: Software licensing and third-party hosting fees not included. They are delivered as pure MSRP pass-throughs.
Note: This protection is available for new servers and as a standalone service for self-managed or Legacy Sustainment assets.
Note: This add-on mandate covers the management and tuning of your security architecture. Because application and compliance requirements demand a highly tailored solution, the underlying software licenses and infrastructure for the protection itself are procured separately.
Office Connectivity Stewardship. Comprehensive oversight for your office connectivity infrastructure. This mandate covers the setup and administration of the stateful gateway, firewalls, and switching fabric. Stewardship applies to services such as Multi-WAN routing, VLAN segmentation, VPN access, and IDS/IPS for one physical /24 subnet. Expert management of the gateway ensures the network remains secure, optimized, and under your total sovereignty.
When a network is still required. Zero-Trust removes the perimeter for people and their applications. It does not remove it for everything else. Printers, cameras, phones, door controllers, payment terminals, and medical, lab or building equipment cannot run an agent or be patched on demand, so the network is the only place they can be contained. Legacy applications tied to a local server, and requirements such as PCI segmentation or data residency, call for it outright. And the building itself still needs Wi-Fi, cabling, and the switch that powers the locks and the cameras.
$350 per unit / month
with annual commitment
$2500 one-time build / hardening
Check our Service Blueprints for more information.
Note: The build/hardening fee is waived for preexisting, remotely manageable networks running Ubiquiti UniFi or Netgate infrastructure, provided the hardware has not reached End-of-Life (EOL) and administrative control is fully transferable.
Zero-Trust
The North-South Perimeter (People-to-Systems): We project your applications securely onto the internet through a centralized, high-speed identity gateway that replaces vulnerable traditional access methods. This sovereign perimeter enforces identity-first validation for personnel, it retrofits modern Single Sign-On (SSO) and MFA protection onto legacy or non-compliant applications, and it grants clientless, scoped access for third-party vendors.
The East-West Overlay Mesh (System-to-System): Across your servers, cloud environments, databases, and endpoints, we weave an encrypted virtual backplane. Traffic routing and micro-segmentation run on infrastructure you own and control, keeping the data plane sovereign. This software-defined mesh darkens communication paths between disparate locations, eliminating the risk of lateral threat movement.
Datacenter
This platform is purpose-built to host stateful line-of-business applications and persistent virtual desktops with predictable performance. This sovereign architecture replaces volatile, consumption-based cloud billing with a durable, fixed-cost asset. It reduces long-term spend and gives you a resilient foundation for projecting these workloads across the local network and the global edge.
For comprehensive data protection, we strongly advise provisioning a fourth, storage-optimized server to act as a dedicated local backup repository. Because backup workloads require disk capacity rather than high compute power, this node can be provisioned with reduced specifications, providing an isolated, cost-effective rapid recovery target for your virtual desktops, servers, and container snapshots.
Note: This mandate is delivered using either Proxmox or Nutanix. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.
Note: For VDI environments, a Virtual Desktop Foundation is required to establish the orchestration layer that runs dedicated Windows virtual machines and sustains their performance at scale. Note: Management of the backup node incurs no additional labor fees; it is covered under this Cluster Stewardship mandate.
Credential Governance
Organizations with advanced regulatory needs should consider the Compliance Edition, which adds a hardened Business-core layer and full activity logging to satisfy SOC 2 and industry-specific audits.
Legacy Asset Mandates (Business Continuity)
Strategic Project Mandates (Prepaid Blocks)
For prospective clients seeking complete visibility into their digital estate, we offer a comprehensive diagnostic engagement at a discounted package rate. This includes a thorough infrastructure inventory and our Sovereignty Snapshot security assessment (below), as well as the identification of strategic opportunities and pre-existing technical debt.
Following the audit, we provide a detailed report and a Hardening Roadmap estimating the hours required for our Principal and Technical Fellows to resolve any technical debt. When you transition to an ongoing stewardship mandate, we will proactively manage and evolve your environment based on the scope of that mandate. However, resolving pre-existing technical debt remains a separate mission, billed outside the mandate at our standard principal consulting rate.
If significant technical debt is discovered, whether during an initial audit or an active mandate, we reserve the right to limit or suspend certain performance and security guarantees until a foundational Baseline of Sovereignty is properly established.
Standard: $12,500 up to 50 users, one tenant, up to 15 applications
Extended: $25,000 up to 150 users, multi-tenant, up to 40 applications
Note: To maximize your investment, clients who initiate an ongoing Stewardship Mandate concurrently with their audit immediately unlock our 15% Preferred Partner Discount (Code: INNET). This preferred rate applies directly to the Discovery Audit itself, as well as any subsequent engineering labor required to resolve legacy technical debt. By running both engagements in parallel, we secure your daily operations immediately while systematically hardening your underlying architecture.
Note: Strategic Mandates of 40 hours or more qualify for a 10% Governance Credit, providing a pre-paid value bonus and priority scheduling for large-scale advisory and engineering projects.
Note: Use Code INNET for 15% off project labor, reflecting the management overhead already satisfied by your Full Concierge monthly mandate.
The Stewardship Toolkit
Note: This mandate includes the software license, deployment, API integration, and continuous system/user stewardship. For self-managed environments, standalone licenses are available via the Microsoft Store or directly through timesqueeze.net.
Note: This mandate includes the software license, deployment, and continuous system/user stewardship. For self-managed environments, standalone licenses are available via the Microsoft Store.
Note: This mandate includes the software license, deployment, and continuous system/user stewardship. For self-managed environments, standalone licenses are available via the Microsoft Store.
Auxiliary mandates and stewardship extensions.
User-Side Stewardship. We govern the human and operational boundaries of your automated workforce to keep it controlled and secure. Strict profile isolation lets multiple executives or departments use the system simultaneously without cross-contaminating their workflows or memories. We maintain a centralized, human-readable "Shared Playbook," a secure repository where the agent's generated procedures are reviewed and curated before they become standard practice. And we enforce strict approval protocols: the agent must request explicit human sign-off, via chat or mobile push, before executing any high-risk action. We operationalize the intelligence, ensuring it remains a strictly governed, highly efficient extension of your organization.
A secure enclave is only as strong as its access protocols. Our user-side stewardship enforces that boundary. We integrate your team into zero-knowledge workflows, architect precise permissions, and anchor your intellectual property within organizationally controlled Team Drives. Should team composition change, we execute immediate server-side access revocation. The departing user is cryptographically locked out of the workspace while your firm's data remains accessible and the zero-knowledge perimeter unbroken.
Note: The standard edition of the Concierge Cloud Vault is provisioned and managed within our Full Concierge mandates.
We engineer an automated pipeline that exports every tenant audit log into a write-once archive. Depending on your regulatory profile, we deploy this inside your existing cloud for certified compliance, or to independent flat-rate storage to eliminate hyperscaler retrieval penalties. The archive operates under a locked retention policy that no administrator can shorten or delete. Each export is cryptographically stamped on arrival, making any tampering instantly provable. As your Steward, we monitor the pipeline for gaps, maintain chain of custody documentation, and produce the extract when counsel, an insurer, or an auditor asks for it.
Your forensic history remains entirely under your ownership and freely accessible to local AI sandboxes. MSPs trap your logs inside their own vendor subscriptions, forcing you to rent access to your own evidence and risk losing it entirely if you leave them. We build the vault in your name, ensuring you never lose your history.
A Note on Telemetry Depth: While this Archive guarantees the survival of your evidence, the depth of that evidence depends on your Microsoft or Google license. Standard tiers track logins, file creations, and downloads. If your risk profile requires granular incident response data, such as proving whether an intruder actually opened a specific email, an add-on will be required on top of your users' monthly cloud licensing fees.
Note: Dedicated flat-rate storage and extraction are fully bundled in our fee. If your regulatory profile (e.g., HIPAA/BAA, SOC 2, FINRA) requires the immutable archive to reside inside your own Azure, Google or AWS boundary, the vault is engineered directly in your cloud, and underlying raw storage (typically pennies per month) is billed directly to your cloud provider.
Architectural governance, continued
Where organizational scale and go-to-market strategy demand it, you may also embrace a company-wide Dual-Ecosystem to unlock best-of-breed capabilities, support highly specialized workflows, and effectively integrate with external clients' and partners' ecosystems.
Ordering, governance & fee policy
Marginal Scaling: We apply Scaled Stewardship Credits to every progressive tier of your estate: 5% (units 10 to 25), 10% (units 26 to 100), and 15% (units 101 to 400). This ensures your average cost per unit decreases as your operational maturity increases, reflecting the architectural efficiencies gained as you scale.
The 1.20 Readiness Standard: Our 1.20 Readiness Standard maintains both a 20% hardware buffer and an emergency virtual desktop to ensure a 15-minute return to billability. To support this physical redundancy, we steward auxiliary computers up to 20% of your active PC and Mac fleet, up to a maximum of 10 machines, at no cost. These covered units incur no one-time hardening or recurring mandates. Machines beyond this allowance take a Managed Asset or Managed Outlier mandate, while spare Chromebooks require no hardening and remain entirely exempt from the count.
The Genesis Mandate: To give you complete visibility into your infrastructure before beginning a possible long-term residency, we invite you to undergo a comprehensive Discovery Audit. This initial project maps your digital estate to identify vulnerabilities, strategic opportunities, and pre-existing technical debt. While our ongoing mandates focus strictly on the buildup and proactive evolution of your environment, the audit provides a clear diagnostic of your starting point. You can explore this engagement in the Project section above.
Foundations: These one-time, organization-level engineering charges cover the architectural build, configuration, and hardening of your cloud, virtual, and hardware environments. A separate Foundation applies to each ecosystem you introduce (e.g., a multi-cloud estate requires both the Microsoft and Google Foundations, while the presence of Macs necessitates the macOS Foundation).
Licensing: Wherever applicable, our persona mandates include a premium productivity suite, such as Microsoft 365 Business Premium or Google Workspace Business Plus. Where a persona does not need a full suite, that becomes a Frontline license, Teams or equivalent. ChromeOS personas include Chrome Enterprise. For a plan-by-plan breakdown of what each Microsoft license actually contains, see M365 Maps.
Asset Hardening Fees: These setup charges apply per-device to ensure provisioning, persona alignment, and architectural security. When subscribing to our persona mandates, manually select the quantity in the dropdown to match your hardware count. Additional setups for subsequent adjustments or replacements are available in the Add-ons section above.
Maintenance Absorption: Assets vetted by a Principal Steward qualify for our "One-In, One-Out" policy. This ensures that any approved Windows device replaced during a Persona mandate is hardened and integrated at no additional cost for the remainder of that term. Both the replaced and replacement PCs must be vetted.
The Managed Outlier: Any device that falls outside your primary cloud ecosystem (such as a Mac in a Microsoft estate or a PC or Mac in a Google estate) is considered Foreign. Because this hardware requires its own separate management plane, identity bridge, and monitoring system, it cannot be stewarded under standard terms. Therefore, barring your 20% auxiliary allowance, every Foreign machine must take The Managed Outlier add-on mandate.
ACH Stewardship Discount: Partners who remit via ACH bank transfer receive a 1.5% recurring discount applied automatically to their mandate. This reflects the elimination of card network interchange fees, a cost we pass directly back to you rather than absorbing into our pricing. To get the discount, check out using a verified bank account and apply the matching code:
- ACH for recurring mandates
- ACH-ONETIME for single charges
If you are currently paying by card and would like to switch, contact your Principal Steward or update your method through the Payment Portal.
Once you have deployed your order, please register and log into this site to manage your onboarding. Your Principal Steward will guide you through your first deployments, onboardings, and offboardings.