3 · Manage — maintain and improve

Keep the tailnet governed after deployment.

Manage operates the agreed control cycle for Tailscale policies, devices, routes, connectors, changes and documentation — without relying on a single administrator's memory.

  • Finnish business hours · 08:00–17:00 Europe/Helsinki
  • Minimum 6 months
  • Price on request

When to choose Manage

When Tailscale is in production and every change needs an explicit owner.

The production state is first documented and accepted through Integrate or a separate Manage onboarding. We do not take responsibility for an environment whose starting state and rollback model are unknown.

Growing environment

Users and resources change

Permissions, tags, devices and routes remain within the approved model.

Continuity

Knowledge does not stay with one administrator

Policy, tests, runbooks and decision trails remain under customer control.

Governance

Changes and exceptions are visible

The service report consolidates completed changes, open risks and upcoming decisions.

Ongoing management

One service with capacity sized to the customer's environment.

Manage is delivered as one service. The proposal is sized according to tailnets, users, resources, connectors, integrations and monthly change demand.

Changes

  • policy changes through a pull-request, review and testing model
  • user, device, tag, route and connector lifecycle
  • maintenance of webhook, API and GitOps automation

Review

  • regular access, policy and routing review
  • review of audit, approval, route and key exceptions
  • escalation to Tailscale support within the agreed scope

Evidence

  • maintenance of documentation, inventory and runbooks
  • monthly report on changes, exceptions and risks
  • agreed service and architecture review

Service hours and initial response

A defined Finnish business-hours service commitment.

Coverage is provided from 08:00 to 17:00 Europe/Helsinki on Finnish business days, excluding Finnish public holidays. Initial response means receiving and classifying the issue and starting progress — it is not a resolution time.

  1. P1 · four covered business hours: broad production access is blocked or a critical Tailscale configuration risk is identified.
  2. P2 · next Finnish business day: a significant access path is degraded, but a limited workaround is available.
  3. P3 · three Finnish business days: a normal change, improvement request or non-critical investigation.

Service acceptance

The monthly report shows agreed changes, reviews, exceptions, open decisions and next actions. The customer has up-to-date configuration and documentation.

Responsibilities and exclusions

Manage governs the Tailscale layer — not the entire security environment.

Plan-dependent capabilities, such as log streaming or specific posture integrations, are implemented only when supported by the customer's Tailscale subscription.

No 24/7 on-call service

Evening, weekend and on-call work is agreed separately. The service does not include an availability guarantee.

No SOC/MDR/IR service

Manage is not a security operations centre, threat-hunting, forensics or incident-response service.

No full management of other platforms

Ownership of IdP, MDM, EDR, SIEM, cloud and network environments remains with the customer or a named provider.

Pricing

Monthly service and one-time onboarding.

Pricing is based on users, resources, routing and connector models, integrations, change capacity and reporting. The minimum term is six months.

Price on requestTailscale licences and third-party services are not included. Manage onboarding is required unless the service starts immediately after an accepted Integrate delivery.See how pricing is determined →

Next step

Does the current tailnet need an ongoing owner?

Describe the tailnet's size, use cases and current management model at a high level. We will respond by the next Finnish business day.

Book a 30-minute Manage scoping call