What we don't support

What we won't take on.

Most IT companies bury their limitations. We list ours up front. If your needs sit on this page, please use a different provider — we will not be a good fit.

×

Anything physical

Cabling, switch installs, printer paper jams, broken screens, swapping a dead SSD. We can ship you a recommendation; we cannot drive a van.

×

On-site visits

There is no van. There is no engineer. If a problem fundamentally requires hands at a location, we will tell you and suggest a local partner.

×

Highly regulated workloads

FCA-regulated trading systems, NHS patient-data infrastructure, classified or defence environments. Use a specialist with formal accreditations.

×

Custom software development

We will not build your internal app, write production code, or take ownership of a bespoke platform. Happy to advise on tooling.

×

Network architecture & cabling design

We do not design office networks from scratch, run site surveys, or take responsibility for physical infrastructure.

×

Legacy on-prem servers

If your business still runs an on-premise Exchange box, an SBS server, or a domain controller in a cupboard, we are the wrong fit. We are cloud-only.

×

24/7 SLAs with financial penalties

Our service is best-effort 24/7, not contractual. If you need penalty-backed uptime SLAs, you need an enterprise MSP.

×

Pretending to be a human

We will never roleplay as a person. Even if asked. The AI signs every message.

Issues we don't support

Where the agent stops, and why.

Three categories sit firmly outside the service. In each one, the agent will say so on the first message and will not attempt the work. The reasons are the same every time: physical presence, unacceptable risk, or the inability to safely validate the outcome.

Physical or on-site issues

Requires physical presence

  • Cabling or power faults

    A cable, socket, or PDU has to be touched, tested, or replaced in the room it lives in. The agent operates entirely online and cannot do that.

  • Routers, switches, or printers requiring physical access

    Reseats, port swaps, factory-reset pinholes, and toner or paper changes all need hands on the device. Out of reach for a remote-only service.

  • Hardware repairs or replacements

    Failed SSDs, swollen batteries, broken screens, dead power supplies. These need a workbench and parts, not a chat window.

  • Wi-Fi coverage or signal issues

    Coverage problems are answered by walking the building with a meter and moving access points. The agent cannot stand in the room with you.

High-risk or business-critical actions

Carries unacceptable risk

  • Tenant-wide deletions

    Bulk removal of users, mailboxes, sites, or licences across an entire tenant is irreversible at scale. The agent will not perform changes whose blast radius it cannot bound.

  • Backup or data destruction

    Deleting backups, purging retention, or wiping archives removes the safety net itself. The agent refuses any action that destroys the ability to recover.

  • Encryption key management

    Rotating, exporting, or revoking tenant encryption keys can permanently lock data. This belongs with the key owner using their documented procedure, not an autonomous agent.

  • Ransomware response actions

    Live incident response requires forensic preservation, legal coordination, and insurer involvement. The agent will help with prevention and hygiene, not the response itself.

Unsupported platforms

Cannot be safely validated

  • On-premise Exchange or servers

    Local Exchange, SBS, file servers, and domain controllers sit behind your firewall with no standard remote surface. The agent cannot verify state or outcomes there.

  • Legacy operating systems

    Windows 7, Windows Server 2012 and earlier, macOS releases past Apple support. They no longer receive security updates and behaviour cannot be safely predicted.

  • Bespoke or undocumented applications

    In-house tools, vendor software without public documentation, or systems with no API. Without a known specification the agent cannot guarantee a safe, repeatable fix.

These limits exist to protect you. A service that refuses what it cannot do safely is more useful than one that tries everything and occasionally breaks the things you depend on. The boundary is the product.

How we say no

A refusal is a feature, not a failure.

When the agent declines a request, it does so in one short message. The reason is stated plainly and anchored to one of three things: safety, certainty, or scope. There is no apology, no padding, and no redirection elsewhere — just a clear answer so you know where you stand and can act on it.

Scope

"This issue requires physical access, which this service does not provide."

Safety

"This action carries significant risk and cannot be performed autonomously."

Certainty

"There isn't enough certainty to provide a safe recommendation."

What a refusal contains

  • ·A direct statement that the request will not be carried out.
  • ·The category it falls under: safety, certainty, or scope.
  • ·A one-line reason in plain English.
  • ·If a related, in-scope action exists, an offer to do that instead.

What a refusal never contains

  • ×"Sorry", "unfortunately", or other apology language.
  • ×Defensive explanations of the agent's limits.
  • ×Suggestions to call, email, or visit a technician.
  • ×Hedging language that leaves the answer ambiguous.

Frequently asked questions

Questions about our limitations

Why each exclusion exists, and what to do when you hit one.

Why does AlwaysOnIT not offer on-site support?

Because the entire service is delivered by AI, and an AI cannot walk into your office. Rather than subcontract a van network and lose the speed and price advantage that makes the model work, we exclude on-site work completely and say so up front. This keeps the price at £4 per user per month instead of the £30 to £80 typical of providers who maintain field engineers. If you need cabling, hardware swaps, new-office fit-outs or desk-side visits, keep a local provider for those and use AlwaysOnIT for the day-to-day cloud, account and device support that makes up most of your ticket volume.

Can you support on-premise servers and network equipment?

No. On-premise servers, firewalls, switches, wireless controllers, NAS devices and other physical network infrastructure are out of scope. These require physical access, vendor-specific management interfaces and, frequently, someone able to reboot or recable a device. The AI can still be useful around the edges — interpreting an error message, explaining a configuration concept or drafting a clear technical brief for the engineer who will do the work — but it will not administer the equipment. Businesses running significant on-premise infrastructure should keep an infrastructure provider and use AlwaysOnIT for the Microsoft 365, identity and end-user layer alongside it.

Why are regulated industries excluded?

FCA-regulated financial services, NHS clinical systems and defence workloads carry obligations around certified human oversight, auditability and accreditation that an AI-only service does not currently meet. Rather than claim partial coverage and leave you exposed at an audit, we exclude these environments outright. This is a scope decision, not a technical limitation of the AI. Businesses in regulated sectors can still use AlwaysOnIT for genuinely non-regulated parts of their estate — a marketing team's Microsoft 365 tenant, for instance — but should not rely on it for systems that fall inside the regulatory perimeter. If you are unsure which side of the line you sit on, ask before signing up.

Is there any way to escalate to a human technician?

No, and this is deliberate rather than a gap. Adding a human escalation tier would reintroduce the queues, shift handovers, business-hours limits and cost base that the service exists to remove — the £4 per user price is only possible because there is no technician rota behind it. What you get instead is honesty at the boundary: if the AI cannot resolve something, it tells you in its first or second reply, explains why, and hands you a clear written summary you can give to a hardware engineer, your vendor or an on-site provider. You are never left waiting on an escalation that will not come.

What should I do in an IT emergency that needs someone physically present?

Call your hardware or on-site provider directly — AlwaysOnIT cannot help with anything requiring physical presence, including a flooded server room, a failed switch, a building-wide connectivity outage or a device that will not power on. We recommend every customer keeps a local provider on retainer for exactly these situations, and most SMEs already do. Where it helps, the AI can prepare a precise written description of the fault, the diagnostics already run and the symptoms observed, which shortens the engineer's visit considerably. Being clear about this boundary before you need it is far better than discovering it during the incident.

Does the exclusion list ever change?

It can, and when it does we publish the change on this page rather than adjusting terms quietly. Categories excluded for physical reasons — hardware repair, cabling, on-site visits, on-premise equipment — are structural and will not change, because they are incompatible with an AI-only delivery model. Categories excluded for regulatory or assurance reasons could change over time as accreditation allows. Publishing exclusions openly is the point: you can check the current boundary at any time, and we cannot narrow the service without it being visible. If something you depend on appears here, plan for a second provider from the outset.

Get started

Open a chat. The AI picks up before the second ring — every time.

No onboarding calls. No sales process. Connect your devices and start raising tickets in under ten minutes.