In this guide
Self-hosting can give a co-op more choice over where and how a service runs. A managed service can reduce the operational work your members must carry. Neither description tells you, by itself, whether the result is secure, affordable or easy to leave.
Compare operating arrangements rather than identities. Open-source software can be professionally managed, and a commercial platform can still require substantial local administration. The decision should account for your co-op's skills, available time, continuity needs and reasons for wanting control.
Define the control you actually need
List the requirements behind the preference: a chosen data location, exportable records, specific integrations, customisation, predictable support or avoiding dependence on one supplier. Be precise. “We want control” is difficult to test; “we can export our files and membership records in documented formats and move them to another provider” is reviewable.
Also record the consequences of downtime. An occasional discussion space and an ordering service used every trading day need different recovery arrangements. If the technical volunteer is unavailable, who will diagnose a fault and who has authority to act?
Use the collaboration-platform comparison to evaluate user needs separately from hosting preferences. A well-operated platform still needs to support the actual work.
Divide the responsibilities explicitly
The NCSC cloud shared-responsibility guidance explains that responsibilities remain divided between providers and customers. Ask who handles each layer in your proposed arrangement.
- Infrastructure: servers, networking, storage and platform availability.
- Software: supported versions, application updates and compatibility.
- Accounts: user approval, permissions, authentication and leavers.
- Recovery: backups, retention, restoration and testing.
- Monitoring: alerts, fault investigation and escalation.
- Information: content accuracy, lawful use, retention and member requests.
- Exit: exports, migration assistance, deletion and documentation.
Write a named owner against every line. “The provider handles security” is too broad to explain whether it updates the application, reviews your permissions or responds to a compromised account. Ask the provider to identify exclusions as clearly as included work.
Test the maintenance burden
Nextcloud's backup documentation covers configuration, data, database and other relevant folders. Its upgrade guidance includes compatibility and sequencing requirements. These are concrete examples of operating work beyond installing an application once.
For an illustrative self-hosted document service, ask the proposed operator to demonstrate a routine update, a failed-update response and a restore into a separate environment. Then ask another authorised person to follow the documentation. If only the original installer can recover it, the co-op has a continuity gap to resolve.
For a managed alternative, request an equally concrete explanation: how to report a fault, expected support arrangements, evidence of restore testing and what happens when a component reaches end of support. Do not infer service levels from the word “managed”.
Include an absence exercise in either option. Describe a service failure on a day when the usual operator is unavailable. Ask who receives the alert, who can approve recovery, where credentials are held and how members receive an update. Check the answer against the actual support agreement or rota. If there is no coverage at that time, record the limitation and decide whether the co-op can tolerate it. An honest support boundary is easier to plan around than an assumed promise.
Compare a full year and a credible exit
- Estimate setup and migration work for each option.
- Annualise hosting, licences, backups and routine support.
- Include staff or volunteer time for maintenance and user assistance.
- Allow for hardware replacement or additional capacity where relevant.
- Cost the work needed if the main operator or supplier becomes unavailable.
- Perform a sample export and confirm another system can use it.
A co-op with reliable technical capacity may reasonably choose to operate some services itself. A co-op whose members are already stretched may prefer managed hosting while retaining organisational ownership and good exports. A mixed approach can also work, provided responsibilities remain understandable.
Record the tradeoffs, owner and review date. Test recovery using the backup guide, and compare full costs in the technology budget tool. Revisit the decision when the people or requirements change.