Go-live isn't the finish line
Most projects budget for construction and treat support as an optional extra. In critical systems that split is backwards: the system is built once and operated for years.
What determines whether a platform is still reliable in its third year isn't the quality of the original code, but whether someone kept up with updates, regulatory changes and the incidents that came up along the way.
What's included
Remote administration and maintenance of your systems, a Help Desk for reporting and tracking incidents, monitoring, and planned updates applied in maintenance windows agreed with your operations.
Subscription tiers are set according to how critical each system is. It makes no sense to pay for maximum-availability coverage on a platform that can wait until the next day — or to under-cover the one that supports customer service.
How an SLA should be written
With differentiated severity levels. A formatting error in a report and an outage of the transactional channel can't carry the same committed response time.
With defined consequences for non-compliance. An SLA without consequences is a statement of intent. Penalties don't make up for operational damage, but they align incentives.
With an escalation path. Critical projects can't depend on one person being available.
Reporting
Every period we deliver a breakdown of incidents handled, response and resolution times against commitments, and preventive work performed.
That evidence serves two purposes: it lets you evaluate whether the service is meeting its commitments, and it gives your organization documentation of how its systems are managed when someone asks for it.