Control / 01
Ten checks from signature to exit
Record the document, named owner, review date, and unresolved point for each check. A marketing page or directory entry is a lead, not a substitute for the signed record.
-
Contracting counterparty
Record the exact legal entity that signs, invoices, supplies the person, accepts obligations, and receives notices.
- Check the legal name, registered address, registration number, and tax details that apply to the transaction.
- Ask whether another entity employs, contracts, or pays the proposed person.
- An office address, trading name, or partner listing does not prove the contracting entity.
-
Scope and document order
State which document controls the role, allocation, deliverables, acceptance, changes, charges, and conflict between terms.
- Connect the master agreement, statement of work, order, proposal, security schedule, and data terms.
- Record which document wins if two clauses disagree.
- Keep availability, hours, location, and substitution person-specific.
-
IP and third-party materials
Define ownership and permitted use of work product, existing code, open-source components, tools, and third-party materials.
- Separate new buyer-paid work from each party's existing materials.
- Require a record of dependencies, licences, notices, and restrictions.
- Ask counsel when assignment, licence, moral-right, or jurisdiction terms need specialist review.
-
Confidentiality boundary
Identify protected information, permitted recipients and systems, required handling, return or deletion, and continuing duties.
- State whether subcontractors may receive confidential information and under what approval.
- Define safe channels for code, credentials, customer information, designs, and incident evidence.
- Do not rely on a general confidentiality label without operational handling rules.
-
Data and subprocessors
Map personal and sensitive data, processing purpose, storage and access countries, subprocessors, retention, deletion, and incident duties.
- Include production data, logs, backups, support exports, ticket attachments, and copied test data.
- Record which entity controls or processes each data set and which tools receive it.
- Ask qualified counsel to assess data terms and international transfer requirements.
-
Repository ownership
Keep source, history, branches, reviews, pipelines, dependencies, and documentation in buyer-approved repositories and accounts.
- Define the branch, review, merge, release, backup, and archival rules.
- Do not let the only current source or pipeline live in a person's private account.
- Record how external tools connect and how their tokens are removed.
-
Privileged and production access
Use named accounts, least privilege, approval, logging, review dates, emergency access, and a clear revocation owner.
- Separate repository, cloud, database, commerce admin, payment, ERP, PIM, monitoring, and support privileges.
- Require multi-factor authentication and approved secret storage where the buyer policy calls for them.
- Record break-glass access and who reviews its use.
-
Security and incident route
Name the reporting channel, contacts, evidence-preservation steps, response expectations, and decision owner for a suspected incident.
- Tell the proposed person what must be reported and how quickly under the agreed documents.
- Keep emergency contacts current across buyer and supplier teams.
- Do not promise a response time that is absent from the signed terms.
-
Offboarding and revocation
Set triggers and owners for account disablement, token and key rotation, device or asset return, and access-log review.
- Cover planned end dates, substitution, absence, role change, suspension, and urgent termination.
- List each system owner and the required evidence of revocation.
- Check service accounts and shared secrets that may survive a user-account removal.
-
Exit materials and transition
List the code, tests, documentation, inventories, open risks, credentials, walkthroughs, and transition support due at exit.
- Set delivery dates early enough for buyer review and correction.
- Name the buyer recipient for each artifact and walkthrough.
- Record open defects, unfinished work, temporary controls, dependencies, and decisions still required.
Control / 02
Trace the counterparty before the person starts
Provider branding can cover several entities and worker relationships. Record the chain without assuming that one public address settles it.
Signature
Who signs and accepts obligations?
Record the full legal name, registration details, notice address, signatory authority, governing terms, insurance evidence if required, and dispute route selected with counsel.
Invoice
Who invoices and receives payment?
Confirm the invoicing entity, currency, tax treatment selected with advisers, payment account, purchase-order requirements, and how a changed bank account is verified.
Person
Who supplies or employs the developer?
Record any employer, contractor, agency, employer-of-record, or subcontractor link and the document that passes relevant duties through that chain.
Data
Which entities and tools receive data?
Map access and storage countries, approved tools, subprocessors, support routes, retention, deletion, and evidence for any material change.
Control / 03
Build access around a named account
For each system, record why access is needed, the smallest useful privilege, the approval owner, the review date, and the removal event.
Access control register
| Surface | Record before access | Exit check |
|---|---|---|
| Source repository | Named account, repository scope, branch rights, merge rights, token owner. | Disable account, revoke tokens, review recent activity. |
| Cloud and hosting | Environment, role, expiry, logging, emergency procedure. | Remove role, rotate affected secrets, review audit log. |
| Commerce admin | Store scope, business functions, approval, test account. | Disable user, invalidate sessions, confirm no shared account. |
| Data stores and logs | Data class, masked option, query rights, export rule, retention. | Remove grants, locate exports, apply agreed return or deletion steps. |
| ERP, PIM, payment, and support tools | Each system owner, least privilege, integration boundary, sensitive action. | Revoke every linked role and inspect service-account dependencies. |
| Devices and secrets | Approved device, security controls, secret manager, prohibited local storage. | Return assets, revoke certificates, rotate keys, record completion. |
Control / 04
Sequence the exit before access is granted
The contract sets duties. The operational sequence assigns people, systems, evidence, and timing to those duties.
- 01
Trigger
Record the end date or urgent event, notify owners, freeze unapproved changes, and preserve needed evidence.
- 02
Artifacts
Review source, tests, documentation, decisions, inventories, open work, risks, and required third-party notices.
- 03
Transfer
Run walkthroughs, answer buyer questions, assign unresolved work, and record accepted and rejected handover items.
- 04
Revoke
Disable accounts, return assets, rotate secrets, inspect logs, apply agreed data return or deletion, and retain completion evidence.
Related field tool
Keep contract controls tied to the role brief
Return to the single-developer brief when the entity, working model, access need, acceptance owner, or exit output changes. A material change may require a revised proposal or signed document.