| Contract exit rights | Notice period, termination assistance, export formats, post-termination access window and deletion proof route. | “Can we leave without losing operating evidence?” | Signing production use without practical exit terms reviewed. |
| Data portability | Input/output logs, retrieval sources, embeddings metadata, user feedback, evaluation sets and export owner. | “What exact data can we export and test elsewhere?” | Assuming dashboard screenshots are a usable export. |
| Prompt and workflow ownership | Prompt versions, policy rules, tool instructions, human-review paths and business process maps. | “Can our team understand how the agent works?” | Letting vendor-only configuration become undocumented process knowledge. |
| Tool and credential boundaries | API keys, service accounts, scopes, revocation steps, delegated access and secret rotation evidence. | “What must be revoked or transferred on exit?” | Sharing broad credentials with no owner or rotation plan. |
| Fallback operations | Manual process, previous automation, alternate model/app route, support queue and rollback test evidence. | “How do customers or staff keep working during transition?” | Treating vendor uptime as the only continuity plan. |
| Handover proof | Runbooks, monitoring ownership, escalation contacts, known limitations, open risks and acceptance record. | “Who can operate this after the vendor steps back?” | Closing procurement with no named internal owner. |