Ship — procurement with a spine
Build vs buy, vendors, and the POC trap
Ship like a delivery lead
Why this matters for a delivery manager
You have sat through vendor theatre. AI vendor theatre is denser: every pitch is a copilot, an agent, and a platform. Your job is to force a POC onto your eval set, your data class, and a clock — and to decide who owns the thing on day 91.
A free POC is not free. It consumes Security time, corpus-owner time, and your calendar, and it creates a constituency that will fight the death date. Write the death date in the SOW. Write the promotion path through Security. Write what you will never outsource: the golden set, the definition of success, the export of prompts and traces.
Build versus buy is not a personality. For a thin slice you buy the model API and maybe a gateway you already have. You build the evals, the prompt, the ingest rules, and the HITL. Turnkey RAG is a maybe, after it passes your golden set and your ACLs. A platform-for-everything deal belongs after two production slices, not before the first.
You will be able to
- Run a vendor conversation with the five questions from day 3, plus evals
- Write a POC charter that cannot become production by accident
- Spot lock-in, demo-ware, and 'platform for everything' pitches
- Choose build vs buy for the Atlas slice with a reason
2-hour clock
120:00
Now: Read the traps · 50m
The 2-hour session
Concepts, in full
This block is a slow read — about an hour with the diagrams. After each concept, write one sentence in notes (what you already do vs what is new) and tick annotated. Do not skim the last concept.
01
Buy vs build for a thin slice, not for a platform fantasy
You are buying outcomes on your eval, not a logo. The default for v1 is: buy the model API and maybe a gateway your company already approved. Build the evals, the prompt, the ingest rules, the HITL, the SLO sheet. That split keeps the IP you actually need when you change vendors, and it keeps you from a six-month platform stand-up before the first slice.
Buy a turnkey RAG or 'knowledge agent' only if it passes three tests: your ACLs, your export of prompts/evals/traces, and your golden set on your corpus (or a sanitized twin). If it fails any of the three, you are buying a demo. Demos are expensive in Security time. Passing a demo on the vendor's corpus is not one of the tests.
Build the thin slice in your own stack when you have engineers who can ship a retrieve-and-generate path in a few weeks, and when the vendor product would take longer to approve than to copy. This is common in companies that already have an enterprise model endpoint. The bottleneck is not the generator. The bottleneck is data-ready, evals, and change. Those are yours either way.
Do not build a platform. A platform is what you consider after two production slices have a pattern worth standardizing: same gateway, same eval harness, same logging shape. Starting with a platform is how a year passes and no user has a copilot. A delivery lead who delays the platform conversation is doing the company a favor. Say that in the recommendation. Someone has to.
People will argue this as identity — 'we are a build shop' or 'we are a buy shop.' Ignore identity. Write a table: what we buy, what we build, what we refuse to outsource, who owns day 91. Four rows. The argument becomes a document. Documents can be marked up. Identity cannot.
Cost at 10× belongs on the table. A vendor that looks cheap on twelve users and ruinous on one hundred and twenty is not cheap. Ask for the price at 10× volume, at 10× context, and at the next model tier. Put the numbers next to the 'we will grow this' slide they brought. If they will not quote 10×, they are selling a land-and-expand with the expand unpriced.
People will argue buy versus build as identity: we are a build shop, we are a buy shop. Ignore identity. Write four rows: what we buy, what we build, what we refuse to outsource, who owns day 91. The argument becomes a document. Documents can be marked up. Identity cannot. Your default for v1 stays boring: buy the model API and maybe a gateway already approved; build evals, prompt, ingest, HITL. That split is the IP you need when the vendor changes.
A turnkey knowledge agent that cannot export prompts, evals, and traces is a tenant you will be trapped in. Passing a demo on the vendor's corpus is not a test. The tests are your ACLs, your export, and your golden set on your corpus or a sanitized twin. Fail any of the three and you are buying a demo. Demos are expensive in Security time. Say no early. Early nos are cheaper than a SOW you unwind in quarter two.
Diagram
Buy vs build for the first slice
Buy
- Model API on an already-approved enterprise path
- Gateway / logging you already have
- Turnkey RAG only if ACL, export, and your golden set pass
- Vendor support hours that match your ops, in writing
Build
- Golden set, eval harness, release bar, waiver path
- Prompt versions and generator contract
- Ingest rules, ACL mapping, data-ready checklist
- HITL roster, incident page, SLO sheet, fallbacks
Do not do yet
- A company-wide 'AI platform' before two production slices
- Fine-tuning as the first move
- Agent frameworks with write-tools on day one
- Multi-year platform SOWs sold off a demo
Default: buy the model, build the eval and the path. Platform deals wait until you have a pattern.
02
The five questions, production edition
You asked five questions on day 3. Production adds teeth. One: what interface do we own — prompts, evals, traces, indexes — and can we export them. Two: cost at 10×, in writing, including the next model tier. Three: data path in writing — region, training clause, subprocessors, retention. Four: deprecation plan — notice period, successor, how long the pin lives. Five: eval on our tasks, our golden set, our ACLs, not their corpus.
Add the operational questions that decide whether you can live with them. SSO and VPC. Log export into your SIEM, not only their UI. Support hours that match your ops, with a named severity response. Status page. A pin you control, not a floating latest. If those answers are 'on the roadmap,' they are no for a production path. Roadmaps are not controls.
Ask who the subprocessors are, and watch how fast the list appears. A vendor who cannot produce the list in the POC window will not produce it in an incident. Day 15 already made this a data-handling item. Here it is a buy decision. Unknown subprocessors on confidential text is a no. You do not need Legal to invent that rule. You need Legal to confirm it.
Ask what happens on day 91 if you stop paying. Export of prompts, evals, traces, and the index. Deletion confirmation. Whether their UI is the only place the golden set lived. If the golden set lived only in their UI, you did not have a golden set. You had a tenant. Tenants die. Your set should not.
Run the questions as a scorecard, not as a conversation you will remember. Six to ten rows, the five questions plus SSO/VPC, log export, subprocessors, support hours. Score each vendor the same week, same corpus, same set. A narrative after two demos is how the better slide wins. A scorecard is how the better path wins.
You can ask these questions without being rude. Send them ahead of the demo. Vendors who refuse to run on your set, or who need a month to answer subprocessors, have told you something. Believe them. Delivery leads who skip the email because the meeting felt good will rewrite the email after the SOW, when it is worse.
Run the questions as a scorecard the same week, same corpus, same set. Six to ten rows: the five questions plus SSO/VPC, log export, subprocessors, support hours. A narrative after two demos is how the better slide wins. A scorecard is how the better path wins. Send the scorecard ahead of the meeting so the facilitator is not surprised when you ask to run your injection row live. Surprise is how you get a reschedule and a friendlier script.
Roadmap answers are no for a production path. 'SSO on the roadmap,' 'export coming soon,' 'VPC later this year' are not controls you can operate on day 91. You may still POC if the death date is real and the data is sanitized. You may not promote on a roadmap. Write that rule down so a sponsor who loved the UI does not promote from the hallway. Controls live in the present tense. Roadmaps live in sales.
| Question | What a pass looks like | Fail / demo-ware |
|---|---|---|
| Interface we own | Export of prompts, evals, traces, index in our hands | Lives only in their UI; API 'coming soon' |
| Cost at 10× | Quote at 10× volume, 10× context, next model tier | Land-and-expand unpriced; 'we will work with you' |
| Data path | Region, training clause, subprocessors, retention in writing | Cannot name subprocessors in the POC window |
| Deprecation | Notice period, successor, how long the pin lives | Sales engineer shrugs; floating latest |
| Eval on our tasks | Runs our golden rows, ACLs on, our corpus or sanitized twin | Will only demo on their corpus, facilitator present |
| Ops extras | SSO/VPC now, log export to our SIEM, support hours match ops | On the roadmap; status page missing |
Vendor scorecard. Same week, same corpus, same golden set. Roadmap answers score as no for production.
03
The POC that cannot accidentally productize
A POC without a death date becomes production by inertia. You have seen it on other tools. AI makes it faster because twelve users will build a habit in ten days and then fight you when you try to turn it off. Write the clock (ten working days), the users (twelve, named), the non-goals (no SSO to the whole company, no write-tools), the kill (the tenant dies on day 11 unless a named exec signs a production design with Security), the data (sanitized or a dedicated space), and the success bar (the eval bar, not 'people liked it').
Put the death date in the SOW and in the calendar with a meeting already booked: promote or kill. The meeting has a packet: eval on your set, data-handling note, cost at 10×, who owns day 91, Security conditions. If the packet is not ready, you kill. An incomplete packet is not a reason to extend. Extensions are how death dates die.
Named users, not 'the PMO.' Twelve humans you can write to when the tenant is going away. If the vendor wants a company-wide SSO for the POC, that is not a POC. That is a deployment. Refuse. A dedicated IdP group of twelve is a POC. Open enrolment is production with a smile.
Sanitized data or a dedicated space, not the real confidential corpus, unless Security has already signed the production path. POCs love to 'just connect Confluence' because it makes the demo sing. That connection is the data path from day 15, with copies, with subprocessors, with no handling note. You already know not to point a trial at production customer data. The wiki is production data. Treat it that way.
Success is the eval bar you brought. If the vendor's facilitator spends the two weeks collecting anecdotes, you will be asked to promote on anecdotes. Run your fifteen or forty rows on day two and on day ten. Compare. That table is the only success metric that matters. 'People liked it' can be a secondary note. It cannot be the gate.
Non-goals are what keep the POC from growing a write-path in week two because someone was excited. No tools that send. No HR spaces. No customer mail. Write them. When someone asks, you have a page. Excitement is not a change-control process.
Book the promote-or-kill meeting on day one, on the death date, with the packet listed in the invite: eval on your set, handling note, cost at 10×, day-91 owner, Security conditions. If the packet is not ready, you kill. An incomplete packet is not a reason to extend. Extensions are how death dates die. Put the death date in the SOW as well as the calendar. A calendar hold the vendor did not sign is a hope. A SOW clause is a lever.
Named users, not 'the PMO,' and no company-wide SSO for a POC. Twelve humans you can write to when the tenant is going away. Open enrolment is production with a smile. Sanitized data or a dedicated space unless Security has already signed the production path. 'Just connect Confluence' is the data path from day 15 with no handling note. You already know not to point a trial at production customer data. The wiki is production data. Treat it that way.
Diagram
POC path with a death date
Charter
Clock, named users, corpus class, non-goals, eval bar, death date, named exec to promote.
Stand-up
Dedicated space or sanitized data. No company-wide SSO. DPA or no confidential text.
Run the set
Your golden rows on day 2 and day 10. Scorecard the five questions plus ops.
Death date
Day 11: tenant dies unless the packet is signed — eval, handling note, 10× cost, Security, day-91 owner.
Promote or kill
Promote is a production design, not an extended POC. Kill means delete and confirm.
If the tenant can still answer questions on day 12 without a signed production design, you did not have a POC. You had a leak.
04
Demo-ware, lock-in, and subprocessors
Demo-ware shines on the vendor's corpus, with ACLs off, on a happy-path script, with a facilitator who already knows the answers. It fades on your corpus, your ACLs, your injection rows, and your empty-retrieve cases. Your job in the demo is to make it fade early if it is going to fade. Bring three of your golden rows, including a refuse and an injection. Ask to run them live. Polite vendors will. The others have told you it is demo-ware.
Lock-in is not 'we use a vendor.' Lock-in is 'we cannot leave without losing the evals, the prompts, the traces, and the ACL mapping.' Own those four and a model swap is a project. Do not own them and a model swap is a rewrite. Day 91 ownership is the test. Write it on the scorecard as a row: export of prompts, evals, traces, index. Yes or no. Not 'API coming soon.'
Subprocessors are a data fact and a concentration risk. If your 'enterprise' copilot sends text to three unknown companies for 'safety' and 'quality,' you have three extra DPAs to think about and three extra incident surfaces. Ask for the list. Ask whether you can opt out of any of them. Ask the region. Put the answers on the handling note. If Sales has to 'get back to you,' the clock on the POC does not pause in their favor.
Facilitated success is a variant of demo-ware. The vendor's engineer sits in the tenant for two weeks and hand-tunes prompts until your twelve users smile. Then they leave. Day 91 you own a tenant nobody on your side can tune. If the POC requires their engineer to be good, the production path requires a named FTE on your side or a paid services retainer you have actually budgeted. Unbudgeted vendor heroics are not a runbook.
Slideware architectures are not designs. A reference architecture can be useful as a starting diagram. A slide that says 'ingestion, orchestration, insights, agents' is a marketing layout. Ask them to draw your data path from day 15 on their product. If they cannot put copies, subprocessors, and log retention on it, they do not have an architecture for you. They have a deck.
You are allowed to say no to a well-known logo. Brand is not a control. Plenty of good logos fail ACL, fail export, or fail your set. Plenty of boring API-only paths pass. Your recommendation should be boring if boring passes. Hiring managers for this job are not looking for a vendor crush. They are looking for a spine.
Facilitated success is demo-ware with a badge. The vendor's engineer sits in the tenant for two weeks, hand-tunes prompts until your twelve users smile, then leaves. Day 91 you own a tenant nobody on your side can tune. If the POC requires their engineer to be good, production requires a named FTE on your side or a paid retainer you have budgeted. Unbudgeted vendor heroics are not a runbook. Score operability as a row. Fail it if they will not leave the tenant alone for three days.
Ask them to draw your data path from day 15 on their product: copies, subprocessors, log retention. If they cannot, they do not have an architecture for you. They have a deck that says ingestion, orchestration, insights, agents. Reference architectures are useful as a starting diagram. Reference slideware is not a design. Bring your diagram. Make them mark it. The marks are the beginning of a handling note, or the beginning of a no.
05
Who owns day 91
Day 91 is the first Monday after the services team leaves, or after the POC promotes, or after the internal engineers who 'helped stand it up' rotate. Who versions the prompt. Who runs the golden set. Who is on-call for the daily cap. Who talks to Security when a subprocessor is added. Who can kill it. If those names are vendor names, you rented a demo. If they are yours, you bought a path you can keep.
Write a RACI for the production path before you promote. You already know how. Prompt owner, eval owner, corpus owner, ops owner, vendor manager. The vendor can be consulted and can run their service. They should not be accountable for your release bar. Accountability that lives off-payroll is how you get a shrug during an incident.
Knowledge transfer is a deliverable, not a vibe. Admin how-to, pin location, log export, how to add a golden row, how to rotate a key, how to disable tools. A one-hour walkthrough that was not recorded is not transfer. Put the artifacts in your wiki. If the vendor's UI is the only documentation, you will be unable to operate on the day their UI is down or their contract is in dispute.
Funding on day 91 is part of ownership. Who pays the tokens, the seats, the extra logging, the HITL hours. A POC paid from an innovation budget that expires, with no run-rate owner, is a trap. Finance should be able to see the envelope and the 10×. If they cannot, do not promote. You will be back in six weeks with an unbudgeted bill and a user community that is now a political fact.
Exit is ownership too. A written export drill: actually export traces and prompts once during the POC. If you cannot, you do not own them. Finding that out on day 91 is late. Finding it out on day 8 is the point of a POC.
When you recommend buy versus build in practice today, the last sentences are about day 91. Not about the demo. Not about the logo. About names, hours, export, and the bill. That is the recommendation a finance partner can respect and a CIO can sign.
Write a RACI before you promote. Prompt owner, eval owner, corpus owner, ops owner, vendor manager. The vendor can be consulted and can run their service. They should not be accountable for your release bar. Accountability that lives off-payroll is how you get a shrug during an incident. Knowledge transfer is artifacts in your wiki: pin location, log export, how to add a golden row, how to disable tools. A one-hour walkthrough that was not recorded is not transfer.
Funding on day 91 is part of ownership. Who pays tokens, seats, extra logging, HITL hours. A POC paid from an innovation budget that expires, with no run-rate owner, is a trap. Finance should see the envelope and the 10× before promote. Exit is ownership too: actually export traces and prompts once during the POC. If you cannot, you do not own them. Finding that out on day 8 is the point of a POC. Finding it on day 91 is late.
06
Platform-for-everything and other ways to delay the first slice
A platform deal before a production thin slice is a delay with a steering committee. You will spend a year on connectors, identity, 'agent frameworks,' and a backlog of use cases that have no eval. Meanwhile a department will buy a point tool, or people will keep using consumer ChatGPT. The platform will arrive to a landscape that did not wait.
Two production slices give you a pattern: the gateway, the log shape, the eval harness, the HITL UI, the handling-note template. That pattern is the start of a platform. Until then, a platform is a guess. Delivery leads are often the only people in the room who can say this without sounding like they hate architecture. Say it. Sequence it. Offer the two slices as the path to the platform, not as a rebellion against it.
Multi-use-case POCs are a cousin of the platform delay. 'Let us try it on service desk, and wiki, and sales, and code.' You will learn nothing well. One slice, one set, one death date. If they want a second slice, it is a second POC with its own clock, or it is a production design for the first. Combining them is how both stay shallow.
Executive enthusiasm is a risk item. A CEO who saw a keynote will ask why you are not buying the platform now. Your scorecard and the Atlas slice are the answer. HIPPO is tomorrow's topic. Today: do not let enthusiasm collapse the death date. Enthusiasm is not a signature from Security and it is not an eval bar.
If you are forced into a platform evaluation in parallel, contain it. Named owner (not you, if you are running the slice), named questions (the five, plus integration with the slice), named date. It does not get to reopen the slice's vendor path every week. Parallel workstreams need a boundary. You know how to write one. Write it.
Your recommendation for Atlas v1 should be boring and dated. Buy the already-approved enterprise endpoint. Build evals, prompt, ingest, HITL. No turnkey agent. No company-wide platform SOW. Revisit platform after two slices or after a written pattern, whichever is later. That paragraph is what day 21's charter will rest on. Write it so you can paste it.
A platform deal before a production thin slice is a delay with a steering committee. You will spend a year on connectors and agent frameworks while a department buys a point tool and people keep using consumer ChatGPT. Two production slices give you a pattern worth standardizing. Until then a platform is a guess. Sequence the platform as something you earn, not as a prerequisite. Offer the two slices as the path to it, not as a rebellion against architecture.
Contain a forced parallel platform evaluation. Named owner (not you if you are running the slice), named questions, named date. It does not get to reopen the slice's vendor path every week. Multi-use-case POCs are a cousin of this delay: service desk and wiki and sales and code at once, nothing learned well. One slice, one set, one death date. If they want a second, it is a second clock or a production design for the first. Combining them keeps both shallow.
Worked case · stay here ~20 minutes
Day 11: the tenant dies, or you have a leaked production
Helix, a well-known knowledge-agent vendor, ran a 'free POC' against Atlas Confluence. Twelve named users became an open link. The death date is Monday. Helix wants company SSO and a six-month platform SOW. You have a packet, or you have a kill.
Tuesday after the ops sheet. Helix's customer-success lead wants thirty minutes. They have been in a tenant since last Wednesday on a handshake Marcus made at a conference. Twelve named users was the story. An open link is the fact: thirty-eight people have asked questions, including two who are not on Atlas. The facilitator, an engineer Helix flew in, has been hand-tuning prompts so the twelve smile. ACLs are off because 'it is just a POC.' They connected production Confluence, including Atlas-People, before Dana's unlesses. The death date you wrote in a side note — day 11, which is Monday — is not in a SOW, because there is no SOW, because it was free. Free consumed Sam's hours, Dana's queue, your calendar, and created a constituency that will fight the kill. You have sat through this theatre on other tools. AI makes the habit faster. Ten days is enough.
You write the POC charter that should have existed last Wednesday, and you write it as if Monday will execute it. Clock: ten working days, already nearly spent. Users: twelve, named, IdP group, not the PMO, not open enrolment. Corpus: dedicated space or sanitized twin, class internal, no Atlas-People, no company-wide Confluence. Non-goals: no SSO to the whole company, no write-tools, no customer mail, no HR. Kill: the tenant dies on day 11 unless a named exec — Marcus — signs a production design with Security. Success: your golden set, not people liked it. You book the promote-or-kill meeting on Monday in the invite now, packet listed: eval on your set, handling note, cost at 10×, day-91 owner, Security conditions. If the packet is not ready, you kill. An incomplete packet is not a reason to extend. Extensions are how death dates die. A calendar hold Helix did not sign is a hope. You send them a one-page SOW addendum this afternoon.
You run the five questions as a scorecard, same day, on their tenant, with ACLs on for the test even if they whine. Interface we own: can we export prompts, evals, traces, index. They show a UI. API coming soon. Fail. Cost at 10×: they will work with you. Unpriced land-and-expand. Fail. Data path: they cannot name subprocessors in the room; they will get back to you. Fail for production; for a sanitized POC maybe, not for Confluence. Deprecation: the sales engineer shrugs; they float latest. Fail. Eval on our tasks: they want to demo on their corpus with the facilitator present. You bring three golden rows including the injection PDF and the salary refuse. They reschedule. That reschedule is the tell. Ops extras: SSO on the roadmap, no SIEM export, support hours that do not match your ops. Roadmap answers are no for a production path. You may still finish a sanitized POC. You may not promote on a roadmap.
Demo-ware shines on their corpus, ACLs off, happy-path script, facilitator who knows the answers. It fades on your corpus, your ACLs, your injection rows, your empty retrieve. Your job is to make it fade early if it is going to fade. You already made it fade by asking to run the rows live. Facilitated success is demo-ware with a badge. If the POC requires their engineer to be good, production requires a named FTE on your side or a paid retainer you have budgeted. Unbudgeted vendor heroics are not a runbook. You score operability as a row: leave the tenant alone for three days. They will not. Fail. You ask them to draw your day-15 data path on their product: copies, subprocessors, log retention. They draw ingestion, orchestration, insights, agents. That is a deck. You bring your diagram. You make them mark it. The marks would be the start of a handling note. They cannot mark. That is the start of a no.
Lock-in is not we use a vendor. Lock-in is we cannot leave without losing evals, prompts, traces, and ACL mapping. Own those four and a model swap is a project. Do not own them and a model swap is a rewrite. You ask what happens on day 91 if you stop paying. Export. Deletion confirmation. Whether their UI is the only place the golden set lived. If the set lived only in their UI, you did not have a set. You had a tenant. Tenants die. Your set should not. You actually attempt an export during the remaining days. Finding out you cannot on day 8 is the point of a POC. Finding out on day 91 is late. Helix's export is a CSV of chat snippets with no chunk ids and no prompt versions. That is not ownership. You write it on the scorecard as a no, not as coming soon.
Buy versus build for the Atlas slice is not a personality. You write four rows. Buy: the already-approved enterprise model API, and the gateway you already have. Build: golden set, eval harness, prompt versions, ingest rules, ACL mapping, HITL roster, incident page, SLO sheet, fallbacks. Do not do yet: a company-wide AI platform, fine-tuning, agent frameworks with write-tools, a multi-year Helix SOW sold off a demo. People will argue we are a buy shop because Helix is a logo. Ignore identity. Documents can be marked up. Identity cannot. Cost at 10× belongs on the table even if they will not quote it: you model tokens at twelve users and at one hundred and twenty, at 10× context, at the next model tier. Helix looks cheap on twelve and ruinous on one hundred and twenty. They are selling land-and-expand with the expand unpriced. Turnkey RAG that fails ACL, export, or your set is a demo. Demos are expensive in Dana's time.
Who owns day 91 is the last test. Prompt versioning, eval runs, on-call for the daily cap, Security contact when a subprocessor is added, kill authority, funding, proven export. If those names are Helix names, you rented a demo. You write a RACI before anyone talks promote: you on eval and kill, Jordan on pin and path, Sam on corpus, Priya on HITL, Dana consulted, Helix consulted on their service and never accountable for your release bar. Accountability off-payroll is a shrug during an incident. Knowledge transfer is artifacts in your wiki, not a one-hour walkthrough that was not recorded. Funding: the POC was innovation budget that expires in June. There is no run-rate owner. Finance cannot see the envelope or the 10×. Do not promote. You will be back in six weeks with an unbudgeted bill and a user community that is now a political fact.
Marcus has a CEO who saw a keynote and asked why you are not buying the platform now. A platform deal before a production thin slice is a delay with a steering committee. You will spend a year on connectors and agent frameworks while a department buys a point tool and people keep using consumer ChatGPT. Two production slices give you a pattern worth standardizing. Until then a platform is a guess. You sequence it as something you earn. You offer Atlas Q&A, then a second slice, as the path to a platform, not as a rebellion against architecture. If you are forced into a parallel platform evaluation, you contain it: named owner not you, named questions, named date. It does not reopen the slice's vendor path every week. Multi-use-case POCs are a cousin of this delay. One slice, one set, one death date. Helix wanting wiki and service desk and sales in the same tenant is how both stay shallow.
Monday's meeting is promote or kill, not a vibe check. Packet: scorecard with five fails for production, handling note Helix never marked, golden rows they would not run, 10× model you built yourself, no day-91 owner, no run-rate, write path already a SEV, ACLs off, Atlas-People ingested. Kill. Delete the tenant. Get confirmation. Write the twelve — and the extra twenty-six — that access ends. Marcus can override in writing. If he does, he is funding a 2 despite the rubric, and you will still not connect production Confluence until Dana's unlesses are met on a production design, not on an extended POC. Promote is a production design. It is not a longer trial. You say no to a well-known logo without being rude. Brand is not a control. Plenty of good logos fail ACL, fail export, fail your set. Plenty of boring API-only paths pass. Your recommendation is boring because boring passes.
You write the recommendation Marcus can paste to finance. Atlas v1 buys the existing enterprise endpoint. Builds evals, prompt, ingest, HITL, SLOs. No turnkey agent. No company-wide platform SOW. Revisit platform after two slices or after a written pattern, whichever is later. Never outsource the golden set, the definition of success, or exportable prompt and eval versions. Helix may return when they can run your rows on your corpus with ACLs on, name subprocessors in the window, export traces into your SIEM, and quote 10×. Until then the official path must be easy enough that the unofficial path — personal ChatGPT on real pages — is not the only one that works. You will not catch all of that. You will make the approved path real. That is the same move you use for unlicensed software. A free POC that cannot die is the unofficial path with a logo on it.
You send Helix the addendum and the Monday invite the same hour, the way you sent Dana the note. What was agreed: sanitized space only from this afternoon, facilitator off the tenant for three days, export attempt on Thursday, death date Monday. What is still open: subprocessors, 10× quote, SIEM export. Who owns the open items: they do. You copy Dana so Security sees the tenant as a time-boxed exception, not as a new standard. You copy Finance so the innovation code is not a surprise later. You copy Priya so her thirty-eight users hear the clock from you, not from a 404. Named users you can write to when the tenant is going away. That is a POC. Open enrolment is production with a smile. You already knew not to point a trial at production customer data. The wiki is production data. You treated it late. You will not treat the next vendor late.
By Thursday the export has failed in the way you needed it to, the facilitator has not left, and the subprocessors list has not arrived. The scorecard does not get better by hoping through the weekend. You draft the kill note before Monday so you are not writing it angry in the room. Tenant dies. Confirmation requested in writing. Atlas v1 proceeds on the enterprise endpoint. Helix is welcome on the next scorecard when the rows pass. You attach the scorecard so HIPPO has to override a document, not a mood. Hiring managers for this job are not looking for a vendor crush. They are looking for a spine. The spine is a death date in a SOW, a packet that can fail, and a day-91 RACI that does not say the team. You have those now. You did not have them last Wednesday. That gap was the leak.
Diagram
Helix POC, with the death date you finally wrote down
Handshake
Conference yes. No SOW. Production Confluence, ACLs off, facilitator in the tenant.
Charter, late
Twelve named, sanitized space, non-goals, eval bar, Monday death date, packet listed in the invite.
Scorecard
Export, 10×, subprocessors, deprecation, your rows, SSO/SIEM. Five production fails.
Day 11
Packet not ready. Kill. Delete and confirm. Write the users. Do not extend.
Atlas v1
Buy the approved endpoint. Build evals, prompt, ingest, HITL. Platform later.
If the tenant still answers questions on day 12 without a signed production design, you did not have a POC. You had a leak.
Practice
A POC charter that dies on day 11
50 minutesA well-known vendor offered a 'free POC' of their knowledge agent on your Confluence.
- Clock, users, corpus, non-goals, eval bar, data class, death date, named exec to promote.
- Scorecard the vendor will be judged on (6 rows).
- Build vs buy recommendation for Atlas v1: 8–10 sentences, including what you will never outsource (evals, golden set).
Done looks like: A charter you could attach to a SOW and a recommendation you could defend to finance.
Check yourself
Attempt in your notes first. Reveal is for after, not during.
What is the difference between a POC and a leaked production?
What should you never outsource?
When is a platform deal premature?
What are the five production questions?
How do you detect demo-ware in the room?
What does 'who owns day 91' actually name?
Terms from this day
- POC charter
- The written clock, scope, success bar, and death date of a proof of concept.
- Exit / export
- Your ability to take prompts, evals, traces, and indexes with you when the vendor relationship ends.
- Demo-ware
- A product that shines on the vendor's corpus and ACLs-off tenants, and fades on yours.
- Subprocessor
- A vendor's vendor who may see data. Ask, in writing.
- Day 91
- The first stretch after the vendor or the stand-up crew leaves. Ownership is real or it is not.
- Death date
- The calendar day the POC tenant dies unless a named exec signs a production design.
Your notes for day 19
Saved on this device. Use this as the start of the artifact.