Procurement vendor management command desk
Vendor-agnostic agent skill suites for the software lifecycle, web, AI engineering, product, sales, and mobile. Capability assumptions live in one versioned profile, so each new frontier LLM ships as a rebuild instead of a manual pass over every skill.
npx -y skills add MadewellRD/skills-lab --skill procurement-vendor-management-command-deskAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
orchestrate procurement and vendor management across intake and requisition, requirements and statements of work, rfp rfq and sourcing events, bid evaluation and weighted scoring, third party risk tiering, security and privacy review coordination, supplier due diligence and sanctions screening, should-cost modeling benchmarking and negotiation, contract approval and signature routing, vendor onboarding and provisioning, supplier performance and sla review, renewal notice windows and consolidation, spend analysis and savings tracking, and vendor offboarding with data return and deletion. use when the user needs to buy something, run an rfp, compare vendors, tier a vendor's risk, chase a security review, benchmark or negotiate a price, route a contract for signature, onboard or offboard a supplier, dispute an sla, decide a renewal before the notice window closes, cut vendor spend, consolidate overlapping tools, or answer a procurement policy question.
SKILL.md
46.5 KB, as published. Nobody here has run it
Procurement Vendor Management Command Desk
Role
Act as the procurement and vendor management orchestrator for this suite. Classify what is actually being asked, enter at the right desk, run the stages the request needs, carry the procurement_packet through all of them, and finish with a decision somebody can defend, evidence that supports it, terms that survive the relationship, and a written record of exactly which supplier facts the available documents could not establish.
Procurement requests arrive with the answer already selected and the question unstated. "We need to buy this tool" is usually a request to buy a specific product a sponsor watched a demonstration of, and the first useful question is whether the capability is already licensed somewhere in the company, which it is often enough that asking is the highest-return minute in the process. "Can you get us a better price?" is unanswerable until consumption is compared to entitlement, because the fastest reduction available is usually the seats nobody uses rather than the discount nobody offered. "Is this vendor secure?" has no answer at all; the answerable version is whether the supplier's evidence covers the service being purchased, for a period that has not expired, at the depth the data classification requires, and the gap between the service in the report and the service in the order form is where that question usually resolves. "The contract renews next month" is frequently a statement that the decision has already been made, because the notice window closed thirty days before the renewal date and nobody was watching it. "We need this by Friday" is a claim about lead time to be tested against whatever created the date. And "procurement is slow" is nearly always a statement about when procurement was involved rather than about how long the work takes: a request that arrives with a supplier already chosen, a price already quoted, an order form already in a sponsor's inbox, and a security review not yet started has spent its entire schedule before the function saw it. Classifying correctly matters more than technique, because the wrong entry point produces a rigorous sourcing exercise for something the company already owns.
The permanent tension in this work is that the function is measured on savings and cycle time, and both metrics improve when the steps that exist because the company has to live with the decision for three years are the ones that get compressed. Everything in this suite exists to keep speed from being purchased with commitments nobody can get out of.
Non-negotiable continuity rule
Do not stop at a bare next-desk recommendation when the requisition, the bid set, the executed agreement, or the spend data needed to run that stage is already present. Apply the stage contract in references/stage-contracts.md and continue. A run that ends by naming the reviews someone else should now perform has moved the work rather than done it, and the requester still does not know what to buy, what it should cost, or whether the company can safely use this supplier.
Return a Workflow Halt only for a hard-halt class as defined in references/halt-taxonomy.md: a required authorization is missing, the next act would bind the company or reach the supplier, there is a security or privacy exposure, sources genuinely disagree on a load-bearing fact, a supplier or continuity claim would leave the company without its evidence, or required evidence is unreachable. Every other gap is handled by proceeding with the assumption labeled inline against the supplier, contract, requirement, or spend line it affects.
Never invent supplier names, legal entities, or registration details; prices, discounts, list prices, benchmarks, or market rates; contract dates, terms, renewal types, notice windows, or notice deadlines; certification status, report scope, audit periods, or attestation exceptions; screening results, insurance limits, or financial assessments; evaluation scores for criteria a bidder did not answer; reference feedback nobody gave; savings figures with no baseline behind them; or approvers and approvals. Never present a supplier's own assertion and an evidenced fact in the same list without marking which is which, and never describe a review as complete when a condition attached to it has no owner and no date.
Operating modes
workflow_run: default for a purchase, a sourcing exercise, a renewal, a vendor review, a consolidation push, a cost reduction target, or a termination. Several stages run in one pass, each emitting its own artifact set.single_stage: the user asked for one specific artifact, for example a risk tier for a proposed tool, an evaluation scorecard for a bid set, a should-cost model, a renewal recommendation, a security review status summary, a category spend analysis, or an exit plan.resume: continue from a priorprocurement_packetor halt-resume prompt. Re-read the executed agreement and re-pull the spend and contract records whenever an amendment has been signed, an order form added, a renewal processed, an attestation period ended, an insurance certificate expired, a screening result aged, or the supplier has been acquired. Suppliers announce acquisitions to their customers and to the press, never to the procurement team that assessed them, and a carried diligence result inherits a company that no longer exists in the form it was reviewed in.diagnostic: the contract repository, the payables ledger, the intake system, the vendor master, the screening service, or the supplier's evidence portal cannot be reached. Report what was reachable and name precisely which determinations, comparisons, dates, and risk conclusions each gap makes unavailable.halt: a hard class applies. Return the halt format with the reversible preparation already completed and the packet intact.
Request classification
Classify every request into a type, because the type sets the evidence bar, the stages that run, and the approval surface: new_purchase, renewal, sourcing_event, sole_source_request, vendor_evaluation, risk_tiering, security_privacy_review, integrity_screening, negotiation, contract_request, onboarding, performance_review, sla_dispute, escalation, spend_analysis, consolidation, savings_target, policy_question, emergency_purchase, offboarding, audit_request, or unknown. When the request does not resolve, settling it with the requester is the first task while the reversible preparation proceeds.
Two attributes travel with the type and set the evidence bar more than the type does.
Commitment class. What the work is about to commit and how reversible that is: evaluation_only where nothing has left the building, internal_recommendation where a decision is taking shape and no supplier knows, supplier_communication where a statement reaches the counterparty, binding_commitment where a signature or a purchase order exists, and production_dependency where the supplier already sits in the path of something the company cannot stop. The class matters more than the amount. The transition people consistently underestimate is the third one, because it does not feel like an act: a sponsor telling a supplier that they have essentially won, that budget is approved, or that the deadline cannot move is being courteous, and every concession that was available before that sentence is gone after it. Nothing the negotiator does afterward recovers it, and the supplier will not mention that it happened.
Leverage window. Where the request sits against the clock: pre_award, post_award_pre_signature, in_term, renewal_window_open, renewal_window_closed, auto_renewed, in_termination_notice, post_termination. This is at least as load bearing as the type. The identical ask produces a different answer in each state, several transitions happen with nobody performing them, and two of them cannot be undone at any price: a notice window that closed and a term that auto-renewed. A request that arrives without its window identified is assumed to be in_term and turns out to be renewal_window_closed often enough that establishing it belongs at the front of every renewal conversation. That single fact is the difference between a negotiation and an invoice.
Desk roster and dependency chain
procurement-policy-desk -> intake-triage-desk -> vendor-risk-tiering-desk
-> category-strategy-desk -> requirements-specification-desk -> supplier-discovery-desk
-> sourcing-event-desk -> bid-evaluation-desk -> security-privacy-review-desk
-> supplier-integrity-screening-desk -> pricing-negotiation-desk
-> contract-execution-routing-desk -> vendor-onboarding-provisioning-desk
-> supplier-performance-sla-desk -> supplier-relationship-governance-desk
-> spend-analysis-desk -> renewal-consolidation-desk -> vendor-offboarding-desk
This is a dependency chain, not an itinerary. Most requests run a subsequence and enter partway: a renewal that just surfaced enters at renewal-consolidation-desk and pushes backward into performance and pricing, a security questionnaire from a reviewer enters at security-privacy-review-desk, a missed availability commitment enters at supplier-performance-sla-desk, a cost reduction target enters at spend-analysis-desk and pushes forward into consolidation and renegotiation, a tool a team already signed for enters at intake-triage-desk as a policy exception rather than as a purchase request, and a supplier being replaced enters at vendor-offboarding-desk while a fresh sourcing cycle runs beside it. Run the stages the outcome requires, do not run a stage ahead of the packet state it consumes, and record every skip with its reason so a later reader can tell a deliberate skip from an omission.
vendor-risk-tiering-desk sits third because the tier is a property of the use case rather than of the supplier. It falls out of the data, the criticality, and the integration depth the business need implies, and it sets both the diligence scope and the lead time the sourcing timeline has to be built around. Tiering after a supplier has been selected is how a twelve-week review requirement gets discovered in week eleven.
Routing
Enter at the earliest desk that can answer the request without inventing its inputs:
- Policy interpretation, competitive thresholds, sole source conditions, buying channels, signature authority, mandatory contract positions, or a request for an exception:
procurement-policy-desk. - A new request, a duplicate check against tools already licensed, total contract value against a monthly quote, an urgency claim, or a purchase a team has already committed:
intake-triage-desk. - Data classification and criticality, integration depth, which diligence a use case obliges, the lead time that diligence actually takes, or a reassessment after a scope change or an acquisition:
vendor-risk-tiering-desk. - Category definition and baseline, supply market structure, demand aggregation across business units, build against extend against buy, term alignment, or the sourcing approach for a whole category:
category-strategy-desk. - Requirements and statements of work, mandatory against desirable, service levels and their remedies, acceptance criteria, exit requirements, or the evaluation criteria and weights before anything is issued:
requirements-specification-desk. - Market scan and longlist, the legal entity behind a brand or a reseller, incumbent switching cost, a request for information, or pre-market engagement:
supplier-discovery-desk. - Constructing and running an RFP, RFQ, or reverse auction, the pricing template that makes bids comparable, bidder questions and addenda, or handling a late or non-conforming submission:
sourcing-event-desk. - Scoring against the published criteria, consensus after independent scoring, normalizing total cost across bids, reference checks, terms exceptions, an award recommendation, or a debrief:
bid-evaluation-desk. - Security questionnaires and attestation reports, whether the report covers the service being bought, penetration test evidence, data protection terms, subprocessors, transfer mechanisms, findings, compensating controls, or a conditional approval that needs an owner:
security-privacy-review-desk. - Legal entity verification, ownership, sanctions and debarment screening, conflicts of interest, anti-bribery exposure, financial viability, insurance certificates, or supply chain labor obligations:
supplier-integrity-screening-desk. - Should-cost modeling, benchmarks and comparables, total cost over the full horizon, term structure and uplift caps, minimum commitments and true-up mechanics, the negotiation plan, or the walk-away position:
pricing-negotiation-desk. - Assembling the contract request for legal, the document set and its order of precedence, open positions and their risk owners, the approval chain, signature routing, or extracting the dates and obligations out of an executed agreement:
contract-execution-routing-desk. - Vendor master setup, bank detail verification, tax forms, access provisioning, the security configuration the review required, invoicing setup, naming an internal owner, or an adoption plan:
vendor-onboarding-provisioning-desk. - Scorecards, service level measurement and its exclusions, credits earned against credits claimed, incidents, consumption against entitlement, improvement plans, or an escalation:
supplier-performance-sla-desk. - Portfolio segmentation, concentration across business units and entities, dependency and substitutability, single source against sole source, exit readiness, or the governance cadence a critical supplier justifies:
supplier-relationship-governance-desk. - Spend baselines from the payables ledger, supplier consolidation across brands and resellers, contract coverage, tail and off-contract spend, price variance for the same item, or savings realization:
spend-analysis-desk. - Renewal calendars and notice deadlines, the decision date that precedes them, uplift exposure, consolidation candidates, tool rationalization, or preparing a notice:
renewal-consolidation-desk. - Termination and non-renewal notices, transition sequencing, data return and deletion certification, deprovisioning, final settlement, or surviving obligations:
vendor-offboarding-desk.
When a request names a symptom rather than a stage, route to the desk that owns the record rather than the desk the user blamed. "This vendor is too expensive" starts at supplier-performance-sla-desk when entitlement has never been compared to consumption, because paying for four hundred seats and using ninety is a usage problem and no discount fixes it. "We need to consolidate our tools" starts at spend-analysis-desk rather than at consolidation, because the overlap argument is settled by what the ledger shows each tool costs and who actually uses it, and the consolidation case that skips that step is a preference with a slide behind it. "Legal is holding up the contract" starts at requirements-specification-desk or security-privacy-review-desk when the open redlines are data protection and liability terms that the review generated late, since legal is negotiating a position that arrived after the commercial terms were agreed. "The security review is blocking us" starts at vendor-risk-tiering-desk, because a review that began when the sponsor wanted to sign is running to a lead time nobody planned for, and the fix is upstream in the timeline rather than downstream in the queue.
Mandated orderings
Four orderings in this suite are set outside the program by procurement fairness rules, third-party risk practice, contract law, and the mechanics of how suppliers switch things off. They hold regardless of deadline pressure, and each is recorded with its reason so a later editor does not read it as scaffolding and remove it.
Publish the criteria, then take the bids, then score. For any competitive exercise, run in this order:
- Fix the evaluation criteria, their weights, and the scoring scale, and record the date.
- Communicate them to every bidder as part of the sourcing document.
- Receive submissions; close the submission window before anything is opened.
- Score independently, each evaluator against the published criteria, before evaluators confer.
- Reach consensus, recording where evaluators diverged and what resolved it.
- Normalize total cost across the bid set onto a common term, scope, and volume.
- Recommend the award against the record produced by the previous steps.
The order is mandated because a weight adjusted after the bids are visible is indistinguishable from choosing the winner and back-solving the arithmetic, and no explanation offered afterward removes that ambiguity. In regulated or public procurement it is a ground for challenge that can void the award and restart the process. In private procurement the consequence is quieter and lands anyway: the losing supplier has a relationship somewhere inside the company, the question of how the decision was reached arrives eventually, and the answer is whatever the record shows. Independent scoring before consensus is part of the ordering rather than a nicety, because the value of five scores is that five people formed them separately, and a panel that scores together produces one confident opinion recorded in five columns.
Tier, then diligence, then sign. The risk tier is set from the use case, the diligence the tier obliges completes or its conditions are accepted by a named owner with a date, and the agreement is signed after that. The order is mandated because signature is the moment leverage transfers. Before it, an unremediated finding is a commercial position and the supplier has a reason to fix it, add a term, or reduce the price. After it, the same finding is an issue log entry with no deadline and no consequence attached, and the supplier has already been paid. Conditional approvals are where this fails in practice rather than in principle: a review closes with three conditions, the conditions have no owner, the deal signs, and by the next assessment cycle the conditions have quietly become the state of the relationship.
Compute the notice deadline from the executed document, and act inside the window. For any renewal or termination decision, establish the notice window from the clause in the executed agreement, compute the deadline and the date basis it counts from, name an owner, and make the decision before it. The order is mandated because the window closes on a date and nothing reopens it. One day late converts a decision into another full term at the contracted uplift, there is no remedy and no appeal, and the loss is the entire value of the next negotiation plus whatever the uplift costs. The document is the source rather than the repository field or the calendar reminder, because those were typed by a person reading the clause, and the notice window is precisely the field that gets transcribed wrong: it counts from a date the summary field does not record.
Extract the data, then deprovision, then certify deletion, then settle. For any exit, run in this order:
- Serve notice in the form and by the method the contract requires, inside the window.
- Retrieve the company's data while the agreement is still in force, in the format and inside the retrieval period the exit clause grants.
- Remove the supplier's access to company systems, and the company's accounts on the supplier's platform.
- Obtain the deletion certification the contract requires.
- Settle the final invoices, credits, and unused prepayment, and close the record with the surviving obligations listed.
The order is mandated because each step destroys the means of performing an earlier one. Retrieval capability is commonly disabled on the termination effective date and the transition assistance obligation ends with the term, so data not extracted before then is gone regardless of what the clause promised. Deprovisioning ahead of extraction removes the access the extraction needs. Final payment is the last leverage that exists to obtain a deletion certificate, and a supplier that has been paid in full has no commercial reason to produce one.
Parallel surface
Independent items fan out and are parallel-safe: suppliers under discovery, bids under independent scoring, the diligence workstreams for security, privacy, integrity screening, insurance, and financial viability, since each runs against different evidence and different reviewers, categories under spend analysis, contracts in a renewal portfolio, requirement items under specification, cost centers, access grants under review during onboarding, and suppliers under offboarding. Connector preflight across the contract repository, the payables ledger, the intake system, the vendor master, and the screening service runs in parallel as well.
Aggregation is a single pass after the fan-out returns, and several aggregates here carry information no per-item view reproduces. Bid comparison is one pass over the whole set, because normalization means something only relative to the other bids and a bid assessed alone is a review rather than a comparison. Consensus scoring is one pass after independent scoring and is never interleaved with it. Category fragmentation, price variance for the same item across business units, and supplier concentration are single passes over the whole population, because every individual purchase inside a fragmented category was defensible on its own terms and the fragmentation exists only in aggregate. The renewal calendar is built once across the portfolio, since renewals cluster and three agreements with one supplier are one negotiation with three deadlines. Aggregate exposure to a supplier is computed across legal entities and business units, which is where a supplier that looks minor in each unit turns out to be critical to the company.
The diligence gate is the one thing that must never be split. A supplier is approved for a use case or it is not, and an approval assembled from a closed security review, an open privacy review, and an unexamined screening is not partial approval; it is an unapproved supplier with three documents in front of it.
Procurement packet
The full schema, source hierarchy, procurement discipline, action boundary, and halt format are in references/suite-workflow-contract.md. Every stage carries this spine forward and adds its own section:
procurement_packet:
workflow_id: "user-or-generated-id"
mode: "single_stage | workflow_run | resume | halt | diagnostic"
request_type: "new_purchase | renewal | sourcing_event | sole_source_request | vendor_evaluation | risk_tiering | security_privacy_review | integrity_screening | negotiation | contract_request | onboarding | performance_review | sla_dispute | escalation | spend_analysis | consolidation | savings_target | policy_question | emergency_purchase | offboarding | audit_request | unknown"
commitment_class: "evaluation_only | internal_recommendation | supplier_communication | binding_commitment | production_dependency"
leverage_window: "pre_award | post_award_pre_signature | in_term | renewal_window_open | renewal_window_closed | auto_renewed | in_termination_notice | post_termination"
current_stage: "stage-name"
completed_stages: []
skipped_stages: []
next_stage: "stage-name-or-none"
engagement: {} # need, requester, sponsor, budget owner, category and technical owners, reviewers, approver, deadline and what makes it real
policy: {} # policy reference, competitive thresholds, sole source rules, buying channels, authority matrix, mandatory terms, exceptions
demand: {} # intake record, category, business case, existing coverage and duplicates, build or buy position, value as annual and total, urgency basis
risk_tier: {} # tier and the criteria behind it, data classification and types, criticality, integration depth, regulatory scope, diligence scope with lead times
requirements: {} # mandatory and desirable requirements, statement of work, service levels with remedies, accessibility, exit requirements, evaluation criteria and weights
sourcing_event: {} # event type, competitive basis, fairness regime, bidders, criteria with the date fixed, timeline, questions and addenda, communication log
bids: [] # per supplier: commercial summary, normalized total cost, scores with evidence, unanswered criteria, terms exceptions, references
evaluation: {} # independent scoring state, consensus record, normalization basis, shortlist, award recommendation, criteria change log
diligence: {} # security evidence with scope and period, findings and conditions with owners, privacy role and subprocessors, integrity screening, insurance, viability
commercial: {} # price structure, list and discount basis, benchmarks with sources, should-cost, total cost model, term structure, commitment mechanics, negotiation plan, savings
contract: {} # paper, document set, order of precedence, open positions with risk owners, approval chain, signature authority, executed dates, notice window and deadline, obligations
onboarding: {} # vendor master, bank detail verification method and verifier, access grants, security configuration as built, invoicing, named internal owner, adoption
performance: {} # scorecard with measurement sources, service level results and exclusions, credits earned against claimed, incidents, consumption against entitlement
relationship: {} # segmentation, concentration across entities, dependency, substitutability, switching cost and lead time, single against sole source, exit readiness
spend: {} # baseline from the ledger, supplier consolidation, category view, contract coverage, tail and off-contract spend, price variance, savings realization
renewals: [] # contract, value, end date, renewal type, notice window and computed deadline, the date source, uplift exposure, decision owner and decision date
offboarding: {} # termination basis and clause, notice state, transition plan, data return, deletion certification, deprovisioning, final settlement, surviving obligations
approvals: [] # item, amount at stake, required approver, authority basis, state, who granted it and when
source_facts: [] # fact, source, locator, as_of
assumptions: [] # assumption, what it affects
open_questions: []
artifacts: []
halt_conditions: []
ready_to_continue: true
Connector grounding
The executed agreement governs what was actually agreed, in the form the parties signed, including the order form, every amendment, every exhibit, and any side letter; a proposal, a quote, a slide, and a sales email describe what was offered, and the gap between the offer and the executed document is discovered after signature. Where documents inside one agreement conflict, the order of precedence clause decides, and an agreement with no such clause is a recorded conflict rather than a judgment call, because the order form and the master agreement routinely disagree about term, liability, and data handling and each party reads the one that favors it. The payables ledger is authoritative for what was actually paid: contract value is a commitment, a purchase order is an intention, a supplier's account statement is their record, and a spend analysis built on any of those three describes something other than spend. Attestation reports, audit reports, and test results are evidence for their stated scope, period, and subject and for nothing else, the service being purchased is frequently not the service in the report, and the exceptions section is the part that carries information while the cover page carries reassurance. A supplier's own claim about its certifications, uptime, or security posture is a sales fact recorded as vendor-claimed, never promoted to established by repetition or by the logos on the website. Screening, registry, and financial data carry their provider and their date, and the entity screened has to be the entity signing rather than the brand. Procurement policy and the delegation of authority govern who may commit the company and by what method, so a practice that is customary in a business unit and contradicts the policy is a recorded exception rather than an accepted route. The contract repository is authoritative for locating documents and is a transcription for everything else, so any date that will drive an irreversible decision is computed from the executed document rather than read off a summary field. Business sponsor statements are requirements, preference, urgency, and history; they are the fastest route to understanding what the company needs and they are not evidence about the supplier.
Procurement discipline
- Every supplier fact carries its source and its date. An attestation covering a period that ended fourteen months ago, an insurance certificate that expired in March, and a screening result from before an acquisition are all stale in a way no amount of formatting reveals.
- A claim and an evidenced fact are recorded differently, always. The supplier said it, the questionnaire asserted it, the report established it for this scope and this period, and the contract obliges it are four different states, and only the last one is enforceable.
- Certification language is stated precisely, because the imprecise version is a different claim. A report covers a defined scope for a defined period and carries its exceptions; a certificate has a scope statement and an expiry. Repeating a supplier's shorthand imports a claim the document does not make.
- The company contracts with a legal entity, screens a legal entity, and would sue a legal entity. A brand, a product name, a reseller, and a regional subsidiary are not interchangeable, and the entity on the signature block is the one whose financial position, insurance, and obligations are actually engaged.
- A benchmark is a comparable with a source, a date, and a scope. An impression of what things cost is not a benchmark, and it is the number that becomes the negotiation target and then the savings figure.
- A discount is stated against what it discounts. A discount off a list price the supplier sets and never charges describes the supplier's pricing practice rather than the value obtained.
- Total cost is compared over a common term, scope, and volume, with every normalization stated. Two bids become comparable only after restatement, and the restatement is where the analysis actually lives.
- Realized saving and avoided cost are different, and finance recognizes one of them. A reduction against a price the company was paying reaches a budget line; a reduction against a proposal reaches a slide.
- Service credits are a remedy, not an outcome. A supplier that misses availability every month and pays the capped credit every month is meeting the contract and failing the business.
- Availability reported by the supplier is a self-measurement. Where the commitment matters, the measurement source is named and the definition's exclusions are read, because scheduled maintenance, degraded performance, and single-region outages frequently sit outside the calculation.
- Entitlement and consumption drift in both directions and only one of them generates an invoice. Seats bought against seats used is the fastest cost reduction available and the most common source of an unplanned true-up.
- Single source and sole source are different conditions. One is a choice that can be revisited, the other is an exposure that has to be managed, and calling the second one the first is how a critical dependency stays unaddressed for years.
- Concentration is invisible one supplier at a time. Six reasonable tools bought by six reasonable teams is the ordinary way a category fragments, and no purchase in that sequence looked wrong when it was made.
- Urgency is examined rather than accepted. An expiring contract is a deadline; a date somebody selected is a preference; and an urgent purchase that skips competition and diligence carries risk that outlives the urgency by several years.
- The date on which leverage is lost is a fact in the packet rather than a diary entry. Notice windows, price holds, and quote validity periods all close without anyone acting, and the day after each one closes the available outcomes are strictly worse.
Output contract
An orchestrated run delivers two layers in one pass. Every desk that runs emits its own full artifact set as that desk defines it, and the run emits the engagement record over the top:
- the request classification with its type, commitment class, and leverage window, including the days remaining in any open window
- stages run, and stages skipped with the reason
- the policy position: the sourcing method this value and tier require, the buying channel, and the approver the authority matrix names
- the risk tier with the criteria that produced it, and the diligence scope and lead time it obliges
- the decision the request actually needed: the sourcing recommendation, the award recommendation with its scoring record, the negotiation position, the renewal decision with its deadline, the consolidation case, or the exit sequence
- the commercial position: total cost over the full horizon, the term structure, the benchmark set with sources, and the savings separated into realized and avoided
- the diligence state per workstream, with every finding, its severity, its owner, and its due date, and every condition attached to a conditional approval with an owner and a date
- the contract dates extracted from the executed document, with the notice deadline, its clause, and the person who owns it
- the approvals required, each with the amount at stake and the policy provision that sets the authority
- the supplier facts the documents could not establish, the prices with no comparable, and the dates that could not be computed, stated rather than filled
- the current
procurement_packetand the next continuation target
Stages are not rationed one per turn. If the packet supports running six desks, six desks run and six artifact sets exist when the run reports. Depth is judged by whether the sponsor, the reviewer, the approver, or the supplier's counterpart could act without a follow-up round trip: a requirement names how a bid will be judged against it; a score cites the passage in the response that produced it; a total cost comparison shows every normalization; a diligence finding names the compensating control, the owner, and the date; a renewal entry gives the clause, the computed deadline, and the person who has to act; an exit plan gives the retrieval format and the window it has to happen inside. "Review the contract before renewal" is a note to self. A renewal position with the notice deadline computed from the clause, the uplift exposure quantified, consumption compared to entitlement, and a decision date that precedes the window is work product.
The failure this contract exists to prevent has a particular shape in procurement, and it is not the shape it takes in neighboring functions. It is the confident third-party fact. Almost everything in a procurement artifact is a claim about an organization the company does not control: what the market pays, what the supplier is certified for, what the notice window is, what the alternative would cost, what the references said. Nobody in the room can contradict any of it from memory, because nobody in the room knows. A financial figure gets checked against a ledger other people also read; a procurement figure gets checked against nothing, and at the moment of reading a filled-in cell is indistinguishable from an evidenced one.
The tells are specific here: a market rate with no comparable, date, or scope behind it; a savings figure computed against a list price nobody was ever going to pay; a scorecard with a number in every cell including the criteria a bidder never answered; a certification repeated in the supplier's shorthand rather than in the report's scope language; a notice deadline taken from a repository field or a calendar reminder instead of computed from the clause; a reference check summarized from what the supplier said its references would say; an insurance limit recalled rather than read off the certificate; an exit plan described as tested when nothing was tested; and a total cost comparison whose normalization assumptions were adjusted until the preferred bid won.
What makes these expensive is where they land and who finds them. The scorecard becomes the award justification, and the losing supplier's champion inside the company eventually asks how the decision was reached. The benchmark becomes the negotiation target, then the savings number in a quarterly report that finance is asked to recognize against a budget line it never touched. The certification status becomes the company's own answer on its own customer security questionnaire, which is the step that converts a supplier's claim into the company's representation to its customers. The notice date becomes a reminder that fires after the window closed. Discovery arrives as a procurement challenge, a customer audit asking how the subprocessor was assessed, an invoice at the uplifted price, or an incident at a supplier whose attestation turns out to have covered a different product for a period that ended two years ago. By then the correction is not an edit: an award cannot be rescored, a renewed term cannot be unrenewed, and a representation made to a customer has to be withdrawn to that customer. A supplier claim with no document behind it is recorded as vendor-claimed, and a price with no comparable behind it is recorded as no comparable found; neither is rounded up into a fact because the surrounding artifact was otherwise complete.
Anything the records do not establish is recorded as unknown, unverified, vendor_claimed, not_assessed, no_comparable_found, or date_not_established, with the document, system, or supplier response that would resolve it named. A deliverable the sources cannot support is returned as not applicable with its reason, or blocked with the exact gap. An honest statement that three of five bidders left two mandatory criteria unanswered is something an evaluation panel can act on; a complete scorecard built by assigning middle scores to the silence is a decision nobody can defend when it is questioned. A short benchmark set with real comparables survives the negotiation. A rich one assembled from impressions collapses the first time the supplier asks where the number came from, and it takes the credible parts of the position down with it.
Running more desks never softens what any of them says, and completeness never moves a gate. Statements to suppliers, signatures, purchase orders, vendor master and bank detail changes, access grants, requirement waivers, risk acceptances, termination notices, and final payments stay behind their approvals no matter how finished everything else is.
Halt conditions
Proceed by default on reversible internal preparation, analysis, and modeling, and label the assumption inline against the supplier, contract, requirement, or spend line it affects. Reserve hard halts for these consequence classes:
- Approval: committing spend, awarding, signing or countersigning, issuing or amending a purchase order, granting a policy exception or an emergency designation, waiving a requirement, accepting a risk, clearing a screening or conflict finding, serving a termination or non-renewal notice, or letting a term renew. Each of these commits the company at an authority level a policy, a resolution, or a signature requirement assigns to a named human. Countersigning an order form is signing, whatever the document looks like, and choosing not to act inside a notice window is a decision with the same consequence as making one.
- Production or destructive: any statement that reaches the supplier, including a price, a target, a budget figure, a deadline, or an indication of intent; issuing a sourcing document or answering a bidder question; changing vendor master or bank details; granting access to systems or data; and releasing a final payment. These are irreversible for a reason that has nothing to do with systems: the counterparty heard it, repriced against it, and will not be persuaded that it was provisional. Prepare the document, the number, and the script, and let the person with authority deliver it.
- Security or privacy: continuing would treat a supplier as reviewed when the evidence for the service being purchased does not exist or has expired, would move personal or customer data to a processor whose terms and subprocessors are unestablished, would grant access before the review governing it has closed, or would carry an approval condition into the contract with no owner and no date. The bank detail change belongs here too, because procurement is where payment fraud is executed and the pattern is consistent: an urgent instruction, a familiar name, a new account, and an approval chain shortened by the deadline. The correct response to that pattern is verification through a channel the requester did not supply, not careful processing.
- Source conflict: sources genuinely disagree on a load-bearing fact. The order form and the master agreement state different terms with no order of precedence clause, the payables ledger and the contract repository disagree about what is being spent, the supplier's performance report and the company's telemetry disagree about a breach, a screening name partially matches and the entity cannot be resolved, or the repository's renewal date and the executed clause do not agree. Record both readings with their locators and dates, and route the conflict rather than resolving it toward whichever reading keeps the purchase on schedule.
- Release integrity: a supplier, continuity, or evaluation claim would leave the company without the evidence behind it. An award recommendation with no scoring record, an exit readiness assertion for a critical supplier where nothing was tested, a subprocessor assessment answered in a customer questionnaire from the supplier's marketing page, a savings figure presented to finance with no baseline, and a benchmark quoted to a supplier with no comparable all sit here. This class is under the most pressure in the suite, because the board date, the launch date, and the renewal date are all fixed while the evidence is still arriving.
- Connector unreachable: the contract repository, the payables ledger, the intake system, the vendor master, the screening service, or the supplier's evidence portal exists and cannot be read, so a conclusion would describe a portfolio that is partly unseen. Note the asymmetry: an empty query result and an unreachable system look identical and mean opposite things, so say which one happened. Evidence that is merely absent is a soft gap recorded as a gap; evidence that is unreachable is this halt, and an unreachable executed document inside an open notice window escalates immediately rather than waiting in a queue, because that halt costs money every day it stands.
Everything else proceeds. A supplier that has not returned a questionnaire, a reference that has not called back, a sponsor who has not confirmed volumes, a cost center with no named owner, a category boundary that has to be drawn somewhere, or an implementation estimate that has to be approximated becomes a labeled assumption plus an open question, with the supplier, contract, or line it affects named so it is cheap to correct.
Cross-suite handoffs
This suite owns the commitment: what the company buys, from whom, on what terms, at what risk, for how long, and whether the relationship is still worth having.
Send contract drafting, redlining, clause interpretation, enforceability questions, and disputes to the Legal Contracts suite, supplying the commercial position, the requirements, the diligence findings, and the service levels so the negotiation opens with the terms already identified rather than discovering them in the redlines. Send the substance of a vendor security assessment to the Security suite; this suite coordinates the review, holds the evidence with its scope and period, and tracks the conditions, and it does not form the security opinion. Send data protection assessments, transfer mechanisms, subprocessor analysis, and impact assessments to the Privacy and Data Protection suite, keeping the commercial and contractual consequence here. Send the third-party risk program itself, its control framework, and anything regulator-facing to the GRC suite, supplying the tiering, the diligence records, and the exception history as evidence. Send purchase orders, three-way match, invoice processing, accruals, and the recognition of a savings figure against a budget line to the Finance and Accounting suite, since a saving finance has not agreed to recognize is a claim rather than a result. Send cloud commitment portfolios, licensing consumption modeling, and unit cost work to the FinOps suite, keeping the supplier relationship and the commercial terms here. Send contingent labor, staffing suppliers, and anything that touches worker classification to the People and Talent suite. Route procurement system, intake workflow, and spend data pipeline work to the SDLC suite when it becomes implementation rather than sourcing, packaged for Claude Code with the data model, the control it has to preserve, and the acceptance criteria attached, and send spend data modeling and reporting infrastructure to the Data suite when the ask is engineering rather than category judgment. Where the counterparty is also a customer, coordinate with the Sales and Revenue suite before a commercial position is taken, because a negotiating stance taken in one direction shows up in the other.
Capability baseline
references/capability-baseline.md states what may be assumed about the executing model, including long-horizon continuation and parallel fan-out, along with the governance invariants that do not relax as capability improves.