Continuity controls
Make the capability portable even when models, vendors, or people change.
AI systems accumulate dependencies quickly: data rights, model and provider versions, prompts, retrieval indexes, evaluation corpora, policies, secrets, tools, monitors, and undocumented judgment. The work record should let the client inspect and change those dependencies without relying on one person's memory.
- Client-held system record
- Architecture, code, contracts, prompts, model and vendor decisions, data sources, rights, configurations, evaluation assets, releases, incidents, corrections, costs, runbooks, and open risks remain in approved client systems.
- Least-privilege operation
- Individual identity, data, repository, model, provider, tool, environment, deployment, monitoring, and support access are approved for the work, reviewable, time-bounded where appropriate, and revoked through an owned exit path.
- Replaceable dependencies
- Provider-specific behavior is isolated behind explicit contracts where practical, and model, data, tool, policy, cost, latency, quality, fallback, migration, and exit assumptions are recorded and tested rather than described as portable by default.
- Demonstrated transition
- A receiving engineer can obtain approved access, reproduce representative evaluations, deploy and roll back safely, respond to an operating scenario, explain unresolved risks, and continue or retire open work before responsibility changes.