The Six Questions Version 1.1 doctrine banner

Six questions to ask any software vendor before you sign.

One minute, no engineer required. Each question has an acceptable answer and a disqualifying one, and you do not need to be technical to hear the difference.

The Six Questions, Version 1.1. Vendor-neutral. Released under CC0.

This is a list of screening questions meant to be run in a sales meeting. It works on any technology vendor, software agency, managed service provider, SaaS platform, AI shop, or database vendor, and each question is binary: there is an acceptable answer and a disqualifying one. You do not need to be a technical expert to notice the difference. Download the printable copy: conti-six-questions-v1.1.pdf.

These questions started as an article about AI agencies, and they kept working on every vendor type they were pointed at: hosted commerce platforms, IT shops, marketing agencies with a retainer to sell. This page is the maintained, vendor-neutral version.

One scoping note, because the word vendor covers two different purchases. These questions screen vendors who build or operate business-critical systems for you. Commodity tools, Stripe, QuickBooks, the hosted cart that still fits your sales, are a different decision: renting is fine when you know it is rent, the data exports, and the exit is priced. The disqualifying condition is rent disguised as ownership, not paid services themselves.

The field copy

Each question ends in a verdict

The printable version renders the structure literally: the acceptable answer boxed in green, the disqualifying answer boxed in rust, and the Ownership Standard items each check verifies printed in the margin. One page per pair of verdicts, four pages total, CC0.

Question one of the Six Questions field copy: who owns the account, with the acceptable answer boxed in green and the disqualifying answer boxed in rust, each citing Ownership Standard items

Question 1: Who owns the account?

Your system runs somewhere: an AWS account, a hosting panel, a SaaS tenancy. Whose name is on that account, who holds the root credentials, and whose card is on the bill?

An acceptable answer: “Yours. The account is registered to your business, you hold the root credentials, and we work through scoped roles you can revoke.”

A disqualifying answer: “It runs in our environment, but you have admin access.” Admin access to somebody else’s account is a guest pass. The owner can change the locks; the guest finds out afterward.

Question 2: Who holds the keys?

Credentials, API keys, signing certificates, the domain registrar login, the payment processor account. Ask where each one lives and who can rotate it.

An acceptable answer: “We administer the credentials through scoped roles in your account. Your business controls the secrets manager, can audit every permission, and can revoke or rotate access without moving the system.”

A disqualifying answer: “We manage all of that in our account, and clients do not receive administrative access.” Management is a service. Irrevocable custody is a dependency. The vendor can do the daily work without owning the only keys.

Question 3: What happens if the operating relationship changes?

A strong operating relationship can last for years. Ask for the continuity procedure before you sign so the relationship stays durable because the work is valuable, not because changing it would break the system.

An acceptable answer: “Here is the named transition procedure. Your systems keep running, and changing operators is a documented engineering transition, not a forced replatform.”

A disqualifying answer: “We have never needed a continuity procedure.” Or a proposal where changing operators requires a separate migration just to keep the same system running.

Question 4: What do the underlying costs run, versus the fee?

Every system has metered inputs: hosting, licenses, API calls, model usage, transaction percentages. Ask what those inputs actually cost, and whether you can see them.

An acceptable answer: “The inputs are metered in your own billing, at published prices. Our fee is for the work, and you can decompose it from the infrastructure any time.”

A disqualifying answer: A flat bundled fee that cannot be broken apart. A fee you cannot decompose is a margin you cannot see, and it grows in the dark.

Question 5: What changes after launch, and who owns it?

Production systems need ongoing attention. Dependencies, APIs, models, threats, traffic, and business requirements change. Ask what work the operator performs, what coverage applies, and where the operating record lives.

An acceptable answer: “Here is what changes over time, what I monitor, what I maintain, the coverage and response targets, and the work included in the fee. The runbooks, alerts, incident history, and deployment path stay in your account.”

A disqualifying answer: “It needs continuous tuning,” with no operating scope, response commitment, runbook, incident record, maintenance history, or clear line between infrastructure cost and engineering labor. Ongoing work is real. An undefined dependency is not an operating model.

Question 6: Can you verify the work at the depth you are buying?

You are buying engineering. Ask whether you can inspect it the way an engineer would.

An acceptable answer: “The repositories live in your organization with full commit history, and any engineer you choose can audit them whenever you like.”

A disqualifying answer: Demos and dashboards only. A demo is the vendor’s account of the work. The repository is the work.

If a vendor fails one question, negotiate. If they fail three, leave. If they refuse to answer at all, they have answered.

One minute to screen, one focused technical review to verify

These questions are designed as a quick screen to be run in a sales meeting, or referred to when considering various vendor offerings. The Exit Test checklist is the focused technical review: eleven concrete checks a qualified engineer can execute against any vendor, also CC0. The Ownership Standard is the engagement-length guarantee: thirteen numbered items, signed, attached as an exhibit to every build agreement I sign, with final payment gated on the audit passing. You can use this page without ever hiring me. You can run the checklist without ever meeting me. The standard you get by signing with me.

Where each question lands in the standard

Each question maps onto numbered items of the Ownership Standard.

  • Question 1, the account: OS-1 and OS-11.
  • Question 2, the keys: OS-3 and OS-4.
  • Question 3, leaving: OS-12 and OS-13.
  • Question 4, costs versus fee: OS-10.
  • Question 5, degradation: OS-2, OS-6, and OS-7.
  • Question 6, verification: OS-5, and the published scorecard.

If a vendor’s answers cannot be mapped onto numbered items in a standard they publish, that is itself the answer.

Print it

Built to be handed across a table

The cover carries the document's own metadata: version, effective date, license, and the verdict rule. Attach it to an outbound message, bring it to the sales meeting, or leave it with the founder who is about to sign a retainer.

The Six Questions Version 1.1 printable field guide cover
Open full-size image

Take it

This page is released under CC0: no attribution required, no permission needed. Print it, rebrand it, bring it to the sales meeting, forward it to the founder who is about to sign a retainer. The questions do not care who asks them. They only care that somebody does. If you want the version with a consequence attached, that is the Ownership Standard, and the vendor it applies to is me.