Skill: Draft Enterprise SaaS Subscription Agreement for Healthcare
1. Subject-matter triage
Start by separating the source set into: governing commercial terms, negotiated legal positions, baseline template language, technical/security evidence, and any side-channel IP or data guidance. Use the commercial sources to control economics and deal mechanics, the negotiation materials to override template defaults, and the security package to test whether promised obligations are supportable. Resolve conflicts by hierarchy, and record any unresolved tension in the issues memo rather than smoothing it over in the agreement.
If the materials point to regulated health data, treat privacy and security as part of the core contract package, not as an optional attachment. Determine whether the agreement needs a privacy addendum, security addendum, or other data-processing exhibit based on the data type and processing role reflected in the materials.
When more than one party, document version, or negotiated position is in play, enumerate the relevant variants before drafting so each is handled expressly. Do not average competing instructions into a generic clause.
2. Failure modes the skill is correcting
- Drafting from the template without reconciling it to the negotiated customer-side position and playbook constraints
- Missing customer-owned data, usage limits, derivative works, and model-training restrictions in the IP and data provisions
- Treating security and privacy commitments as boilerplate instead of checking them against the actual security package and regulated-data requirements
- Failing to carry commercial deal points through to operative clauses, exhibits, service levels, remedies, and termination mechanics
- Producing an agreement without a companion issues memo that identifies discrepancies, open items, and drafting judgments
- Hiding uncertainty in silent compromises instead of making the unresolved point visible and actionable
3. Legal frameworks / domain conventions that apply
- A SaaS agreement should allocate subscription scope, permitted use, support, uptime, service credits, fees, term, renewal, termination, and post-termination transition in a way that matches the deal papers and playbook
- Customer data should be expressly owned by the customer; vendor rights should be limited to hosting, processing, support, and other stated operational purposes
- Vendor IP should remain with the vendor, but customer-specific deliverables, configurations, or feedback rights must be aligned with the negotiated position in the source materials
- Regulated healthcare data requires contract language that tracks the applicable privacy and security regime reflected in the source documents, including any required addendum or exhibit
- Security representations should not exceed the documented controls, certifications, or practices in the security package; any gap must be surfaced and addressed
- Standard SaaS risk allocation often addresses confidentiality, audit, subcontracting, indemnities, liability caps, exclusions, and data return/deletion obligations
- Where the source materials identify a controlling policy or clause hierarchy, follow it; where they do not, state the drafting assumption in the issues memo and keep the agreement internally consistent
- Any legal proposition used in the drafting or memo should be tied to the controlling authority or governing contractual source reflected in the materials, not stated as an unsupported conclusion
4. Analytical scaffolds
- Term-sheet concordance: map each commercial point from the term sheet or proposal into an operative clause, exhibit, or schedule
- Template delta review: compare the starting template against the negotiated position and mark each meaningful deviation for the issues memo
- IP and data allocation: confirm ownership, license scope, use restrictions, derivatives, feedback, and post-termination handling
- Privacy and regulated-data integration: determine the required data-protection commitments and incorporate them consistently across main agreement and exhibits
- Security consistency check: compare contractual security promises to the security package and identify any overstatement, under-documentation, or missing control
- Operational remedies review: test support, service levels, credits, audit, suspension, remediation, and termination rights for fit with the deal
- Risk allocation review: confirm indemnity, warranty, limitation of liability, and exclusions track the negotiated balance
- Issues memo synthesis: for each issue, state the source conflict or gap, the drafting choice, the consequence of that choice, and any open approval needed
When analyzing multiple issue areas, address each one separately rather than compressing them into a single general note. If only one area is actually implicated, say so and explain why.
5. Vertical / structural / temporal relationships
Carry definitions forward consistently: data rights, services scope, security commitments, fees, and remedies should use the same defined terms throughout the agreement, exhibits, and memo. Keep the order of precedence explicit so the main agreement, addenda, statements of work, and security or privacy exhibits do not conflict.
Track temporal sequencing carefully: pre-signing commitments, service commencement, onboarding, renewal, notice windows, remediation periods, suspension triggers, termination rights, data return, and deletion obligations should each appear in the proper place and not be conflated. If a clause depends on another document being attached or finalized, flag that dependency in the issues memo rather than assuming it will be cured later.
Where one provision affects another, draft them together in substance even if they appear in different sections: for example, confidentiality interacts with data use; indemnity may interact with IP ownership; service levels may interact with credits and termination; security representations may interact with audit and breach notice; and post-termination rights may interact with data retention obligations.
6. Output structure conventions
- Draft the SaaS subscription agreement first, as the primary deliverable, and ensure it is complete and execution-ready before drafting the issues memo
- If the source materials require an addendum or exhibit, integrate it into the agreement package rather than leaving it as a dangling reference
- Use conventional contract architecture: parties, recitals, definitions, services, fees, term, data rights, confidentiality, security, compliance, support/service levels, IP, indemnity, limitation of liability, termination, post-termination obligations, and miscellaneous terms
- The agreement should read as a coherent final form, not as a commentary on the drafting process
- The drafting issues memo is secondary and should be organized by topic area with concise entries that identify: the source conflict or gap, the drafting decision taken, the consequence of that decision, and any item requiring client or business confirmation
- Use an ordinal severity label for each memo entry and apply it consistently across the memo; define the scale once at the top of the memo and keep the labels uniform
- End the memo with a short Recommended Actions section that tells the relevant owner what to do next and when, using imperative verbs and timing tied to the signing or implementation timeline
- Before finishing, confirm that the agreement file exists, is non-empty, and contains operative contractual language, and that the memo file exists, is non-empty, and contains actual issues analysis rather than a summary of the agreement
1---2name: draft-saas-subscription-agreement3description: Draft an enterprise SaaS subscription agreement for a healthcare platform procurement, together with a drafting issues memo, using the available commercial, legal, negotiation, and security materials.4---56# Skill: Draft Enterprise SaaS Subscription Agreement for Healthcare78## 1. Subject-matter triage910Start by separating the source set into: governing commercial terms, negotiated legal positions, baseline template language, technical/security evidence, and any side-channel IP or data guidance. Use the commercial sources to control economics and deal mechanics, the negotiation materials to override template defaults, and the security package to test whether promised obligations are supportable. Resolve conflicts by hierarchy, and record any unresolved tension in the issues memo rather than smoothing it over in the agreement.1112If the materials point to regulated health data, treat privacy and security as part of the core contract package, not as an optional attachment. Determine whether the agreement needs a privacy addendum, security addendum, or other data-processing exhibit based on the data type and processing role reflected in the materials.1314When more than one party, document version, or negotiated position is in play, enumerate the relevant variants before drafting so each is handled expressly. Do not average competing instructions into a generic clause.1516## 2. Failure modes the skill is correcting1718- Drafting from the template without reconciling it to the negotiated customer-side position and playbook constraints19- Missing customer-owned data, usage limits, derivative works, and model-training restrictions in the IP and data provisions20- Treating security and privacy commitments as boilerplate instead of checking them against the actual security package and regulated-data requirements21- Failing to carry commercial deal points through to operative clauses, exhibits, service levels, remedies, and termination mechanics22- Producing an agreement without a companion issues memo that identifies discrepancies, open items, and drafting judgments23- Hiding uncertainty in silent compromises instead of making the unresolved point visible and actionable2425## 3. Legal frameworks / domain conventions that apply2627- A SaaS agreement should allocate subscription scope, permitted use, support, uptime, service credits, fees, term, renewal, termination, and post-termination transition in a way that matches the deal papers and playbook28- Customer data should be expressly owned by the customer; vendor rights should be limited to hosting, processing, support, and other stated operational purposes29- Vendor IP should remain with the vendor, but customer-specific deliverables, configurations, or feedback rights must be aligned with the negotiated position in the source materials30- Regulated healthcare data requires contract language that tracks the applicable privacy and security regime reflected in the source documents, including any required addendum or exhibit31- Security representations should not exceed the documented controls, certifications, or practices in the security package; any gap must be surfaced and addressed32- Standard SaaS risk allocation often addresses confidentiality, audit, subcontracting, indemnities, liability caps, exclusions, and data return/deletion obligations33- Where the source materials identify a controlling policy or clause hierarchy, follow it; where they do not, state the drafting assumption in the issues memo and keep the agreement internally consistent34- Any legal proposition used in the drafting or memo should be tied to the controlling authority or governing contractual source reflected in the materials, not stated as an unsupported conclusion3536## 4. Analytical scaffolds3738- Term-sheet concordance: map each commercial point from the term sheet or proposal into an operative clause, exhibit, or schedule39- Template delta review: compare the starting template against the negotiated position and mark each meaningful deviation for the issues memo40- IP and data allocation: confirm ownership, license scope, use restrictions, derivatives, feedback, and post-termination handling41- Privacy and regulated-data integration: determine the required data-protection commitments and incorporate them consistently across main agreement and exhibits42- Security consistency check: compare contractual security promises to the security package and identify any overstatement, under-documentation, or missing control43- Operational remedies review: test support, service levels, credits, audit, suspension, remediation, and termination rights for fit with the deal44- Risk allocation review: confirm indemnity, warranty, limitation of liability, and exclusions track the negotiated balance45- Issues memo synthesis: for each issue, state the source conflict or gap, the drafting choice, the consequence of that choice, and any open approval needed4647When analyzing multiple issue areas, address each one separately rather than compressing them into a single general note. If only one area is actually implicated, say so and explain why.4849## 5. Vertical / structural / temporal relationships5051Carry definitions forward consistently: data rights, services scope, security commitments, fees, and remedies should use the same defined terms throughout the agreement, exhibits, and memo. Keep the order of precedence explicit so the main agreement, addenda, statements of work, and security or privacy exhibits do not conflict.5253Track temporal sequencing carefully: pre-signing commitments, service commencement, onboarding, renewal, notice windows, remediation periods, suspension triggers, termination rights, data return, and deletion obligations should each appear in the proper place and not be conflated. If a clause depends on another document being attached or finalized, flag that dependency in the issues memo rather than assuming it will be cured later.5455Where one provision affects another, draft them together in substance even if they appear in different sections: for example, confidentiality interacts with data use; indemnity may interact with IP ownership; service levels may interact with credits and termination; security representations may interact with audit and breach notice; and post-termination rights may interact with data retention obligations.5657## 6. Output structure conventions5859- Draft the SaaS subscription agreement first, as the primary deliverable, and ensure it is complete and execution-ready before drafting the issues memo60- If the source materials require an addendum or exhibit, integrate it into the agreement package rather than leaving it as a dangling reference61- Use conventional contract architecture: parties, recitals, definitions, services, fees, term, data rights, confidentiality, security, compliance, support/service levels, IP, indemnity, limitation of liability, termination, post-termination obligations, and miscellaneous terms62- The agreement should read as a coherent final form, not as a commentary on the drafting process63- The drafting issues memo is secondary and should be organized by topic area with concise entries that identify: the source conflict or gap, the drafting decision taken, the consequence of that decision, and any item requiring client or business confirmation64- Use an ordinal severity label for each memo entry and apply it consistently across the memo; define the scale once at the top of the memo and keep the labels uniform65- End the memo with a short Recommended Actions section that tells the relevant owner what to do next and when, using imperative verbs and timing tied to the signing or implementation timeline66- Before finishing, confirm that the agreement file exists, is non-empty, and contains operative contractual language, and that the memo file exists, is non-empty, and contains actual issues analysis rather than a summary of the agreement