Platform AI Policy and Vendor Governance
A 50-location HVAC and plumbing platform does not have one AI policy in 2026 โ it has a policy stack. Master vendor agreements with Avoca, Rilla, ServiceTitan, CallRail, Hatch, NiceJob, Podium, Birdeye, Wisetack, GreenSky, and Synchrony. Per-location operating procedures that translate the master policy into what every CSR, dispatcher, advisor, tech, and GM may and may not do with AI. Data-pooling architecture across all 50 locations that decides what data crosses location boundaries and what stays brand-local. Off-boarding rights that anticipate the day a vendor gets bought, raises prices 80%, or pivots away from trades. AI-output IP language that decides whether the call summaries Avoca produces are the platform's property, the vendor's, or jointly held. And the three risks of pooling โ leakage, contamination, and lock-in โ that the platform CEO and general counsel sign their names to. This is the L5 governance lesson. Written, signed, audited. The artifact set the PE board reads on slide 8 of the quarterly review and the artifact set that survives the day a state AG, CFPB examiner, or class-action plaintiff arrives.
Why Policy Stack, Not Policy Document
The single-document trades AI policy circulated in 2023-2024 ("our AI policy is on page 14 of the employee handbook") is structurally inadequate at platform scale. A 5-location independent operator can survive a one-pager because the owner enforces it directly. A 25-location operator under Wrench Group, Authority Brands, Apex Service Partners, Sila Services, Path Light Pro, Redwood Services, or ARS-Rescue Rooter cannot. The policy must function across 8-12 vendors, 50-450 locations, 4-15 brands, 30-50 states, and a CSR floor turning over at 35-45% annually. A single document gets ignored at scale; a policy stack gets enforced.
The stack has six layers. Layer one is the master AI policy โ the platform-wide document signed by the CEO, general counsel, and (for PE-backed platforms) the PE partner with operating oversight. Layer two is the vendor governance schedule โ the master agreements with every named AI vendor in the platform stack, with data clauses, off-boarding terms, AI-output IP, sub-processor disclosure, and pricing locks. Layer three is the per-location operating procedure โ the document a GM signs that translates the master policy into daily operations at their site. Layer four is the per-role role card โ the laminated card the CSR, dispatcher, tech, advisor, and marketing manager keeps at their station summarizing what they may and may not do. Layer five is the data-classification and pooling architecture โ the data-flow document the Director of AI Operations and the platform CISO co-own. Layer six is the audit cadence and incident response โ quarterly governance review, monthly vendor-configuration audit, 72-hour breach response playbook (the topic of Lesson 3).
Each layer has a named owner. Master policy: CEO and General Counsel co-sign. Vendor governance: Chief Procurement Officer or Director of AI Operations owns; General Counsel reviews. Per-location procedure: Regional Director owns; GM signs annually. Role cards: Director of AI Operations co-owns with HR. Data architecture: CISO + Director of AI Operations co-own; reviewed quarterly. Audit cadence: Director of AI Operations operationally; General Counsel legally. Without named ownership at every layer, the stack collapses into the unenforced one-pager that produced the 2024-2025 platform AI graveyard.
The Master AI Policy โ What Every Location Must Do and Must Not Do
The master AI policy is the platform-wide operating posture. It is 8-14 pages, signed by the CEO and General Counsel, and re-signed annually with documented revision history. The policy covers eight required sections: scope, approved-vendor list, data classification, prompt discipline, customer-language rules, financing discipline, dispute-handling discipline, and governance and audit cadence. The policy is written as enforceable operating language, not aspirational philosophy.
Scope defines who is covered: every employee, contractor, franchisee under the platform brand, and third-party agency operating on behalf of the platform. Approved-vendor list names the only AI tools any location may deploy without HQ approval โ Avoca, Rilla, ServiceTitan Titan Intelligence, CallRail Conversation Intelligence, Hatch, NiceJob, Podium AI Employee, Birdeye AI Employee, and the financing portals (Wisetack, GreenSky, Synchrony). Any tool not on the list requires the override request memo (the L5 Ch1 Lesson 3 topic for franchise platforms) submitted to the Director of AI Operations with a 14-day review SLA. The list is reviewed quarterly; vendors are added or removed by the governance committee, not by individual location managers.
Data classification defines four tiers: public (marketing content, service-area pages, general FAQ โ AI may freely process), business confidential (job notes without PII, route history, equipment SKUs โ AI may process with vendor-signed BAA or DPA), customer PII (name + address + phone + email + payment + SSN + soft-pull identifiers โ AI may only process within named approved vendors with active BAA/DPA and per-state two-party-consent compliance), and regulated content (financing disclosures, FCRA adverse-action notices, EPA 608 logs, contractor-board-required disclosures โ AI may NEVER originate; portal output or lender template only). Each tier has named approved vendors and forbidden vendors. Consumer ChatGPT, Claude, Gemini, Perplexity, and Copilot are explicitly forbidden for any tier above public data. The policy lists this prohibition with the same emphasis as "no working under the influence."
Prompt discipline mandates the 5-part prompt structure (role, context, task, format, constraint) and forbids the paste-customer-record pattern. Customer-language rules mandate that no AI output reaches a customer (text, email, proposal, review response, IVR script) without named licensed human signoff for any artifact with regulatory exposure, manager signoff for any artifact above $5K in customer commitment, and CSR/advisor signoff for routine artifacts. Financing discipline mandates portal-output verbatim โ AI never drafts APR, term, payment schedule, or adverse-action language. Dispute-handling discipline mandates owner final authority on any customer dispute above $5K, manager authority on $1K-$5K, advisor authority on under $1K; AI may draft responses at each tier but the named human signs. Governance and audit cadence mandates weekly failure-log review, monthly vendor-configuration audit, quarterly governance committee meeting, and annual policy refresh with documented revision history.
Master Vendor Agreements and the Eight Required Clauses
The master vendor agreement is the platform's contract artifact with each named AI vendor. The standard SaaS click-through that an individual location might accept is structurally inadequate at platform scale. The platform's General Counsel negotiates eight required clauses with every AI vendor in the stack. Vendors that refuse to commit to all eight are not approved-vendor list members โ they are pilot-only candidates, not platform-deployed tools.
Clause one: data ownership and use. The platform owns the data the platform's customers, employees, and operations generate. The vendor may process the data to deliver the contracted service but may not use it to train models that benefit other customers without affirmative opt-in. The 2024-2025 standard SaaS clause that let vendors aggregate platform data into training corpora is what the master agreement explicitly forbids. Clause two: sub-processor disclosure and approval. Every vendor's vendors (the AI model provider behind Avoca, the cloud provider behind CallRail, the analytics vendor behind Hatch) must be named, listed in a sub-processor schedule, and require platform approval before substitution. Sub-processor changes mid-contract trigger 60-day notice and a re-approval right.
Clause three: data residency. Platform data may be processed only in named jurisdictions (typically US, with EU-only carve-outs for specific tools where applicable). The clause names the jurisdictions and forbids cross-border transfer without written platform approval. Clause four: off-boarding rights. On termination (for cause, for convenience, on acquisition, on price increase above defined threshold), the platform has the right to (a) export all platform data in usable structured formats within 30 days, (b) delete confirmed data within 60 days, (c) receive vendor cooperation for migration to a successor vendor, and (d) maintain read-only access to historical artifacts (call recordings, scorecards, proposals) for 6 months post-termination at no incremental cost. The clause prevents the vendor-capture risk that turns AI deployment into a 5-year ransom.
Clause five: AI-output IP. The artifacts AI produces โ call summaries, scorecards, transcripts, draft proposals, review responses, engineered prompts โ are platform IP. Vendor has a non-exclusive license to use de-identified, aggregated outputs to improve the service; platform retains exclusive use of outputs in production. The clause is a 2026 negotiating frontier โ vendors initially resist but converge under pressure from the eight named platforms. Clause six: deployment success metrics. Contract names the lift vendor is accountable for during deployment (Avoca missed-call %, Rilla close-rate, Dispatch Pro RPT, Hatch reactivation rate). Failure to meet stage-gate targets is a termination-for-cause trigger with prorated refund eligibility.
Clause seven: indemnification and insurance. Vendor indemnifies platform against vendor's own gross negligence and IP infringement claims; vendor maintains cyber-liability insurance with $5M per occurrence and $10M aggregate minimum, names platform as additional insured, provides annual evidence of coverage. Clause eight: audit rights. Platform may audit vendor compliance (data residency, sub-processor list, SOC 2 Type II posture, security controls) annually with 30 days notice. Rarely exercised; its existence converts the contract into an operational instrument rather than a sales artifact.
Data Pooling Across 50 Locations and the Three Risks
The platform's compound advantage is data scale. A 50-location operator generates 100K-500K recorded calls per month, 50K-300K customer records, 200K-1M job artifacts (proposals, work orders, photos, scorecards). Pooled across the platform, this data trains better AI scorecards, drives better dispatch decisions, surfaces better lead-source attribution, and produces case-study quality lift documentation the PE board reads. Pooled poorly, the data creates three risks the General Counsel cannot defend.
Risk one: leakage. Pooled data flowing to a vendor's broader model corpus produces customer-record exposure if vendor training data leaks. Mitigation is contractual (master agreement clause 1), operational (data classification preventing tier-3 customer PII flow to non-BAA vendors), and architectural (data masking and tokenization at vendor handoff). The data architecture document names masking rules per type โ phone numbers tokenized after extraction, SSNs never sent to AI vendors (PCI-segregated to financing portals), credit cards PCI-tokenized at all touchpoints.
Risk two: contamination. Data pooled across brands with different voice, pricing model, market positioning, and customer-base demographic produces models that average across distinctions. A One Hour Heating & Air call summary trained on Wrench-Group-pooled data may not capture the brand-specific tone the franchisor's standards require. A premium-positioned Northeast Sila Services proposal template dilutes when the corpus includes value-positioned Southeast acquisitions. Mitigation is pooling architecture segmented by brand, region, or customer-segment with brand tags preserved on every record โ data flows into shared infrastructure but model fine-tuning or prompt customization preserves brand-specific signal.
Risk three: lock-in. The more pooled data a vendor holds, the higher the platform's switching cost on price increase, acquisition, or pivot. The 2025 case where a regional voice AI vendor sold to a PE consolidator and raised prices 70% on year-2 renewals is the precedent. Locations that had let the vendor accumulate 18-24 months of call history faced switching costs measured in months of operational disruption. Mitigation is off-boarding rights (clause 4), continuous export to platform-owned storage (so vendor copy is always derivative), and the multi-vendor sequencing discipline that preserves switching optionality.
The risk triad โ leakage, contamination, lock-in โ is signed off by General Counsel and Director of AI Operations on the data-pooling architecture document. Each risk has documented mitigation, named owner, and quarterly review. The risk register lives in the policy stack; the PE board sees it on slide 8.
Per-Location Operating Procedure and the GM Signature
The master policy is enforceable across 50 locations only if every GM signs the per-location operating procedure annually. The per-location procedure translates the master policy into the site's daily operations and the GM's named accountabilities. The signature is not ceremonial โ the GM's annual review includes confirmation the procedure was followed during the year and the failure log reflects any breaches with documented remediation.
The procedure has six sections matched to the master policy. Approved vendor list for the location (platform stack plus 0-2 location-specific tools approved via override request). Data handling per role at the site (which CSR, dispatcher, advisor, tech data tier maps to which AI tool). Prompt and customer-language discipline (role cards posted, 5-part prompt, 30-second verify pass, commitment-language ban for review responses). Financing discipline (portal-paste workflow, literal placeholder language in AI-drafted advisor talk tracks). Dispute-handling (GM, manager, advisor signoff hierarchy by dollar value). Audit and reporting cadence (weekly failure log review by GM, monthly vendor-configuration check, quarterly governance submission to HQ).
The GM's signature acknowledges they have read the master policy, understand the per-location procedure, trained the team on the role cards, and will maintain the audit cadence. Annual re-signature follows the master policy refresh; mid-year significant changes trigger interim acknowledgment. The signature is what connects platform-level governance to operational accountability โ without it, platform policy is unenforceable at the location where the work actually happens.
Role Cards and the Laminated Discipline at Every Station
The role card is the one-page laminated artifact at every CSR station, every dispatcher desk, every advisor's tablet bag, every tech's truck cab, and every manager's office. The card is the operating discipline the master policy enforces at the moment of work โ the platform's defense against the gap between policy and practice that kills enforcement at scale.
Each role gets a tailored card. The CSR card lists the 5-part prompt structure, the 30-second verify checkpoints (numbers, names, parts, warranty terms, financing language), the no-PII-to-consumer-AI rule, the approved-vendor list for CSR work (Avoca, Jobber Copilot, Housecall Pro AI Agents, ServiceTitan Voice, CallRail Conversation Intelligence), and the escalation path for uncertain AI output. The dispatcher card lists Dispatch Pro override criteria, data-handling on customer addresses and route history, and escalation for dispatch decisions diverging from AI by more than $400 expected revenue. The advisor card lists the financing portal-paste workflow, proposal verify checklist (SEER ratings, warranty terms, code citations, rebate amounts), the named signoff hierarchy, and the kitchen-table consent-disclosure script. The tech card lists EPA 608 verify (manufacturer table cross-reference for refrigerant charge), photo-and-tag AI discipline (no people in photos without consent), and customer-address data-handling. The manager card lists weekly failure-log review, AI review-response approval discipline, and policy-breach escalation. The GM card lists monthly vendor-configuration audit, quarterly governance submission, and named authorities for dispute resolution by dollar value.
Each card is refreshed annually with the master policy refresh and any mid-year significant change. Cards are produced by HQ, distributed to each location, and posted by the GM at every station within 30 days of issuance. 2025 audit findings at the platforms running the framework: locations with visible role cards scored 65-80% higher on policy compliance than locations without โ the card is the discipline made visible at the moment of work.
Audit Cadence, Incident Response, and the PE Board Slide Eight
The governance and audit cadence is the heartbeat of the stack. Weekly: each GM reviews the location's failure log (any AI-touched artifact that produced an issue โ a hallucination caught, a customer complaint traced to AI output). Monthly: the Director of AI Operations runs the platform-wide vendor-configuration audit โ every vendor's per-state two-party-consent settings, sub-processor list vs. the master agreement schedule, and data-residency confirmation. Quarterly: the governance committee meets (CEO, General Counsel, Director of AI Operations, CISO, Chief Procurement Officer, rotating regional director) and reviews the master policy revision queue, vendor stack approvals/removals, data-pooling architecture changes, and consolidated failure log. Annual: master policy refresh; vendor master agreement renewal review; LP reporting package summary.
Incident response defines the escalation path: GM-level for routine incidents, Director of AI Operations for cross-location or regulatory-adjacent, General Counsel and CEO for incidents requiring regulatory notification or customer disclosure, PE partner for material-adverse-change or LP disclosure obligations. The incident playbook itself (the topic of L5 Ch3 Lesson 3 on cybersecurity and breach response) sits inside this layer.
PE board slide eight is the artifact the platform CEO walks into the quarterly review with. Failure-log volume and trend (count by category, quarter-over-quarter). Vendor-stack changes (additions, removals, renewals with material term changes). Governance committee decisions of note. Policy-stack health score (audit compliance rate across the 50 locations, GM signature currency, role card distribution status). Two to three minutes of board time. The operating system behind the slide is the discipline that converts AI deployment into an operational compounding asset rather than an unmanaged liability surface.
Key Takeaways
- Policy stack, not policy document. A 50-location platform's AI governance is six layers: master AI policy (CEO + General Counsel co-sign), vendor governance schedule (Director of AI Operations owns), per-location operating procedure (GM signs annually), role cards (laminated, posted at every station), data classification and pooling architecture (CISO + Director of AI Operations co-own), audit cadence and incident response (Director of AI Operations operationally, General Counsel legally).
- The master AI policy has eight required sections. Scope, approved-vendor list, data classification (four tiers โ public, business confidential, customer PII, regulated content), prompt discipline, customer-language rules, financing discipline (portal-output verbatim), dispute-handling discipline (named signoff hierarchy by dollar value), and governance and audit cadence (weekly, monthly, quarterly, annual).
- Master vendor agreements require eight clauses. Data ownership and use; sub-processor disclosure and approval; data residency; off-boarding rights (30-day export, 60-day deletion, 6-month read-only post-termination); AI-output IP (platform owns artifacts, vendor has non-exclusive de-identified license); deployment success metrics (stage-gate-measured, termination-for-cause trigger); indemnification and cyber-liability insurance ($5M occurrence / $10M aggregate); audit rights (annual, 30-day notice). Vendors refusing all eight are pilot-only candidates, not platform-deployed tools.
- Data pooling has three named risks. Leakage (mitigated via master agreement clause 1, data classification policy, tokenization and masking); contamination (mitigated via pooling architecture segmented by brand/region/customer-segment with brand tags preserved); lock-in (mitigated via off-boarding rights, continuous export to platform-owned storage, multi-vendor sequencing discipline preserving switching optionality). Each risk has documented mitigation, named owner, and quarterly review.
- Per-location operating procedure connects platform governance to operational accountability. Six sections mirroring the master policy; GM signs annually with mid-year acknowledgments on significant changes; the GM's annual review includes procedure compliance confirmation. Without the GM signature, platform policy is unenforceable at the location where the work happens.
- Role cards are the discipline made visible at the moment of work. CSR, dispatcher, advisor, tech, manager, owner each get tailored laminated cards posted at every station. The cards close the gap between binder policy and actual practice; 2025 audit data shows 65-80% higher compliance at locations with visible role cards.
- Approved-vendor list is the gate for any AI tool. Avoca, Rilla, ServiceTitan Titan Intelligence, CallRail Conversation Intelligence, Hatch, NiceJob, Podium AI Employee, Birdeye AI Employee, Wisetack, GreenSky, Synchrony are the platform stack. Consumer ChatGPT, Claude, Gemini, Perplexity, and Copilot are explicitly forbidden for any tier above public data. Additions or removals go through the governance committee, not individual locations.
- Audit cadence is the heartbeat. Weekly failure-log review by GM; monthly vendor-configuration audit by Director of AI Operations; quarterly governance committee meeting (CEO, GC, Director of AI Ops, CISO, CPO, rotating regional director); annual master policy refresh and vendor renewal review.
- Incident response escalation by severity. GM-level for routine incidents; Director of AI Operations for cross-location or regulatory-adjacent incidents; General Counsel and CEO for regulatory notification or customer disclosure; PE partner for material adverse change or LP disclosure obligations.
- PE board slide eight is the artifact. Failure-log volume and trend, vendor stack changes, governance committee decisions of note, policy-stack health score (audit compliance rate, GM signature currency, role card distribution status). Two to three minutes of board time; the operating system behind it is the platform's compound governance advantage.
- The asymmetry holds at platform scale. Without the stack, the platform absorbs the 2024-2025 graveyard pattern โ write-offs, regulatory inquiries, vendor-capture losses, PE board confidence erosion. With the stack, the platform demonstrates the operating maturity capital favors with multiple expansion at exit.
Skill.re