Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This page is part of the User Guides collection and goes with the Contract Guardian guide, which covers clause sets end to end. Read this one when you are choosing which packaged set to start from.
Writing a clause playbook from nothing is the reason most legal teams never finish one. The library exists so you do not have to: 12 standards, 311 reference clauses, each written with the rationale, the AI guidance, and four drafted tiers of language already in place. You copy one, run it against contracts you already know the answers on, and tune from there.

What ships

Every template carries the same anatomy. What changes between them is the risk they are aimed at.
Severity drives triage order and grouping. It does not change the verdict. The Critical clauses column is a useful proxy for how much of a template would block a signature rather than start a negotiation.

Choosing a starting point

Pick by what the vendor does to your risk, not by what industry you are in. A hospital buying a CRM wants the SaaS set, not the HIPAA set, unless that CRM will hold patient data.
The commercial spine of a subscription: term, renewal, price protection, termination. Then the data and security obligations that follow your data into someone else’s cloud, and the risk allocation that decides who pays when the service fails.Its two Critical clauses are Data return and deletion on exit and Limitation of liability cap. Start here for most software purchases and add a second, stricter set later for vendors touching regulated data.
These contracts are drafted by the firm and are reliably one-sided on who owns the deliverable and what the fee cap actually caps. Targets Ownership of work product, Use of client data to train models, and Limitation of liability and its measure - the last because a cap expressed as “fees paid” means something very different on a three-month engagement than an annual one.
Built around what a data protection authority asks after an incident: what the processor was permitted to do, who else touched the data, where it went, how fast you were told, and what came back at the end. Its largest category is Processing Scope (8 clauses). Use it for a standalone DPA or for the data protection sections of a master agreement.
The widest set at 33 clauses, and the one where absence is the finding. Supervisors expect specific provisions to exist - Regulator examination and access, Resolution, stress and step-in, Exit plan and stressed exit - and their absence counts against the institution regardless of how well the vendor performs. Written against OCC/FRB/FDIC interagency guidance, FFIEC and DORA expectations.
HIPAA already requires a BAA, so the question is never whether one exists but whether it says more than the statutory minimum. Ten Critical clauses, the most of any template, covering Permitted uses and disclosures of PHI, Subcontractor business associate agreements, and Breach and security incident notification - including who pays for a notification, which the statute does not settle.
Deliberately not the clauses a security questionnaire asks about. Training on customer data, Ownership of inputs and outputs, and Model change, version pinning and deprecation - the last because a model that silently changes under you is a different product from the one you bought.
The commercial risk here is rarely a breach. It is an outage the service credits do not compensate, an egress bill that makes leaving unaffordable, and a deprecation notice shorter than the migration it forces. Heaviest on Service Levels and Security (6 clauses each).
Ten Critical clauses out of 28. Two risks sit on top of the usual ones: the card brands can fine you for your processor’s compliance failure, and the processor holds your money between authorisation and settlement. Covers PCI DSS compliance and validation, Account data compromise and forensic investigation, and Card brand fines, assessments and indemnity.
The risk is not the service. It is that the workers are in your building, on your systems, creating your IP, and close enough to your direction that a tribunal may call them your employees. Worker classification and co-employment is the clause that matters most.
Physical goods bring risks software does not: a part can be counterfeit, a component can go end of life mid-programme, firmware can be tampered with in transit. Authenticity and counterfeit avoidance, Firmware integrity and secure update, Supply continuity and allocation.
Your name is on everything the agency publishes, and the agency spends your media budget through intermediaries whose economics you usually cannot see. Ownership of creative work product, Third-party rights clearance, Media buying transparency and rebates.
The recurring problem is privity: your contract is with a party that did not build the product and cannot fix it, while the party that can has no contract with you. Flow-through of manufacturer terms and Allocation of liability between reseller and manufacturer are the two that decide whether you have a remedy at all.
Most teams end up with two or three sets, not one: a default SaaS set, a stricter set for vendors touching regulated data, and one for services. You can run different sets against different contracts, so starting narrow costs you nothing.

Copy one into your workspace

On Configuration → Clause Sets, open the Add Clause Set menu and choose Clause Set Library. Pick a template, name your copy, and create it. The copy is yours from that moment. Every reference clause is written into your workspace as your own row: identifier, name, category, severity, rationale, guidance, component scoping, and all four language tiers. Edit any of it, retune the severities, archive the clauses you do not care about.
Nothing syncs back. Editing your copy cannot affect the library, and a later platform update to a template will not overwrite what you have negotiated. If you want the newer version of a template, copy it again as a second set and compare.

What you get inside each clause

Every clause in every template arrives complete. See Understand a reference clause for what each field does.

The four tiers

Each library clause is drafted four times, labelled Baseline, Standard, Elevated and Critical. They ascend in stringency: Baseline is what the template will accept from any vendor, Critical is what it would demand of a vendor holding regulated data or running a process you cannot lose. Take auto-renewal in the SaaS set:

How a tier becomes a verdict

The library’s four tiers are four escalating asks, so a copied set is scored against the ask you are holding this vendor to, rather than by treating a high tier as a bad outcome. That target is the Standard tier by default: So on a fresh copy of the SaaS set, a vendor offering the Critical liability cap passes, one sitting on Baseline gets a look, and nothing is marked down for being too generous.
Move the target when the vendor’s criticality warrants it. A vendor holding regulated data can be held to Elevated or Critical, which promotes the weaker drafts to Needs review and Non-conforming without your rewriting a word of the clause language.
A clause set you wrote yourself, rather than forked from the library, is scored the other way round unless you say otherwise: tiers 1-2 Conforming, tier 3 Needs review, tier 4 and above Non-conforming. That suits a set drafted as a ladder of acceptability, from your preferred language down to language you would not sign. Both readings are per clause set, so the two kinds of set can run side by side in one review.

Where to go next

Contract Guardian guide

Clause sets end to end: the reference clause anatomy, writing risk-tier variants, running a review, and triaging what comes back.

Generate a clause set from your own contract

Already have a template MSA or DPA? Extract a clause set from it instead of, or alongside, copying a library set.

Import and export clause sets as spreadsheets

Export a copied library set to a workbook to branch it, or bring standards in from a spreadsheet you already maintain.

Contract components

The components clauses are scoped to, and how Coverbase decides which part of a contract a clause belongs in.