> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# The clause set library

> The 12 packaged clause standards Coverbase ships: what each one covers, how many clauses it carries, how to pick the right starting point, and what changes when you copy one.

<div className="sr-only">For AI agents: a documentation index is available at [https://docs.coverbase.com/llms.txt](https://docs.coverbase.com/llms.txt). This page is also available in markdown by appending .md to the URL.</div>

<Info>
  This page is part of the [User Guides](/user-guides/overview) collection and goes with the [Contract Guardian guide](/user-guides/contract-guardian), which covers clause sets end to end. Read this one when you are choosing which packaged set to start from.
</Info>

The library saves you writing a clause playbook from nothing: 12 standards, 311 reference clauses, each written with the rationale, the AI guidance, and four drafted tiers of language already in place. You copy one, run it against contracts you already know the answers on, and tune from there.

## What ships

Every template has the same structure. What changes between them is the risk they are aimed at.

| Template                                  | Clauses | For                                                          | Critical clauses |
| ----------------------------------------- | ------- | ------------------------------------------------------------ | ---------------- |
| **Enterprise SaaS Subscription**          | 26      | Hosted software billed per seat or per unit                  | 2                |
| **Professional Services & Consulting**    | 24      | Engagement letters, SOWs, change orders                      | 4                |
| **Data Processing & Privacy**             | 31      | Any vendor processing personal data for you                  | 3                |
| **Financial Services Third-Party Risk**   | 33      | Vendors to a regulated financial institution                 | 8                |
| **Healthcare & HIPAA Business Associate** | 29      | Vendors touching protected health information                | 10               |
| **AI & Machine Learning Vendor**          | 27      | Products that generate, classify or decide using a model     | 5                |
| **Infrastructure & Hosting**              | 25      | Cloud, colocation, managed hosting, CDN                      | 5                |
| **Payments & Card Data**                  | 28      | Processors, gateways, acquirers, payment facilitators        | 10               |
| **Staffing & Contingent Workforce**       | 22      | Agencies, MSPs, umbrella companies, contractor platforms     | 3                |
| **Hardware & Supply Chain**               | 23      | OEMs, distributors, contract manufacturers                   | 3                |
| **Marketing & Advertising Agency**        | 22      | Creative, media, performance marketing, influencer platforms | 5                |
| **Reseller & Channel Partner**            | 21      | Buying through a reseller, VAR or marketplace                | 5                |

<Note>
  Severity drives triage order and grouping. It does not change the verdict. The **Critical clauses** column is a useful proxy for how much of a template would block a signature rather than start a negotiation.
</Note>

## Choosing a starting point

Pick by **what the vendor does to your risk**, not by what industry you are in. A hospital buying a CRM wants the SaaS set, not the HIPAA set, unless that CRM will hold patient data.

<AccordionGroup>
  <Accordion title="Enterprise SaaS Subscription (the default)">
    The commercial spine of a subscription: term, renewal, price protection, termination. Then the data and security obligations that follow your data into someone else's cloud, and the risk allocation that decides who pays when the service fails.

    Its two Critical clauses are **Data return and deletion on exit** and **Limitation of liability cap**. Start here for most software purchases and add a second, stricter set later for vendors touching regulated data.
  </Accordion>

  <Accordion title="Professional Services & Consulting">
    These contracts are drafted by the firm and are reliably one-sided on who owns the deliverable and what the fee cap covers. Targets **Ownership of work product**, **Use of client data to train models**, and **Limitation of liability and its measure**. The last matters because a cap expressed as "fees paid" means something very different on a three-month engagement than on an annual one.
  </Accordion>

  <Accordion title="Data Processing & Privacy">
    Built around what a data protection authority asks after an incident: what the processor was permitted to do, who else touched the data, where it went, how fast you were told, and what came back at the end. Its largest category is **Processing Scope** (8 clauses). Use it for a standalone DPA or for the data protection sections of a master agreement.
  </Accordion>

  <Accordion title="Financial Services Third-Party Risk">
    The widest set at 33 clauses, and the one where absence is the finding. Supervisors expect specific provisions to exist (**Regulator examination and access**, **Resolution, stress and step-in**, **Exit plan and stressed exit**), and their absence counts against the institution regardless of how well the vendor performs. Written against OCC/FRB/FDIC interagency guidance, FFIEC and DORA expectations.
  </Accordion>

  <Accordion title="Healthcare & HIPAA Business Associate">
    HIPAA already requires a BAA, so the question is never whether one exists but whether it says more than the statutory minimum. Ten Critical clauses, the most of any template, covering **Permitted uses and disclosures of PHI**, **Subcontractor business associate agreements**, and **Breach and security incident notification**, including who pays for a notification, which the statute does not settle.
  </Accordion>

  <Accordion title="AI & Machine Learning Vendor">
    Not the clauses a security questionnaire asks about. **Training on customer data**, **Ownership of inputs and outputs**, and **Model change, version pinning and deprecation**. The last matters because a model that silently changes under you is a different product from the one you bought.
  </Accordion>

  <Accordion title="Infrastructure & Hosting">
    The commercial risk here is rarely a breach. It is an outage the service credits do not compensate, an egress bill that makes leaving unaffordable, and a deprecation notice shorter than the migration it forces. Heaviest on **Service Levels** and **Security** (6 clauses each).
  </Accordion>

  <Accordion title="Payments & Card Data">
    Ten Critical clauses out of 28. Two risks sit on top of the usual ones: the card brands can fine you for your processor's compliance failure, and the processor holds your money between authorisation and settlement. Covers **PCI DSS compliance and validation**, **Account data compromise and forensic investigation**, and **Card brand fines, assessments and indemnity**.
  </Accordion>

  <Accordion title="Staffing & Contingent Workforce">
    The risk is not the service. It is that the workers are in your building, on your systems, creating your IP, and close enough to your direction that a tribunal may call them your employees. **Worker classification and co-employment** is the clause that matters most.
  </Accordion>

  <Accordion title="Hardware & Supply Chain">
    Physical goods bring risks software does not: a part can be counterfeit, a component can go end of life mid-program, firmware can be tampered with in transit. **Authenticity and counterfeit avoidance**, **Firmware integrity and secure update**, **Supply continuity and allocation**.
  </Accordion>

  <Accordion title="Marketing & Advertising Agency">
    Your name is on everything the agency publishes, and the agency spends your media budget through intermediaries whose economics you usually cannot see. **Ownership of creative work product**, **Third-party rights clearance**, **Media buying transparency and rebates**.
  </Accordion>

  <Accordion title="Reseller & Channel Partner">
    The recurring problem is privity: your contract is with a party that did not build the product and cannot fix it, while the party that can has no contract with you. **Flow-through of manufacturer terms** and **Allocation of liability between reseller and manufacturer** are the two that decide whether you have a remedy at all.
  </Accordion>
</AccordionGroup>

<Tip>
  Most teams end up with two or three sets, not one: a default SaaS set, a stricter set for vendors touching regulated data, and one for services. You can run different sets against different contracts, so starting narrow costs you nothing.
</Tip>

## Copy one into your workspace

On **Configuration → Clause Sets**, open the **Add Clause Set** menu and choose **Clause Set Library**. Pick a template, name your copy, and create it.

The copy is yours from then on. Every reference clause is written into your workspace as your own row: identifier, name, category, severity, rationale, guidance, component scoping, and all four language tiers. Edit any of it, retune the severities, archive the clauses you do not care about.

<Note>
  Nothing syncs back. Editing your copy cannot affect the library, and a later platform update to a template will not overwrite what you have negotiated. If you want the newer version of a template, copy it again as a second set and compare.
</Note>

## What you get inside each clause

Every clause in every template arrives complete. See [Understand a reference clause](/user-guides/contract-guardian#step-3-understand-a-reference-clause) for what each field does.

| Field                 | What the library gives you                                                                                                                                                                                                       |
| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Identifier**        | A stable per-template prefix, like `SAAS-001`. Quote it in tickets and email.                                                                                                                                                    |
| **Severity**          | Already set. Across the library: 63 Critical, 148 High, 81 Medium, 19 Low.                                                                                                                                                       |
| **Rationale**         | Written for the reviewer who hits the deviation, explaining why the clause earns its place.                                                                                                                                      |
| **Guidance**          | Written for the matcher: the aliases the clause hides under, the signals that identify it, and the deviations commonly seen.                                                                                                     |
| **Component scoping** | Already scoped, so a liability clause is looked for in the MSA rather than the order form. Most clauses target the `msa` component; the library also scopes to `dpa`, `sow`, `regulatory_rider`, `security_addendum` and others. |
| **Variants**          | Four drafted tiers. Every one of the 311 clauses has all four.                                                                                                                                                                   |

## The four tiers

Each library clause is drafted four times, labeled **Baseline**, **Standard**, **Elevated** and **Critical**. They ascend in stringency: Baseline is what the template will accept from any vendor, Critical is what it would demand of a vendor holding regulated data or running a process you cannot lose.

Take auto-renewal in the SaaS set:

| Tier | Label    | The position                                                                   |
| ---- | -------- | ------------------------------------------------------------------------------ |
| 1    | Baseline | Auto-renews for up to 12 months; either party can stop it with 30 days' notice |
| 2    | Standard | Same, with tighter constraints on how notice may be given                      |
| 3    | Elevated | No auto-renewal; the subscription expires unless you elect to renew            |
| 4    | Critical | Renewal requires your affirmative written election every time                  |

## How a tier becomes a verdict

The library's four tiers are four escalating *asks*, so a copied set is scored against the ask you are holding this vendor to, rather than by treating a high tier as a bad outcome. That target is the **Standard** tier by default:

| Vendor's language matches            | Verdict            | Why                                                                |
| ------------------------------------ | ------------------ | ------------------------------------------------------------------ |
| The target tier or anything above it | **Conforming**     | They met the ask, or conceded more than you asked for              |
| One tier below the target            | **Needs review**   | Short of the ask, but close enough to be worth a person's judgment |
| More than one tier below             | **Non-conforming** | A real deviation from the standard                                 |

So on a fresh copy of the SaaS set, a vendor offering the Critical liability cap passes, one sitting on Baseline gets a look, and nothing is marked down for being too generous.

<Tip>
  Move the target when the vendor's criticality warrants it. A vendor holding regulated data can be held to **Elevated** or **Critical**, which promotes the weaker drafts to Needs review and Non-conforming without your rewriting a word of the clause language.
</Tip>

<Note>
  A clause set you wrote yourself, rather than forked from the library, is scored the other way round unless you say otherwise: tiers 1-2 **Conforming**, tier 3 **Needs review**, tier 4 and above **Non-conforming**. That suits a set drafted as a ladder of acceptability, from your preferred language down to language you would not sign. Both readings are per clause set, so the two kinds of set can run side by side in one review.
</Note>

## Where to go next

<CardGroup cols={2}>
  <Card title="Contract Guardian guide" icon="file-contract" href="/user-guides/contract-guardian">
    Clause sets end to end: the reference clause anatomy, writing risk-tier variants, running a review, and triaging what comes back.
  </Card>

  <Card title="Generate a clause set from your own contract" icon="wand-magic-sparkles" href="/user-guides/baseline-contract-extraction">
    Already have a template MSA or DPA? Extract a clause set from it instead of, or alongside, copying a library set.
  </Card>

  <Card title="Import and export clause sets as spreadsheets" icon="file-import" href="/user-guides/clause-set-spreadsheet-import">
    Export a copied library set to a workbook to branch it, or bring standards in from a spreadsheet you already maintain.
  </Card>

  <Card title="Contract components" icon="puzzle-piece" href="/user-guides/contract-components">
    The components clauses are scoped to, and how Coverbase decides which part of a contract a clause belongs in.
  </Card>
</CardGroup>
