Почніть з ownership boundaries
Уточніть, кому належать repositories, cloud accounts, domains, data, credentials і deployment access.
Ваш бізнес має продовжити operations навіть при зміні vendor.
Оцініть engineering process
Питайте про architecture decisions, code review, release tests і incident handling.
Transparent process простіше управляти, ніж delivery на героїзмі окремих людей.
Security має бути contractual і technical
Access — least privilege, secrets — centralized, offboarding — швидке removal credentials.
Security responsibility повинна мати named owners і auditable controls.
Communication потребує operating rhythm
Визначте product decision makers, engineering leads, escalation paths, reporting cadence і response expectations.
Good communication будується навколо decisions і risks, а не нескінченних meetings.
Порівнюйте total delivery cost
Враховуйте rework, delayed releases, support burden, vendor lock-in і incident risk.
Сильний vendor робить progress і risk видимими рано.
Оцінюйте vendor як product risk
До довгого engagement проведіть focused technical discovery або чітко обмежений pilot, якщо це доречно, щоб перевірити communication, architecture judgment, code quality і delivery visibility. Важливо побачити поведінку команди при incomplete requirements або technical risk.
З першого дня зафіксуйте exit conditions: repository ownership, infrastructure access, documentation, credential rotation і handover. Продукт не повинен ставати operational hostage vendor.