Picture the intake the morning after a sales kickoff. Forty-six contracts in the queue: eleven inbound NDAs, nine renewals procurement forwarded because someone half-remembered the GC asking to see "anything over $50K," six vendor security addenda from a SaaS vendor whose MSA is in place, a reseller agreement the CRO wants signed by Friday, a Fortune 500 MSA back with 64 redlines, two offers stuck on IP language.
The GC, who has a board deck due Wednesday, opens the queue and starts at the top. That is the failure mode most in-house teams call a process.
A real playbook is a routing layer that prevents that morning. It says which paper a contract manager clears, which the in-house counsel handles, which goes to the GC, which goes to a firm.
It names fallback positions on recurring clauses, so the same NDA is not negotiated three ways. It survives AI stacked on top, because AI is a junior reviewer working off the same checklist.
This guide is for in-house counsel and legal ops at scaleup and midmarket companies (Series B through D), and it sits alongside our broader take on legal AI for in-house counsel. AmLaw process is different.
What is a contract review playbook?
A contract review playbook is a written routing and position document. It says which contracts each role clears (a tiered escalation), and it names the preferred, fallback, and walk-away position on every recurring clause (liability cap, indemnity, term, IP, data, termination). The point is to make legal judgment reusable: the same NDA is not negotiated three ways, and a contract manager can close a routine deal without pinging the GC. AI sits on top as a first-pass reviewer working off the same written positions.
TL;DR
Part of our in-house counsel guide series.
- A five-tier playbook beats ad-hoc review: auto-approve, contract manager, in-house counsel, GC, outside counsel. Dollar value crossed with risk category, routing decided once and written down, not negotiated per contract.
- Every recurring clause needs three positions: accept on first pass, negotiate up, walk away. The master clause table below is the part most playbooks skip and the part a contract manager actually uses.
- Contract-type playbook items (MSA, DPA, SaaS, NDA, reseller, employment, vendor security, confidentiality) need named fallback positions, not vibes. Write it down.
- Tooling sits on top of the playbook, never in place of it. CLM (Ironclad, SpotDraft, Lexion) handles routing and storage. AI review handles the first read. E-signature handles the close. None of them tells you what your fallback on liability cap should be.
- Use AI for first-pass review. Refusing in 2026 is a budget decision dressed up as a risk position.
Under the default five-tier structure, what SaaS ACV auto-approves at Tier 1?
Why a playbook beats ad-hoc review
Four costs of going without.
Inconsistency. Without a written fallback on liability cap, three reviewers accept three different caps. The vendor side knows and negotiates against whatever your last reviewer accepted.
Escalation overload. Everything routes through legal. The GC reviews the same form NDA the contract manager could have cleared in two minutes.
Vendor onboarding drag. A clear "SaaS under $25,000 auto-approves" line cuts onboarding from weeks to days for the long tail.
Velocity falls. Without a playbook, legal becomes a two-week function. Deals slip, ARR slips, the CRO knocks on the GC's door.
The five-tier structure
Five tiers, dollar value crossed with risk category. Calibrate to deal mix and revenue.
A Series B at $15M ARR with 90% SaaS inbound should auto-approve under $15,000, not $25,000, because a higher floor sweeps up material vendors. A Series D at $80M ARR with custom enterprise MSAs as half its inbound should run Tier 4 GC review at $1M+, not $500,000, or more deals hit the GC than the GC can read.
Defaults below assume $20M to $100M ARR, mixed book. Rewrite against your last 90 days of inbound.
Tier 1: Auto-approve. SaaS under $25,000 ACV on the vendor's paper, where they signed your standard MSA or DPA in the last twelve months. NDAs matching your form (mutual, two-year, standard carve-outs). Order forms under an existing MSA where only pricing and quantity change.
Procurement runs the checklist. Legal sees a weekly summary.
Tier 2: Contract manager or paralegal. SaaS $25,000 to $100,000. NDAs deviating on length or carve-outs but not on indemnity or governing law. Order forms with custom payment terms. Vendor security addenda matching a pre-approved control set.
The reviewer works from the fallback-position checklist. Anything outside it escalates.
Tier 3: In-house counsel. Custom MSAs, deviating DPAs, SaaS $100,000 to $500,000, reseller agreements under $250,000, employment offers above a salary band, vendor agreements touching customer data.
The in-house lawyer redlines against the playbook and closes. Novel positions escalate.
Tier 4: GC review. Contracts above $500,000 ACV, anything shifting indemnity or LoL outside the playbook fallback, anything touching IP licensing posture, anything with board-level reporting implicated. GC signs off; in-house counsel runs the redlines.
Tier 5: Outside counsel. Specialized risk (cross-border tax, regulated industries, FCPA, antitrust review), novel structures (joint ventures, equity-linked commercial terms, M&A side letters), or litigation-adjacent contracts. The firm is named in the playbook by practice area. Keeping routine paper out of this tier is how a playbook quietly cuts outside counsel spend.
The point: thresholds and risk categories are written down. The contract manager does not decide whether to escalate. The playbook decides.
Eight contract-type playbook items
Five-tier routing is the skeleton. Per-type entries name the fallback positions. Eight cover roughly 90% of scaleup in-house volume.
MSA and SOW
Your standard MSA is the starting position. Negotiable: LoL (12 months fees, super-cap at 3x or uncap for confidentiality and IP), indemnity (mutual for IP infringement, one-way running to vendor for negligence and willful misconduct), termination for convenience (30 days).
Hard reject: uncapped indirect damages, mutual indemnity for everything, audit rights into your source code. SOWs run under the MSA: deliverables, acceptance, and payment milestones negotiable; MSA boilerplate is not.
Data Processing Agreement (DPA)
Every vendor touching personal data needs a DPA aligned to GDPR Article 28. Accept: subprocessor lists, breach notice within 48 hours, standard contractual clauses for EEA transfers.
Negotiate up: audit rights, data return on termination (90 days minimum), incident notification at 24 hours.
Hard reject: any DPA stripping your right to instruct the processor, or capping processor liability for data incidents at the underlying contract cap. Data incidents sit outside the general LoL cap or super-capped at multiples.
Software license or SaaS subscription
The most common contract, usually on the vendor's paper. Accept: 12-month term with auto-renewal, 30 days notice to terminate, payment net 30.
Negotiate up: data portability on termination (CSV within 60 days), uptime SLA with credits at 99.5%+, price-increase cap at the lower of CPI or 7% annually.
Hard reject: auto-renewal with no notice window (a New York General Obligations Law § 5-903 problem), unilateral mid-term price changes, vendor termination for cause on subjective determination.
NDA (mutual vs unilateral)
NDAs eat more hours than they should. The cure is a one-page entry and disciplined NDA triage. For mutuals: accept two-year confidentiality, three-year residuals-free for trade secrets, standard carve-outs (independently developed, publicly available, required by law).
Negotiate up: confidential information limited to material marked or identified within 30 days. Hard reject: perpetual terms, non-solicitation bundled inside, anything expanding the NDA into a non-compete.
Unilateral NDAs against you trigger Tier 3 to ask why a mutual is not on offer. The full one-page entry, with AI-enforced positions, lives in our NDA playbook template.
Reseller or channel partner agreement
Reseller agreements are where the playbook earns its keep. Accept: published partner discount tier, one-year term, mutual termination for convenience with 90 days notice.
Negotiate up: who owns the customer relationship and data, marketing approval rights, deal-registration. Hard reject: exclusivity without a meaningful minimum commitment, MFN clauses, any right to sublicense or rebrand.
Default Tier 3 or 4 depending on the exclusivity ask.
Employment offer and IP assignment
Offer letter and IP assignment (often combined) are templated, but variable terms need entries. Accept: at-will employment in at-will states, four-year vesting with one-year cliff, broad IP assignment subject to state-mandated carve-outs (California Labor Code § 2870 and equivalents in Washington, Minnesota, Illinois).
Hard reject: prior-invention lists including current-employer IP without indemnity, and IP assignment trying to capture inventions outside scope where statute prohibits it. Above a defined salary band, escalate to Tier 4.
Vendor security addendum
The contractual face of your security program. Accept: SOC 2 Type II annually, encryption at rest and in transit, breach notice within 48 hours, subprocessor approval with 30 days notice.
Negotiate up: annual scoped penetration testing at vendor cost, annual security questionnaire, defined incident response runbook with named contacts.
Hard reject: vendors refusing a specific framework, capping security-incident liability at the contract cap, or changing posture without notice. Contract manager runs first pass, in-house counsel signs off, because the failure mode is regulatory.
Confidentiality and data processing addendum
Some counterparties combine confidentiality and data processing. Treat it as a DPA plus a mutual NDA, apply both, surface conflicts. Accept: NDA terms govern non-personal confidential info, DPA terms govern personal data, stricter rule applies where they overlap.
Negotiate up: breach timelines (24 hours for personal data, 48 for other). Hard reject: structures collapsing both regimes into a single cap below where each would sit individually. Default Tier 3.
Fallback positions
Most playbooks list clauses. The better ones list positions per clause: accept on first pass, negotiate up, hard reject.
Negotiation is asymmetric. The vendor's rep has done this deal a hundred times; your contract manager has done a few. If the playbook says "negotiate liability cap," the manager does not know whether to push from 1x annual fees to 12 months, from 12 to 24, or to ask for a super-cap on IP.
The vendor's rep knows their floor. The playbook closes the asymmetry.
Worked example. A SaaS vendor offers $75,000 ACV with a liability cap at fees paid in the prior 3 months. Playbook entry: "Accept LoL at 12 months fees with super-cap at 3x for IP and data breach; negotiate up to 24 months above $250,000 ACV; hard reject below 12 months fees."
Tier 2 runs that play without escalating. Deal closes in two days, not two weeks.
The playbook is a default, not a rulebook. Tier 3 and Tier 4 can override, but the override is a logged decision. That matters when the same vendor comes back a year later.
The clause-position table (copy and calibrate)
This is the page a contract manager keeps open during review. Six clauses cover most of the fights. Preferred is your opening paper. Fallback is the most you give without escalating. Walk away is the line that triggers escalation to the next tier, never a silent concession. Calibrate the dollar thresholds to your own book.
| Clause | Preferred (open here) | Fallback (concede to here) | Walk away / escalate |
|---|---|---|---|
| Limitation of liability | Cap at 12 months fees; super-cap at 3x (or uncapped) for IP infringement and data breach; indirect/consequential damages excluded both ways | Cap up to 24 months fees above $250K ACV; super-cap at 2x for data | Cap below 12 months fees; uncapped indirect damages running to you; data-incident liability folded into the general cap |
| Indemnity | Mutual for third-party IP infringement; vendor indemnifies for its negligence and willful misconduct; defense plus settlement | Drop willful-misconduct carve-out if cap holds; cap indemnity at the super-cap | Mutual indemnity for everything; you indemnify vendor for its own product; indemnity capped at the base LoL |
| Term and renewal | 12-month term, 30 days notice to terminate, auto-renewal with 30-day pre-renewal notice | 24-month term if pricing is locked; auto-renew with 60-day notice window | Auto-renewal with no notice window (a New York General Obligations Law § 5-903 exposure); evergreen term with no exit |
| IP ownership | You own deliverables and your data; vendor keeps its pre-existing IP and tooling; feedback license is non-exclusive | Vendor retains a license to aggregated, de-identified usage data | Vendor owns your data or derivatives; vendor claims rights in your inputs; broad license to your confidential material |
| Data / DPA | GDPR Art. 28 terms; SCCs for EEA transfers; breach notice within 48 hours; data return within 90 days | Breach notice at 72 hours if the rest holds; subprocessor list on request, not attached | Stripping your right to instruct the processor; capping data-incident liability at the contract cap; no breach-notice obligation |
| Termination | Termination for convenience with 30 days notice; termination for cause with 30-day cure; pro-rata refund of prepaid fees | For-convenience at 60 days; cure period at 45 days | For-convenience for vendor only; termination for cause on the vendor's subjective determination; no refund of prepaid fees |
Thresholds assume a $20M to $100M ARR book. Rewrite the dollar figures against your last 90 days of inbound before you ship this.
A worked redline
Positions only matter when a reviewer can run them on live paper. Here is one clause, the way it lands in the queue and the way it leaves.
Vendor's draft (SaaS MSA, $75,000 ACV):
Vendor's aggregate liability under this Agreement shall not exceed the fees paid by Customer in the three (3) months preceding the event giving rise to the claim.
Playbook entry it trips: liability cap below 12 months fees, no data-breach super-cap. Tier 2 reviewer flags it, no escalation needed.
Redline back to the counterparty:
Vendor's aggregate liability under this Agreement shall not exceed the fees paid by Customer in the twelve (12) months preceding the event giving rise to the claim, provided that this cap shall not apply to liability arising from a breach of Vendor's data security or confidentiality obligations, which shall be capped at three (3) times the fees paid in the prior twelve (12) months.
The one-line flag a reviewer (or the AI) leaves in the margin:
Cap at 3 months is below our 12-month floor and folds data-breach liability into the general cap. Pushed to 12 months plus a 3x data super-cap per the LoL playbook entry. If vendor refuses the super-cap, escalate to Tier 3.
That is the whole loop: a position, a deviation, a redline, a flag. A contract manager runs it in minutes. The deal closes in two days, not two weeks, because nobody had to invent the number.
Where playbooks fail in practice
Three failure modes show up over and over.
Sales pressure on Tier 1. CRO has a quarter to close. Deal is $4,000 over auto-approve. Someone asks if it can "just go through" because the customer is strategic.
The playbook either holds or it does not, and the answer the first time is the answer forever.
Build a documented override path (GC approves in writing, logged in the CLM) so it is not silently broken in a Slack thread.
Fallback drift. Six months in, your team has accepted liability caps below the playbook floor on three deals in a row. The playbook still says 12 months fees. The executed portfolio does not.
Audit 20 executed contracts quarterly and either update the playbook or retrain the team.
Exception accumulation. The Tier 3 lawyer keeps a private list of vendors who "always negotiate that clause" and applies their own fallback. Within a year, the playbook is fiction and the lawyer's notebook is policy.
Surface every Tier 3 override into the quarterly review. If the same exception happens three times, promote it into the playbook.
Governance closes the loop. Name an owner (legal ops lead or senior in-house counsel). Quarterly review cadence. Off-cycle triggers: new state privacy law, board-level risk event, audit finding, single vendor type representing more than 15% of inbound volume.
The tooling layer
Tooling sits on top of the playbook. Three layers.
CLM. Ironclad, SpotDraft, and Lexion (now part of Docusign) are the options most in-house teams evaluate in 2026. The CLM owns intake, routing, redline tracking, signature, and storage.
Ironclad fits high-volume teams needing workflow customization. SpotDraft fits scaleup teams wanting template-driven self-serve for sales and procurement with legal as the exception path. Lexion fits teams wanting AI-native review baked in.
None defines your playbook for you. They enforce the one you wrote.


AI review. Use AI for first-pass review.
A first-pass AI reviewer reads the counterparty paper against your playbook entries and returns the deviations: cap below floor, missing data super-cap, auto-renewal with no notice window. It does the clause-spotting a contract manager would do, faster, so the human spends time on the judgment calls.
The gain is not in the most expensive product. It is in feeding the AI a written playbook with named fallback positions instead of a generic "review this contract" prompt. An AI with no positions just generates faster ad-hoc opinions, the same inconsistency problem a playbook exists to kill. Teams refusing AI in 2026 are not managing risk, they are paying a tax. For the mechanics of turning playbook entries into review prompts, see the contract-review skill setup and the broader AI contract review guide.
Ship AI into Tier 2, audit weekly, adjust the playbook when audits surface drift. For how this fits next to a stack-wide matrix view, see bulk review across a contract stack.
E-signature. Docusign or Dropbox Sign. The choice rarely matters. What matters is integration into the CLM, so executed contracts land with metadata intact instead of in a sales rep's email folder.
What actually changes after CLM rollout: intake-to-first-touch drops from days to hours, inbound NDA cycle time halves once Tier 1 templates land. Custom MSA cycle time barely moves, because the bottleneck was Tier 3 bandwidth, not the queue.
The common rollout misread is watching the cycle-time chart drop and concluding the team has 30% more capacity. The gain is in Tier 2. Tier 3 still owns the same week.
How to roll out in 60 days
Run by an in-house counsel or legal ops lead.
Days 1-14: write the playbook. Pull the last 90 days of contracts. Categorize by type and counterparty paper. Write the five-tier routing with calibrated thresholds. Write the eight contract-type entries.
Get GC sign-off. Tooling without a playbook is just faster ad-hoc review.
Days 15-30: pick the CLM. Demo two of three (Ironclad, SpotDraft, Lexion) against your contract types. The demo question: can your routing rules be encoded in the workflow engine without three months of professional services. Sign and configure.
Days 31-45: load the playbook into the AI layer. Playbook entries become the prompts and fallback positions. Run the AI against your 90 days of historical contracts. Compare its redlines to what your team did. Tune.
Days 46-60: cut over. Contract manager handles Tiers 1 and 2 with AI. In-house counsel handles Tier 3. GC sees Tier 4 weekly. Outside counsel sees Tier 5 by named engagement. Weekly retrospective.
By day 90 the queue is shorter, cycle time is faster, the contract manager owns more lanes, and the GC has stopped reviewing the cleaning vendor MSA at 9pm. The teams winning in 2026 wrote the playbook first and let the tool enforce it.
One thing to do this week: pull your last 90 days of executed contracts, audit ten of them against your current escalation path, and count how many were touched by the wrong tier. That is your baseline.
FAQ
What is a contract review playbook?
It is a written document that does two jobs: route each contract to the right reviewer by dollar value and risk, and name the preferred, fallback, and walk-away position on every recurring clause. The routing layer decides who handles what. The position layer decides what they accept, push on, and escalate. Together they make legal judgment reusable instead of re-litigated on every deal.
What is the difference between a contract playbook and a contract template?
A template is the document you send out (your standard MSA, your form NDA). A playbook is the instructions for negotiating it: which clauses are non-negotiable, what fallback language is pre-approved, and when to escalate. You need both. The template is your opening position, the playbook tells a reviewer how far to give.
What clauses should a contract review playbook cover first?
Start with the six that cause most of the fights: limitation of liability, indemnity, term and renewal, IP ownership, data and privacy (DPA), and termination. The clause-position table above gives a preferred, fallback, and walk-away line for each. Add contract-type entries (MSA, SaaS, reseller, employment, vendor security) once the core clauses are set.
What is a fallback position in a contract?
A fallback is the pre-approved compromise a reviewer can offer when the counterparty rejects your preferred clause, without asking anyone. Example: preferred liability cap is 12 months fees; the fallback is up to 24 months above $250K ACV; below 12 months is a walk-away that triggers escalation. Naming the fallback in advance closes the negotiation-experience gap between your reviewer and the vendor's rep.
How do you build a contract review process for an in-house team?
Pull your last 90 days of contracts, categorize by type and whose paper they sit on, then write a tiered escalation (auto-approve, contract manager, in-house counsel, GC, outside counsel) with dollar-plus-risk thresholds. Write the clause positions, get GC sign-off, then layer tooling (CLM, AI first-pass, e-signature) on top. The 60-day rollout earlier in this guide is the sequence.
Can AI do contract review against a playbook?
Yes, for the first pass. An AI reviewer reads the counterparty draft against your written positions and returns the deviations (cap below floor, missing data super-cap, auto-renewal with no notice). It does not decide your fallback for you; you still feed it the playbook. Fed a generic prompt instead, it produces fast ad-hoc opinions, which is the inconsistency a playbook exists to remove.
How often should a contract playbook be updated?
Quarterly at minimum, plus off-cycle triggers: a new state privacy law, a board-level risk event, an audit finding, or any single vendor type crossing 15% of inbound volume. Audit 20 executed contracts each quarter against the playbook floors. If the executed portfolio has drifted below the written positions, either update the playbook or retrain the team.
Who owns the contract playbook?
One named person: a legal ops lead or a senior in-house counsel. Shared ownership means no ownership, and the playbook rots into a private notebook of exceptions. The owner runs the quarterly review, promotes recurring exceptions into the playbook, and keeps the override log honest.
Run your playbook inside the review, not in a separate doc
A playbook in a Google Doc gets ignored under deadline pressure. The version that holds is the one the reviewer (or the AI) reads against live paper in the same place they redline. Vaquill AI is the legal AI workbench in-house teams use to do that: load your clause positions, run a first-pass review across the queue, and get the deviation flags with a citation back to the position they break. It is one honest fit among several. Pick the tool that puts your written positions where the review actually happens.
For related operational playbooks, see the Outside Counsel Guidelines Template, the DPA negotiation playbook, and the DPA Review Field Guide for In-House Counsel. To reuse the clause positions themselves, browse the clause library. For running review across a stack of contracts inside a single workbench, see bulk contract review with a document matrix.
New legal AI guides, weekly.
Further Reading
Legal AI for Chief Legal Officers (CLOs) in 2026
Read postRolling Out Legal AI to Your Team (Adoption Playbook)
Read postAI Compliance Check: CCPA, GDPR, and SOX for In-House Teams (2026)
Read postTop 10 GC AI Alternatives for In-House Counsel (2026)
Read postTop 10 Harvey Alternatives for In-House Counsel (2026)
Read post12 Best Legal AI Tools for In-House Counsel (2026)
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.