The most common way an implementation goes wrong is not a technical failure. It is that nobody can say, at any given moment, what has been agreed, what is being built, and what would happen if they said stop.
The cure is not a bigger contract. It is a shape: six phases, each ending in something you can hold, each closed by a signature, and three rules that apply to all of them.
Why phases
A phase is a unit of work small enough to accept or reject on its own. Its output exists as a document or a configured environment, not as a percentage on a status report. You read it, you sign it, and only then does the next one start.
That does three things for you. You always know where the money went, because nothing later is built or invoiced while an earlier phase is open. You can stop at the end of any phase and keep everything accepted so far. And each phase asks you for a specific, bounded contribution, so your team's time is spent on decisions rather than on chasing.
The six, and what you hold after each
Map. We record how the agreed workflows run today: systems, owners, handoffs and where work stalls. You hold a current-state map of the agreed workflows. You gave us time with the people who run the work and an honest account of how it moves, rather than how it is meant to.
Design. We decide, with you, what stays, what connects, what is replaced, who can do what, and what will be built. You hold the Blueprint: architecture, access, scope, responsibilities, exclusions and what done looks like. You gave us the decisions on which systems stay or go, and a named owner for each workflow.
Deploy. We configure the agreed workspaces, applications, permissions and operating structures. You hold a configured environment for the agreed scope, recorded as built. You gave us admin approval and the accounts and licences it depends on.
Migrate and connect. We move the agreed data, connect the systems and build the integrations in scope. You hold a record of what was moved, what was connected and which checks were run. You confirmed the data in scope and signed off the checks for each move.
Operationalise. We switch on the live workflows: queues, approvals, dashboards, alerts and escalation paths. You hold live workflows documented as configured. You gave us the operating rules, approval limits and escalation contacts your team wants applied.
Handover. We hand over access records, architecture maps, procedures and training. You hold a handover pack with the acceptance evidence for each phase. You named the owners who take it, and made a written decision on whether any recurring managed layer continues.
The three rules
Each phase waits for the last. Nothing later is designed, built, scheduled or invoiced while the phase before it is open. This is what makes the phase boundary real rather than decorative.
Sign-off is written down. A phase closes when you have read its output and accepted it in writing. Silence never counts. Neither does work that has already started on the next phase.
You can stop at the end of any phase. Everything accepted to that point stays with you, documented. No phase obliges you to commission the next. This rule is the one that makes the other two worth having, because it means the signature is a real choice.
What a signature should be attached to
A sign-off is only as good as the thing it signs. The Blueprint at the end of the Design phase is the best example. It should record, for each step of each workflow in scope, the system of record, the accountable owner, what is handed off and to whom, what is recorded, and what has to be true before the next step starts.
Worked example. The business, people and systems shown are fictional. A brokerage's enquiry-to-close flow, written this way, is six rows. Enquiry capture: a shared intake record, owned by the operations coordinator, moves to qualification once the required fields are complete. Qualification: the opportunity record, owned by the commercial lead, moves to case preparation with the decision and its reason recorded. And so on to closure, where the closure reason is present and the case reconciles against the finance record before it reaches the weekly review.
Read that table and you know what you are signing. Read a slide that says "phase two complete" and you do not.
What stays yours
The phases exist so that the result is an operating backbone your own team can understand, run and change. Systems you kept stay yours and stay the system of record for their work. What was built was documented as it was built, not reconstructed afterwards. Components built where no suitable system existed are handed to your team on the terms of the accepted scope.
How far that reaches depends on the scope you accept. It is a delivery approach, not a standing promise, and what is built and handed over on any engagement is set by the proposal or contract you sign. But the shape is the same every time: six phases, a signature on each, and the option to stop.
Where to start
The way in is the free Operating Infrastructure Audit, which reads the picture you describe and says whether a paid Blueprint is worth commissioning. The sample Blueprint on this site shows the full shape of the Design-phase output, with every business, role and system invented, so you can judge the format before you commission one.
The example is invented to show the shape of the record. It describes no client and no delivered work.