Polestar Solutions

Field Notes

What we will not let the AI do on your deals

A procurement agent that invents a benchmark or leaks your number is worse than no agent at all. The guardrails: no figure without a source, agents draft and humans send, vendor text is never trusted, and everything is logged.

Key points

  • A fabricated benchmark repeated to a vendor and then retracted costs credibility for the rest of the negotiation, and one leaked walkaway figure can move a $2M deal by the entire gap between your target and your ceiling, easily six figures.

It may not state a figure without a source

The first and firmest rule is that no number reaches you without a citation. Every figure an agent produces is tagged back to the document or the benchmark cohort it came from, and answers pass a groundedness check before they are ever shown. When the underlying data is thin, the honest output is that the data is thin, not a confident number improvised to fill the silence.

This is not a nicety, it is the whole point of a procurement analyst. A benchmark you cannot trace is not a benchmark, it is a rumour with a decimal point, and a rumour you carry into a negotiation and cannot defend is worse than saying nothing. By refusing to state a figure it cannot ground, the agent stays the kind of colleague you can actually quote, because everything it tells you comes with its receipt.

app.isvcosell.com/ask

Every figure carries its source, and where the data is too thin, the honest answer is that it is thin, not an invented number.

THE SAME JOB, TWICE

TODAY, BY HAND

The analyst pastes contract text into a general purpose chatbot and gets a confident benchmark figure with no source attached.

That number, a rumour with a decimal point, goes into the deck and gets repeated to the vendor, where it cannot be defended.

A draft reply to the vendor goes out with the internal walkaway figure still in the second paragraph, because nobody scanned it.

Nobody checks whether the vendor's PDF carried text meant to steer the model that read it, and nothing the tool did was logged anywhere.

Seconds to get a number, and no way to know if it is real

WITH ISVCOSELL

Ask ISVCOSELL the same question: every figure comes back tagged to the document or the benchmark cohort it came from, and answers pass a groundedness check before you see them.

When the data is thin, read the honest answer that it is thin, instead of a confident guess you might repeat to a vendor.

Let the agents draft the reply, then send it yourself: the confidentiality scan warns you if a draft is about to expose your mandate, walkaway, or internal targets, without ever blocking you.

Rely on the enforced defenses: vendor authored text is wrapped as untrusted, the build fails if a feature skips the wrapper, and every agent action lands in the same audit trail as the human ones.

The same seconds, with a citation on every number and a human on every send

What changes: the risk profile, not just the speed. A fabricated benchmark repeated to a vendor and then retracted costs credibility for the rest of the negotiation, and one leaked walkaway figure can move a $2M deal by the entire gap between your target and your ceiling, easily six figures. The guardrails, no figure without a source, draft but never send, scan every outbound, trust no vendor text, are what make the fast answer safe to use.

PART TWO

It may draft, but it may not send

The second rule governs action. The agents prepare, they do not commit. The ghost writer drafts the reply to the vendor, the copilot whispers the fact during the call, the dossier assembles the package, and in every case a person makes the move that binds the company. There is no path where an agent emails a vendor, accepts a term, or sends a number on its own. Draft is a machine verb. Send is a human one.

And before anything drafted goes out, it is scanned for what it should not reveal. Outbound text destined for a vendor runs through a confidentiality check that looks for your own sensitive figures, your mandate, your walk away, your internal targets, and warns you if a draft is about to expose them. It never blocks you, because sometimes you mean to share a number, but it never lets you leak one by accident either. The judgment stays yours, with a second pair of eyes that never gets tired.

"Draft is a machine verb. Send is a human one. An agent that could email a vendor on its own would be a convenience you could not afford."

PART THREE

It may not trust what the vendor wrote

The third rule is about defense. Modern AI can be manipulated by the very documents it reads, a vendor proposal or an inbound email carrying hidden instructions meant to steer the model. So every piece of vendor authored text, proposals, emails, invoices, is wrapped and explicitly marked as untrusted before it reaches the model, and the system is instructed to treat it as data to analyze, never as commands to follow. An instruction buried in a vendor's PDF telling the analyst to ignore its rules is treated as exactly what it is: part of the vendor's document, not a directive.

This defense is enforced in the code, not just intended. The build itself fails if a new feature feeds document text to the model without the untrusted wrapper, so the protection cannot quietly erode as the platform grows. Custom instructions are screened before they are saved. The principle is simple: the buyer's agent takes its orders from the buyer, and from no one whose text happens to pass through it.

app.isvcosell.com/security

Vendor text wrapped as untrusted, outbound drafts scanned, and every agent action written to the same audit trail as the human ones.

THE LINES

Four things the AI will not do

1 Invent a figure. No number without a citation to a document or cohort, and an honest "the data is thin" instead of a confident guess.

2 Send on its own. Agents draft, people send. Nothing reaches a vendor without a human making the move that commits the company.

3 Leak your position. Every outbound draft is scanned for your own sensitive figures and you are warned before a number you meant to keep goes out.

4 Obey the vendor's paper. Vendor text is wrapped as untrusted and treated as data, never as instructions, enforced by a test that fails the build otherwise.

THE HONEST LIMIT

Guardrails are a discipline, not a boast

No set of rules makes an AI system perfectly safe, and we do not claim it. Groundedness checks can miss, scans are not omniscient, and defenses against a manipulated document are an arms race, not a solved problem. Every agent action, human and machine alike, lands in the same audit trail precisely because trust is verified, not assumed, and because you should be able to see exactly what was done on your behalf.

What we can say plainly is where the lines are drawn and why. The machines take the reading, the watching, the reconciling, and the first draft. People keep the figures they will defend, the messages they will send, and the signature that binds the company. An AI you can hand a renewal to is not the one that can do the most. It is the one whose limits you can name.

FF

About the author

Fredrik Filipsson, Cofounder, ISVCOSELL

Fredrik has spent more than twenty years in enterprise software, with time at Oracle, IBM, SAP, and Salesforce before moving to the buy side. He structured and priced the kind of large agreements most buyers only see once or twice in a career, which taught him where the leverage sits and how far a vendor will actually move. He started ISVCOSELL to hand that knowledge to every sourcing team.

More posts by Fredrik Connect on LinkedIn →

See it in the product

How benchmarking works → Browse the use cases → Every feature → Calculate your time saved →

FREE TRIAL · FULL PLATFORM · NO CARD REQUIRED

An AI analyst with guardrails you can name.

The free trial opens the benchmarking database, 1,483 vendors deep, plus the negotiation guides, playbooks, and talking points for your own renewals. No card needed, a corporate email is all it takes.

Start your free trial → Or decode a contract free, no account

Free for 30 days, no card needed. Your data stays isolated at the database, and you can export or delete it any time.

Watch it in action

ISVCOSELL: the three minute demo What discount should we expect? One question, every agreement

Browse the full demo library →

THE ISVCOSELL AI BRIEF · WEEKLY

The week in enterprise software buying, in one email.

What shipped on the platform, and the pricing and licensing moves worth knowing before your next renewal. One email a week, to your work address. Unsubscribe any time.

Subscribe

More in Field Notes

1,483 vendors, one method: how the benchmark library is built

A benchmark is only as good as the deals behind it and the honesty of how it is compared. How the library is built from modelled deal cohorts, normalized, placed in the right peer cohort, and graded by confidence.

Read

300 vendors, 52 weeks, one team: the renewal calendar problem

The average enterprise runs 300+ software vendors and every one of them renews. Why notice windows are where budgets quietly die, and how a renewal desk with AI agents turns the calendar from a threat into leverage.

Read

A calmer desk, and Main Apps where the work starts

The platform now wears the desktop look: warm paper, one interactive colour, and Main Apps folded into Home so your instruments live where you start.

Read

A live analyst in your ear: inside the call copilot

The vendor call is where prepared positions meet improvisation, and the rep does this every day. The live call copilot runs a whisper rail beside the conversation: live transcript, grounded prompts, and the exact fact you need at the moment the claim is made.

Read

Adobe ETLA vs VIP: seat reclaim, right-profiling, and the walk away

An Adobe ETLA renewal is decided before you discuss price, by how many seats sit idle and how many are over-profiled. How to reclaim the waste, right-profile the rest, and build the VIP walk away Adobe respects.

Read

Agent to agent: how the Agent Negotiation Protocol works

When a buyer's AI agent negotiates with a vendor's AI agent, someone has to keep the record straight. How the open Agent Negotiation Protocol handles identity, mandate, and a ledger neither side can rewrite.

Read

Want help putting this into practice?

Contact us to discuss your project.

Get in Touch