Skip to content
← Field notes
Rubric · Assessment

The Prevouched rubric: what we actually check.

Five weighted pillars, written pass bars, and a reviewer who has to defend the score. Here is what each pillar tests, where agencies most often fall short, and how to self-assess before you apply.

By · Guest expertAgencies9 min read

Directories sell placement. Marketplaces sell leads. Neither tells a buyer whether the team can do the work, which is why the buyer ends up re-running the whole evaluation themselves. Prevouched exists to do that evaluation once, publish the evidence, and stand behind it, which only works if the standard is written down where agencies and buyers can both read it.

The rubric has five pillars, each weighted, each with criteria that carry a written pass bar and a list of red flags. A reviewer scores against the bar and has to be able to defend the score. Below is what each pillar is really testing, and the failure mode we see most.

02

Craft and judgment: 25 percent

The largest weight, and the one agencies most often assume is about tooling. It is not. It tests output quality and idiom (does the work look like it was made by someone fluent in the medium), approach and tradeoffs (can the team explain what they chose not to do and why), verification and QA, peer review culture, and where necessary a live exercise.

The common failure is not weak output. It is an inability to narrate a decision. A team that shows good work but cannot explain the alternative it rejected scores lower than a team with plainer work and a clear reasoning trail, because the buyer is hiring judgment they will not be present to supervise.

03

Past-work review: 20 percent

Shipped artifacts, outcomes attributable to the team, engagement longevity, scope discipline, and IP and handoff hygiene. The word doing the work is attributable. Plenty of agencies show impressive products they contributed to in a way nobody can isolate. A reviewer needs to know which part was yours.

The frequent shortfall here is handoff hygiene. Repositories, credentials, documentation, and account ownership at the end of an engagement. Agencies that cannot describe a clean exit lose points, and rightly, because buyers who have been through a bad exit will not accept a vague answer twice.

04

Reference checks: 20 percent

Five criteria at equal weight: coverage, delivery against scope, communication under pressure, would-rehire, and candor of the reference set. That last one surprises people. A reference set where every call is uniformly glowing scores worse than a set including a client who describes a difficult period and how it was handled.

Uniform praise reads as curation. Reviewers are not looking for a flawless history, they are looking for a truthful one, because that is the only kind that predicts behaviour. The usual failure is coverage: references who are unreachable, out of date, or all from one engagement shape.

05

Communications assessment: 20 percent

Written clarity, working-language fluency, responsiveness and cadence, expectation-setting, and bad-news delivery. This pillar carries the same weight as past work, which reflects how engagements actually fail. Very few die from a technical inability. Many die because a slip was communicated late, softly, or not at all.

Bad-news delivery is the criterion agencies score worst on and prepare for least. A reviewer wants a real instance: what went wrong, when the client was told, in what words, and what was proposed alongside the bad news. "We keep clients updated" is not evidence of anything.

06

Operating baseline: 15 percent

Data handling, access controls, delivery workflow maturity, and contract hygiene. To be explicit about what this is not: it is not SOC 2 and it is not a formal security audit. It confirms the team handles client data, access, and contracts at a level a buyer can defend to their own security team.

The pass bars are concrete. A written data-handling policy that is followed in practice and survives questioning. MFA enforced, leavers off all systems within one business day. A change-control path making client-visible changes reviewed and reversible. Red flags include shared logins and former employees with live access, and those are found by asking, not by auditing.

07

Tiers, floors, and why the floors matter more than the score

Verified requires a composite of 70 with every pillar at 60 or above and no criterion below level 2. Backed requires 82 composite, all pillars at 70, and Past-work and References at 80, and adds a named Prevouched liaison on the engagement record. Managed requires 90, all pillars at 80, Operating baseline at 85, and clears legal review.

The floors do more work than the composite. They stop an agency from averaging its way past a weak pillar, which is exactly the failure mode a buyer cares about. A team scoring 92 on craft and 48 on communications is not a safe engagement, and a single composite number would hide that. Marks are point-in-time and revocable; the triggers are published alongside the rubric.

08

How to self-assess before applying

Read the rubric criterion by criterion and score yourself honestly against the pass bars, not against your intentions. Then look only at your lowest pillar, because the floors mean that is the pillar deciding your outcome. Fix the evidence gap there before you apply.

Practically, that usually means three things: writing down a decision-narrative for two recent projects, briefing three reachable references and asking one of them to be candid about a hard period, and putting dates on your security and handoff documents. Agencies that do those three things before applying tend to clear the review on the first pass.

Takeaways
  • 01Five weighted pillars: Craft 25, Past-work 20, References 20, Communications 20, Operating baseline 15. Each criterion has a written pass bar.
  • 02Craft tests the reasoning behind the work, not the tooling. A team that cannot narrate a rejected alternative scores lower than plainer work with a clear trail.
  • 03Candor is scored. A uniformly glowing reference set reads as curation and scores below one that includes a hard period handled well.
  • 04Operating baseline is not SOC 2. It checks data handling, access, change control, and contract hygiene at a level a buyer can defend internally.
  • 05Pillar floors matter more than the composite, so self-assess by fixing your weakest pillar before applying.
Questions this post answers

Related
Turn this into a shortlist

Get vetted. Get listed. Get the paper that survives the memo.

Twelve-minute intake, three-day turnaround. A passing scorecard is the shortest path from a good deck to a serious shortlist.