Skip to content
Vetting rubric · v1.2 · Effective 1 April 2026

What an agency had to prove to carry the Prevouched mark.

The full, published specification. Five pillars, weighted criteria, evidence requirements, tier floors, and the conditions under which the mark is suspended or revoked. Written so a buyer can inspect a specific team, and so an applicant knows exactly what will be scored.

One rubric, four trades

Pillars, weights, pass bars and tier floors are shared. Only the artifact a reviewer asks to see changes with the trade.

Where a bullet in the evidence column differs by trade, the shared expectation is stated first, followed by a compact By trade row naming what stands in for it in each discipline.

SoftwareEngineering, product build, data & AI.MarketingGrowth, SEO, content, paid media, lifecycle.DesignBrand identity, UX & product design, research.Product & strategyPM-as-a-service, strategy, ops consulting.
Scoring scale

Five levels. One descriptor each.

Every criterion in every pillar is graded on the same five-level scale. Reviewers anchor each score to the descriptor and a reference example from the calibration set.

L0
Fail
Disqualifying evidence. The mark cannot be issued at any tier, regardless of the overall score.
L1
Below bar
Below the pillar's minimum bar. The team must fix the gap before we can issue the mark.
L2
Meets bar
Meets the published bar. The evidence is present and a reviewer can verify it.
L3
Strong
Clearly above the bar on substance, consistency, and how recent the evidence is.
L4
Exemplary
Best-in-class against the reference examples the reviewer panel scores from.

Critical-failure rule · Any criterion graded L0 blocks issuance at every tier.

Composite & tier floors

Pillar scores roll up. Tiers gate the mark.

Each pillar score is the weighted average of its criteria, normalized to 0–100. The composite is the weighted sum across pillars. Tier floors are published; the underlying calibration keys stay internal.

Tier
Verified
70composite ≥
What a buyer gets

For the buyer: the team met every pillar's minimum bar under reviewer inspection. Evidence is on file. Runs on the agency's own delivery process.

Floor

All pillars ≥ 60. No criterion below level 2.

Tier
Backed
82composite ≥
What a buyer gets

For the buyer: a named US-based Prevouched liaison joins your weekly call, reads the same updates you do, and is the escalation contact when something is off.

Floor

All pillars ≥ 70. Past-work and References pillars ≥ 80.

Tier
Managed
90composite ≥
What a buyer gets

For the buyer: Prevouched is inside the contract on the specific engagement, with defined obligations. Reserved for opt-in projects that pass legal review.

Floor

All pillars ≥ 80. Security pillar ≥ 85. Legal review gated.

01
Craft & judgment
25%
of composite
02
Past-work review
20%
of composite
03
Reference checks
20%
of composite
04
Communications assessment
20%
of composite
05
Operating baseline
15%
of composite
Pillar 01 · 25% of composite

Craft & judgment

We score judgment, not tool familiarity. Two senior reviewers from the relevant trade read the team's real shipped work and compare it against a set of reference examples the panel has scored before. Software agencies show code; marketing agencies show campaigns and reporting; design agencies show shipped files; product agencies show decision memos.

Reviewers
Two senior practitioners from the discipline; a third on split decisions.
On file
Reviewer notes, per-criterion score, artifact references, threshold pass/fail.

Clarity, structure, and idiomatic use of the medium. The work is legible to a peer reviewer without a walkthrough, and the moving parts have obvious seams.

Pass bar (Meets bar)

Consistently legible to a new reviewer. Structure has obvious seams. No load-bearing cleverness.

Evidence required
  • Read-only access to two shipped exemplars in the team's medium.
    Software
    Production repositories.
    Marketing
    Campaigns with brief, creative, and 90-day reporting.
    Design
    Deliverables (product surface, brand system, or research report) with source files.
    Product & strategy
    Decision or strategy artifacts (PRD, market-entry memo, ops playbook) the team owned.
  • One self-selected exemplar the team is proudest of, with reviewer commentary.
Red flags
  • The same scaffold copy-pasted across engagements with no adaptation
  • Assumptions and inputs left implicit where a peer would document them
  • Style and conventions change within a single deliverable

Choice of approach relative to the problem; explicit handling of failure modes and constraints; cost-of-change discipline.

Pass bar (Meets bar)

Decisions are defensible and reversible. Trade-offs are named, not avoided.

Evidence required
  • A rationale doc for one shipped engagement showing the options considered, not just the pick.
    Software
    Architecture write-up for one shipped system.
    Marketing
    Channel-mix rationale with the counter-options weighed.
    Design
    Design rationale for the surface, with alternates.
    Product & strategy
    Strategy memo laying out the options considered.
  • One call the team would now make differently, with reasoning.
    Software
    An architecture or implementation decision.
    Marketing
    A campaign that underperformed and what changed.
    Design
    A design decision, and what they'd revise.
    Product & strategy
    A recommendation, and what they'd revise.
Red flags
  • A single default approach applied to every engagement with no adaptation
  • No documented handling of the obvious failure modes for the trade
  • Abstractions or frameworks built before a second use case exists

How the team catches problems before the client does. QA appropriate to the trade — tests, tracking audits, design reviews, or evidence checks.

Pass bar (Meets bar)

Critical paths have checks that fail loudly when broken. Signal is trusted, not muted.

Evidence required
  • The checklist or automation that catches problems before the client does.
    Software
    Test coverage on one critical path, with rationale.
    Marketing
    Tracking-audit checklist.
    Design
    QA / review checklist used before hand-off.
    Product & strategy
    Assumption log and evidence-check practice for one engagement.
  • A recent record of that check working, not just its existence.
    Software
    CI configuration and last 30 days of run signal.
    Marketing
    One experiment log: hypothesis, ship, read-out.
    Design
    One critique or design-review record with resolved items.
    Product & strategy
    One post-decision review of a shipped recommendation.
Red flags
  • QA reduced to a superficial sign-off with no substance
  • Known-broken signals ignored rather than investigated
  • No systematic check on the outputs that drive client money

Whether work is reviewed by a second pair of eyes with substance, and whether authors are ever their own approvers.

Pass bar (Meets bar)

Reviews engage with substance. Disagreement is documented. Authors are not their own approvers.

Evidence required
  • A sample of recent peer-review activity across the team.
    Software
    10 recent PRs across the team.
    Marketing
    5 recent creative / copy approvals before launch.
    Design
    5 recent design-critique notes.
    Product & strategy
    Peer-review record on 5 recent strategy artifacts.
  • A named second reviewer for the high-stakes calls, with stated SLA.
    Software
    Review SLA and adherence.
    Marketing
    Named second reviewer on paid-media budget decisions.
    Design
    Named second reviewer on brand or IA decisions.
    Product & strategy
    Named challenger on major recommendations.
Red flags
  • Most work approved with only "looks good" and no substantive comment
  • No record of a reviewer blocking or requesting changes in the last quarter

Borderline cases only. A 60-minute pairing on a small, real problem in the team's trade; we watch reasoning, not speed.

Pass bar (Meets bar)

Practitioner states assumptions, validates them, and produces a working sketch with named trade-offs.

Evidence required
  • Reviewer transcript and rubric notes
Red flags
  • Will not explain their thinking out loud
  • Cannot adapt when the reviewer introduces an intentional ambiguity
Pillar 02 · 20% of composite

Past-work review

Screenshots and mockups are not evidence. We grade shipped work you can open, outcomes the team can prove they caused, and how long their clients stay.

Reviewers
One senior engineer plus one liaison.
On file
Case-study dossier, retention timeline, outcome scoring with sources.

Real, accessible work in the team's trade. Live URLs, repos, running campaigns with reporting access, published design systems, or delivered strategy engagements. Not mockups.

Pass bar (Meets bar)

Two reviewers can independently verify the team's contribution.

Evidence required
  • Three shipped deliverables from the last 24 months, each verifiable in the trade's medium.
    Software
    Live URLs, repos, or recorded walkthroughs.
    Marketing
    Campaigns or programs with brief, creative, and reporting access.
    Design
    Product surface, brand system, or research report.
    Product & strategy
    Strategy or PM engagements with the artifacts the client received.
Red flags
  • NDA cited as the reason no work at all can be discussed or shown under reviewer NDA
  • Only mockups or slides, no shipped artifact the client used

What changed because the team was involved. Numeric where possible, narrative where not.

Pass bar (Meets bar)

Outcomes are named, sourced, and tied to the team's actual work.

Evidence required
  • What changed because the team was involved, sourced.
    Software
    Before / after metrics or client-attested narrative.
    Marketing
    Before / after business metrics (pipeline, revenue, CAC) reconciled to the client's CRM — not just platform dashboards.
    Design
    Before / after user or business metric where measured; client-attested narrative otherwise.
    Product & strategy
    Decision-to-outcome trail: what was recommended, what shipped, what changed.
  • Identification of the team's specific scope on the engagement.
Red flags
  • Outcomes claimed by the team that happened before their engagement started
  • Percentage improvements quoted with no baseline number
  • Platform metrics (ROAS, CTR, impressions) presented as business outcomes

How long clients stay and why. Renewals and scope expansions count more than headline logos.

Pass bar (Meets bar)

Median engagement >9 months; renewals on at least two of the last five.

Evidence required
  • Engagement timeline for the last five clients
  • Renewal and expansion record
Red flags
  • Repeated short pilots (around six weeks) that rarely convert into longer work
  • Client departures cluster around one specific team lead

Evidence that the team can say no, re-scope, and protect the engagement from drift.

Pass bar (Meets bar)

Team can cite at least one engagement where they pushed back and the relationship survived.

Evidence required
  • One example of a refused or re-scoped request and the reasoning
Red flags
  • Every engagement grew in scope without ever re-negotiating price
  • No record of a difficult scope conversation with any client

Deliverables, documentation, and access transfer cleanly at engagement end.

Pass bar (Meets bar)

A non-author can stand the system up from the handoff alone.

Evidence required
  • A sample handoff package — everything a non-author needs to keep the work alive.
    Software
    Runbook, source, and access transfer.
    Marketing
    Creative source files, ad-account access, reporting, playbook.
    Design
    Source files, design tokens, component documentation, license notes.
    Product & strategy
    Strategy artifacts, decision log, follow-up plan.
Red flags
  • Credentials, files, or accounts withheld at engagement end to pressure renewal
  • No documented checklist for ending an engagement cleanly
Pillar 03 · 20% of composite

Reference checks

We speak with prior clients on the record using the same set of questions for every agency, and we keep the notes on file. References an agency cannot or will not provide are themselves a signal.

Reviewers
One liaison; second-listener on negative signal.
On file
Reference roster, call transcripts or structured notes, per-call scoring.

Number, recency, and seniority of references actually reached.

Pass bar (Meets bar)

Three reachable references within the last 24 months; two completed structured calls.

Evidence required
  • Three references contacted; at least two with decision-maker authority
Red flags
  • Only one reference is actually reachable
  • All references come from a single industry while the agency claims to serve many

Did the team ship what was promised, in roughly the time and cost they said?

Pass bar (Meets bar)

Majority of references confirm delivery on substance, with reasonable variance on time and cost.

Evidence required
  • Reference rating on delivery vs. scope, with examples
Red flags
  • Multiple references describe budget or timeline overruns that the team did not raise until after the fact

How the team behaved when something went wrong. Escalation speed, transparency, recovery.

Pass bar (Meets bar)

References can name at least one incident handled with proactive disclosure.

Evidence required
  • Reference recounting of one incident or near-miss
Red flags
  • References cannot recall a single difficult moment on the engagement
  • Long periods of silence followed by unexpected invoices

Two questions asked verbatim. Hesitations are scored.

Pass bar (Meets bar)

Unprompted yes from at least two of three references.

Evidence required
  • Direct quotes; pauses and hedges noted
Red flags
  • An initial yes that becomes a no once the reference is asked a follow-up question

Whether the references offered are willing to discuss weaknesses, not just strengths.

Pass bar (Meets bar)

Each reference identifies a real area to improve.

Evidence required
  • At least one substantive weakness named per call
Red flags
  • Every reference is uniformly positive, suggesting they were coached or hand-picked
Pillar 04 · 20% of composite

Communications assessment

Most offshore engagements break down on written communication before they break down on code. We test writing, calls, scope conversations, and how the team raises bad news.

Reviewers
One liaison.
On file
Writing sample, call recording, structured rubric.

A 500-word async update on a synthetic engagement scenario.

Pass bar (Meets bar)

Lede first, decisions named, asks unambiguous, no buried risk.

Evidence required
  • Submitted sample graded against the calibrated reference set
Red flags
  • Status updates that hide the actual blocker several paragraphs in
  • Long unstructured paragraphs with no headings, bullets, or clear asks

Functional English on the call, on the page, and under disagreement.

Pass bar (Meets bar)

Comprehension and expression are not the bottleneck of the conversation.

Evidence required
  • Live call segment; reviewer scoring
Red flags
  • Rehearsed answers that fall apart when the reviewer asks a follow-up question

Stated SLA for async response and adherence over a one-week observation window.

Pass bar (Meets bar)

First response within stated SLA on all three; substantive response within one business day.

Evidence required
  • Logged turnaround on three test messages across the window
Red flags
  • First reply is an emoji acknowledgement with no substantive follow-up

Can the team scope realistically and push back on a request that doesn't fit?

Pass bar (Meets bar)

Team narrows scope, names trade-offs, proposes a smaller first delivery.

Evidence required
  • Synthetic intake scenario; reviewer transcript
Red flags
  • Team agrees to anything the buyer proposes
  • Team quotes a price without asking a single clarifying question

How the team raises a slip, an overrun, or a quality issue.

Pass bar (Meets bar)

Issue stated plainly, with impact, options, and a recommended path.

Evidence required
  • Roleplay segment; reviewer notes
Red flags
  • Bad news softened with so many qualifiers the actual issue is unclear
  • News only surfaced after the client asks directly
Pillar 05 · 15% of composite

Operating baseline

This is not a formal security audit or a SOC 2 certification. We confirm the team handles client data, access, and contracts at a level a serious buyer can defend to their own security team.

Reviewers
One reviewer with infosec background; legal review on contract hygiene.
On file
Checklist, supporting documents, attestations on file.

Where client data lives, who can read it, how long it is retained, how it is deleted.

Pass bar (Meets bar)

Written policy exists, is followed in practice, and survives reviewer questioning.

Evidence required
  • Data-handling policy plus a sample DPA scoped to what the team actually touches.
    Software
    General DPA.
    Marketing
    DPA covering customer lists, ad-audience uploads, and CRM data.
    Design
    DPA covering research-participant PII and asset repositories.
    Product & strategy
    DPA covering interview transcripts and strategy documents.
Red flags
  • Client data copied onto personal laptops
  • No process for deleting client data when the engagement ends

SSO, MFA, least-privilege, joiner and leaver discipline.

Pass bar (Meets bar)

MFA enforced; leavers off all systems within one business day.

Evidence required
  • Least-privilege access to client systems, with a documented leaver checklist.
    Software
    Identity-provider configuration for the team's own systems.
    Marketing
    Delegated access to client ad accounts, analytics, and CRMs.
    Design
    Access to client design tools and asset stores.
    Product & strategy
    Access to client docs, dashboards, and interview archives.
Red flags
  • Shared logins used across the team
  • Former employees still have access to client accounts, ad platforms, or repositories

Change control appropriate to the trade. Who can change what, who approves, how a bad change gets rolled back.

Pass bar (Meets bar)

The path from a proposed change to a client-visible change is documented, reviewed, and reversible.

Evidence required
  • The change-control path that makes a client-visible change reviewed and reversible.
    Software
    Repository branch-protection rules, deploy pipeline overview, and rollback plan.
    Marketing
    Approval workflow for creative and paid-media budget changes; recovery plan for a bad launch.
    Design
    Versioned source files with branch / library governance; rollback for a published brand or system change.
    Product & strategy
    Versioned decision log with named approvers; process for revising a shipped recommendation.
Red flags
  • A single person can push a client-visible change with no second set of eyes
  • Manual edits to live client systems with no audit trail

A documented process, a recent test of it, and at least one post-mortem on file.

Pass bar (Meets bar)

Process exists, has been used, and led to a documented change.

Evidence required
  • IR runbook; one redacted post-mortem
Red flags
  • Team reports no incidents have ever occurred, which is not credible at their scale

MSA quality, IP assignment, subcontractor disclosure, insurance.

Pass bar (Meets bar)

IP cleanly assigns to the client. Subcontractors are disclosed. Insurance is current.

Evidence required
  • Sample MSA; certificate of insurance; subcontractor policy
Red flags
  • Ambiguity about who owns the delivered work
  • Subcontractors used but not disclosed to the client
  • Professional liability insurance has lapsed
Worked examples

How two real-looking applicants come out of the rubric.

Pillar scores below are illustrative. Composed from the actual weights and tier floors so the arithmetic is reproducible. Both applicants clear the L0 critical-failure rule.

Applicant A. Senior generalist studio

Even profile, strongest on references.

Applicant A. Senior generalist studio. Per-pillar score, weight, contribution, composite, and issued tier.
PillarScoreWeightContrib.
01 · Technical screen7825%19.5
02 · Past-work review8220%16.4
03 · Reference checks8820%17.6
04 · Communications7420%14.8
05 · Security & process7015%10.5
Composite78.8
TierVerified
Applicant B. Strong technical, weak operations

High technical score, security/comms gap.

Applicant B. Strong technical, weak operations. Per-pillar score, weight, contribution, composite, and issued tier.
PillarScoreWeightContrib.
01 · Technical screen9125%22.8
02 · Past-work review8420%16.8
03 · Reference checks8020%16.0
04 · Communications6220%12.4
05 · Security & process5515%8.3
Composite76.2
TierVerified
Reading the result

Applicant A composites at 78.8 and earns Verified. Applicant B composites at 76.2, above the Backed composite threshold. But the Communications and Security pillar scores sit beneath the Backed and Managed floors, so the panel issues at Verified with remediation on pillars 04 and 05 before a tier upgrade is considered.

How to read this page
If you are a buyer

You landed here from a badge or the directory.

This page tells you exactly what an agency had to prove to carry a Prevouched mark, and the events that will strip that mark. The five pillars each cover a way offshore engagements typically fail. The tier floors below show the minimum score required for Verified, Backed, and Managed.

If you are an agency

Read this before you apply.

Every criterion lists what we look at, the evidence you will need to produce, the bar you must clear, and the patterns that count against you. If most items describe how your team already works, the application will be quick. If not, the rubric itself is the gap analysis.

Shorthand used throughout: is the five-level scoring scale. is the weighted total across pillars, scored 0–100. is the minimum a pillar or composite must reach for a given tier. Hover, tap, or focus any dotted term for a plain-English definition.

Glossary

Terms used on this page.

Every dotted term below is also hoverable inline throughout the rubric. Written for readers who have never worked with a vetting scorecard before.

Disqualifying evidence on a single criterion.
Present but not sufficient. Must be fixed before the mark can issue.
The published minimum. Evidence is present and a reviewer can verify it.
Clearly above the bar on substance, consistency, and how recent the evidence is.
Best-in-class against the reference examples the reviewer panel scores from.
The minimum evidence a criterion must show to score L2 (Meets bar).
The weighted total score across all five pillars, on a 0–100 scale.
The minimum scores required to issue a given tier.
A single L0 score anywhere. Blocks the mark at every tier.
The share a pillar contributes to the composite. All five weights sum to 100%.
The share a criterion contributes to its pillar score. Criterion weights inside one pillar sum to 100%.
Reference examples reviewers score against so scores mean the same thing across teams.
A fresh review of the pillars affected by a change or complaint.
The annual confirmation that the evidence on file is still current.
The mark is not currently valid. Verification page shows Suspended until re-vetting concludes.
Re-attestation window closed without a submission. Directory listing is demoted.
The mark has been withdrawn. The agency may re-apply after a 90-day cooling-off period.
Revocation

A mark that cannot be taken away isn't trust.

The rubric is point-in-time. The status is live. These are the events that move an agency from Approved to Suspended, Lapsed, or Revoked. And the action Prevouched takes when each fires.

01
Quality-of-attestation event

A client complaint corroborated by evidence. Missed SLA, undisclosed subcontracting, material misrepresentation.

Action

Suspension within 5 business days pending re-vetting on the affected pillars.

02
Security or contract breach

Confirmed data incident, IP dispute, or material breach of the engagement contract.

Action

Immediate suspension. Revocation on confirmation. Directory listing removed.

03
Periodic re-attestation lapse

Annual re-attestation not completed within the published window.

Action

Status changes to Lapsed on the verification page. Directory listing demoted.

04
Reviewer-panel down-grade

Routine re-vetting returns a composite below the tier floor.

Action

Tier reduced or mark revoked. Agency may re-apply after a 90-day cooling-off period.

Calibration

Reviewers train on the same reference set.

Quarterly calibration sessions re-anchor scoring against shared exemplars at L1, L2, L3, and L4 in every pillar. Drift between reviewers is measured and tracked.

Appeals

One appeal per cycle, heard by a second panel.

An agency may contest a scoring decision once per vetting cycle. The re-review is conducted by reviewers who did not sit on the original; their score stands.

Changelog

Rubric versions are dated and preserved.

Each agency record states the rubric version it was issued against. A new rubric does not retroactively re-grade prior cohorts. Re-attestation does.