Document type: Guide Practice area: Technology — Technology Transactions Jurisdiction: United States Last reviewed: 5 September 2026
Step one: define the requirement in the units the market prices
The most common failure in infrastructure procurement is specifying the wrong variable.
For colocation, the requirement is:
- Committed power in kilowatts, not square feet or cabinets. Compute the number from actual equipment nameplate ratings, apply a realistic utilization factor, add growth, and state it as usable continuous load — not breaker capacity.
- Density per cabinet, which determines whether the facility can serve you at all. A facility rated for 5 kW per cabinet cannot host a 20 kW rack, whatever the total.
- Redundancy configuration required, expressed as the number of independent paths to the equipment and whether redundancy must be maintained during maintenance.
- Interconnection: which carriers, how many cross connects, which cloud on-ramps.
- Latency requirements to users, to other facilities, and to cloud regions, which constrain geography.
- Access requirements: who, how often, at what hours.
- Growth: capacity you will need in years three through five, and whether you need it in the same facility.
For cloud, the requirement is:
- Consumption by service, historical and forecast, at a granularity that lets you evaluate a discount.
- Instance types you depend on, including any with constrained availability.
- Data volumes, including transfer out and between regions — the line most forecasts omit.
- Regions required, and any data-location constraints.
- Services you would be unable to replace quickly, which is your real lock-in exposure.
- Support tier required by severity of your workloads.
Write the requirement down before speaking to a provider. Providers are excellent at reframing a requirement into the shape of what they sell.
Step two: run a process that preserves leverage
Infrastructure deals are won on leverage, and leverage exists only before you commit.
Talk to at least three providers, and mean it. A provider that believes it is the only candidate negotiates differently, and providers can tell.
Sequence the negotiation. Get commercial terms — price, term, committed capacity, discount — into a term sheet before legal review begins. Then negotiate the agreement. Reversing the order means negotiating legal terms with a provider who knows you have already chosen it.
Do not let the technical team commit. The single most common source of lost leverage is an engineer who tells the provider's solutions architect that the migration is scheduled for the following quarter. Providers reasonably conclude the deal is done.
Understand the provider's incentives. Colocation providers sell capacity that is expensive to build and idle until sold; a provider with vacancy in a facility will trade on price, and one with none will not. Cloud providers are compensated on committed spend and on adoption of particular services; a commitment that includes services the provider wants to grow is worth more to them than one that does not, and that is a lever.
Time it. Quarter and year end matter in this industry as much as any other.
Step three: negotiate power and capacity
This is the heart of a colocation deal.
Commitment. State the committed capacity in kilowatts of usable continuous load, and require the provider to warrant that the facility will deliver it to the customer's cabinets at the specified redundancy.
Measurement. Define whether power is billed on committed capacity, metered draw, or committed with metered overage. Reject provisions that bill both.
Overhead multiplier. If metered IT load is multiplied by a facility efficiency factor, get the factor disclosed, cap it, and require notice of any change.
Escalation. Separate the base rate escalator from the utility pass-through. Cap the base escalator at CPI or a stated percentage. Limit the pass-through to documented increases in the utility tariff, with an audit right.
Growth. Negotiate a right of first refusal on adjacent capacity, priced at the then-current contract rate or a stated formula, with a defined notice period. This is usually granted and is worth a great deal if you need it.
Reduction. If the business may shrink, negotiate a right to reduce committed capacity by a stated percentage on notice, once or twice during the term. Providers resist, but a limited flex right is achievable.
Step four: negotiate the service level
Read the SLA backwards, from the exclusions.
Define unavailability by reference to something the customer can observe. For colocation, loss of power at the customer's cabinets or environmental conditions outside the stated band. For cloud, the definition the provider offers, tested against how the customer would actually detect a failure.
Cap maintenance. Scheduled maintenance windows limited in number and total hours per year, with advance notice measured in weeks, scheduled outside periods the customer identifies as critical, and — for a redundant facility — a commitment that redundancy is preserved during maintenance, or that time spent on a single path counts as unavailability.
Constrain emergency maintenance. Require that it be genuinely emergent, reported promptly, and followed by a root cause analysis.
Define the demarcation point precisely, so that "outside our demarcation" cannot be asserted for a failure inside the facility.
Root cause analysis within a defined period, in writing, with remediation commitments.
Measure the credit. Understand what the maximum credit is in dollars and compare it with the cost of an outage. Then negotiate the remedy that matters:
Chronic failure termination. If availability falls below the commitment in a stated number of months in any rolling twelve, or below a floor in any single month, the customer may terminate without early termination charge, with a transition period at the contract rate. This is the provision that gives the SLA teeth, and providers grant it more readily than they grant a higher credit cap.
Step five: interconnection and access
Cross connects. Fix the price per connection for the term. Confirm carrier neutrality as a contractual obligation, not a marketing statement. Confirm which cloud on-ramps are available. Negotiate the right to use a third-party provider where technically feasible.
Access. 24×7, for a list the customer maintains and can update immediately, including contractors and vendors. Escorts available at all hours at a fixed rate or included. Emergency access without advance notice.
Suspension. Access may not be suspended except for non-payment of undisputed amounts after written notice to a named executive and a cure period, and in no event may the customer be prevented from removing its own equipment where undisputed amounts are current.
Remote hands. Response times by severity, rates fixed for the term, a defined scope of included tasks, and provider liability for its technicians' negligence in handling customer equipment.
Step six: the cloud-specific negotiation
Committed spend. Negotiate: shortfall roll-forward rather than forfeiture; satisfaction across all services, regions, and affiliates; a renegotiation trigger on a material divestiture; and survival of the discount on a change of control.
Price protection. Hold prices for services in production against list increases, with a mechanism to add newly adopted services to the protected set.
Egress. An allowance, a discounted rate, and — the item worth the most — waiver of egress charges for a defined exit window on expiration or termination.
Capacity. For any instance family the business depends on, a reservation, with a stated remedy if the provider cannot deliver.
Regions and data location. Where data is stored and processed, restrictions on movement, and notice of change.
Change of terms. No material adverse change to a production service without notice; twelve months' deprecation notice; and a right to terminate an affected service without penalty if a change is materially adverse.
Support. Response commitments by severity, escalation path, named contacts, and — for large accounts — a technical account manager.
Step seven: security, audit, and data
Certifications. Maintained throughout the term, with current reports provided, and notice of any lapse or qualified opinion.
Audit. Third-party reports plus an annual questionnaire is the workable position at scale. For regulated customers, add regulator access.
Incident notification. Within a defined period, with defined content, covering incidents affecting the provider's environment.
Legal process. Notice of any demand for customer data unless legally prohibited; efforts to obtain permission to notify; redirection of the requester to the customer where lawful; production limited to what is legally required; cooperation with the customer's efforts to quash or narrow; and no voluntary disclosure.
Data export. The right to export data in a documented format at any time, at a defined cost, within a defined period.
Return and destruction. Certified destruction of media and deletion of data on a defined timetable.
Step eight: liability
Understand the stack — credits as the sole SLA remedy, exclusion of consequential damages, and a cap on direct damages — and negotiate at the margins:
- Carve-outs for confidentiality breach, indemnities, gross negligence and wilful misconduct, and breach of security obligations.
- A supercap for security incidents caused by the provider's failure to meet stated obligations.
- Data loss liability where the provider failed to perform a backup or replication service the customer purchased.
- Insurance: confirm coverage and limits, obtain certificates, and seek additional insured status on general liability.
Then close the residual gap with the customer's own insurance. Contingent business interruption and system failure coverage exist precisely for this exposure, and buying it is usually cheaper than negotiating a cap the provider will not move.
Step nine: exit
Negotiate before signature. Afterward you have nothing.
- Renewal notice periods short enough to be a real decision, and calendared at signature.
- Early termination charges declining over the term, based on unrecovered capital, waived on chronic failure or provider change of control.
- A transition period at the contract rate — thirty to ninety days for colocation, longer for a complex cloud estate.
- Transition assistance at defined rates, with a documented data export format.
- Egress waiver for cloud.
- Equipment removal protected by an express carve-out from any lien.
- Certified data destruction.
- Survival of confidentiality, indemnities, and the transition obligations themselves.
Step ten: the provisions that protect you if the provider fails
- Characterization. For colocation, exclusive possession of a demised space strengthens the customer's position materially under 11 U.S.C. § 365 if the provider files. Where the deal is large enough, structure toward a private suite with defined boundaries.
- Non-disturbance from the provider's building landlord, and confirmation that the provider's own lease runs beyond the customer's term.
- Lien limits. Cap any provider lien, condition it on notice and cure, and carve out equipment removal.
- Escrow or step-in for critical services where available.
- Architecture. The most reliable protection is not contractual. A workload that can run in a second facility or region is protected in a way no clause can match.
Reading the provider's form: a triage order
Infrastructure agreements arrive as a master agreement plus schedules plus incorporated online policies, and the total can run to two hundred pages. A first read has to be triaged, because reviewing it linearly wastes the review on definitions.
Read first, always:
- The power or capacity schedule. What is committed, in what units, at what price, with what escalation.
- The SLA, starting with the exclusions. Then the definition of unavailability. Then the credit.
- The term and renewal provision. Length, auto-renewal, notice period.
- The exit provisions. Transition, egress, equipment removal, data destruction.
- The fee schedule in full, including cross connects, remote hands, change fees, and anything described as "as published."
Those five items carry most of the economics and most of the risk. A reviewer who reads only these has covered more ground than one who reads everything else.
Read second:
- Liability limitations and their carve-outs.
- Force majeure, with attention to how utility failure is treated.
- Access and suspension.
- Security obligations and incident notification.
- Any lien or security interest.
Read third: assignment, governing law, dispute resolution, notices, insurance, and the incorporated policies — which deserve attention not because their content is usually objectionable but because they are unilaterally amendable and should therefore be constrained by a change-of-terms provision in the master agreement.
A note on incorporated documents. Provider forms routinely incorporate by reference an acceptable use policy, a security policy, a support policy, a service description, and a data processing addendum, each posted online and each amendable at the provider's discretion. Print them, date them, and attach them as exhibits. Then negotiate a provision that changes to incorporated documents do not apply to the customer without notice, and that materially adverse changes give a termination right. Without that, the customer has signed a contract whose terms the other party can rewrite.
Getting the internal work right
Infrastructure negotiations fail internally more often than externally.
Assemble the team before the first provider meeting. Infrastructure or platform engineering owns the technical requirement. Finance owns the commitment model and the escalation exposure. Security owns certifications and incident terms. Legal owns the agreement. Procurement runs the process. Someone senior owns the decision.
Get finance to model the whole cost, not the headline rate. For colocation: committed power, metered overage, cross connects, remote hands, escalation over the term, and the early termination exposure. For cloud: compute, storage growth, egress and inter-region transfer, support tier, and the shortfall risk on the commitment.
Get security to review before you are committed. A certification gap discovered after signature is a problem the customer owns.
Make one person the single channel to the provider. Infrastructure providers are skilled at building relationships with engineers, and a well-run account team will know your migration timeline, your board's expectations, and your CTO's preferences long before your procurement lead intends them to.
Write down what you decided and why. Two years later, when someone asks why the commitment was sized as it was, the memorandum is the answer.
Governance after signature
The contract is the beginning of an operational relationship that will last years.
Build the obligations register. Every recurring obligation on both sides, with owners and dates: reports the provider owes, notices the customer must give, certifications to be refreshed, price reviews, capacity reviews, renewal notice deadlines.
Track the SLA yourself. Do not rely on the provider's reporting. Instrument your own monitoring, record incidents contemporaneously, and file credit claims within the contractual window. Most customers forfeit credits by not asking.
Run a quarterly business review with the provider. Capacity, incidents, roadmap, pricing, and anything the provider is deprecating. Attend with someone who can make decisions.
Watch consumption. Cloud spend drifts upward without anyone deciding it should. Storage lifecycle policies, unattached volumes, idle instances, and inter-region transfer are the usual culprits, and a quarterly review typically finds five to fifteen percent.
Re-verify the assumptions annually. Is the committed capacity still right? Is the redundancy configuration still what the business needs? Has the provider changed hands, changed its own landlord, or changed a policy? Has anything in the customer's regulatory position changed?
Start the renewal eighteen months out, or one renewal-notice-period plus six months, whichever is longer. A renewal negotiated under time pressure is a renewal at the provider's price.
Worked example one: a first colocation deal
Rasmus Lindqvist is CTO of Verity Payments, moving out of a closet in the office into a real facility. He has never negotiated a colocation agreement.
The requirement, built properly: 62 kW of usable continuous load, growing to roughly 95 kW by year three; maximum 12 kW per cabinet; 2N power with redundancy maintained during maintenance; four carriers plus two cloud on-ramps; sub-2ms latency to the primary cloud region; 24×7 access for six named staff plus a hardware vendor.
The process: four providers, a term sheet before legal review, and a deliberate decision not to tell any of them the target migration date.
What the negotiation changed from the provider's form:
The form quoted "20 cabinets at 5 kW." Rasmus's counsel converted this into a commitment of 62 kW usable, warranted at the cabinet, and discovered in the process that the quoted 5 kW was breaker rating — 4 kW usable. The deal as originally proposed was 20% short.
The SLA committed 99.999% with unlimited scheduled maintenance. Negotiated to four windows and eight hours a year, forty-five days' notice, none during month-end processing, and redundancy preserved throughout.
A chronic failure termination right was added.
Cross connect pricing was fixed for the five-year term.
The provider's lien on Verity's equipment was limited to ninety days' non-payment of undisputed amounts, with removal expressly permitted while current.
A right of first refusal on the adjacent cage was obtained, at the contract rate, exercisable on sixty days' notice — which is what will accommodate the growth to 95 kW.
The whole negotiation took seven weeks and moved the effective price by about 6%. The provisions that mattered were not about price.
Worked example two: the enterprise cloud renewal
Bettina Ohlsson is deputy general counsel at Aldergrove Health, whose three-year cloud commitment expires in eight months. Spend has grown from $11 million to $19 million annually.
What she does first is not read the contract. She asks finance for a consumption breakdown by service, region, and business unit, and asks the architecture team which services Aldergrove could not replace within six months. That analysis takes three weeks and reframes the negotiation: two services account for most of the lock-in, storage has grown 40% year over year with no lifecycle policy, and inter-region transfer is $1.4 million a year that nobody had ever looked at.
What she negotiates:
A commitment sized to the base case rather than the growth case, with roll-forward of shortfalls and satisfaction across affiliates — Aldergrove is acquiring, and the acquired entity's spend should count.
Price protection on the twelve services in production, with a mechanism to add new ones.
An egress waiver for a 120-day exit window, and a discounted inter-region transfer rate that will save more than the headline discount.
A capacity reservation for the instance family running the clinical imaging models.
Twelve months' deprecation notice for production services, and a termination right for materially adverse changes.
The regulated-customer addendum, which the provider did not offer and Bettina asked for: regulator access, subcontractor notice and flow-down, data location commitments, resilience testing with results provided, a documented stressed exit plan, and incident notification on Aldergrove's regulatory timeline rather than the provider's standard.
What she does not get: a higher liability cap. She closes that gap by adding a system failure extension to Aldergrove's cyber policy, which costs a fraction of what the negotiation would have.
Worked example three: the migration
Kwame Boateng is programme director for Steelyard Media's move from one provider to another, and the legal work is mostly about sequencing.
Before signing the new agreement, confirm the old one's exit terms: notice period, transition rights, egress costs, and whether any early termination charge applies. Steelyard discovers a twelve-month notice period on an agreement that renews in five months — which means the decision has to be made now or the migration slips a year.
Overlap. Both agreements will run concurrently for the migration period. Budget for it, and negotiate the new provider's ramp so that Steelyard is not paying full committed spend on capacity it is not yet using. A ramped commitment over the first six months is standard and is granted when asked for.
Data transfer. Egress from the old provider is the largest single migration cost, and the old agreement contains no waiver. Kwame's counsel negotiates one as part of the non-renewal discussion — the old provider would rather have an orderly exit and a preserved relationship than a dispute.
Reverse transition. The new agreement includes the exit provisions Steelyard wished the old one had, negotiated at the only moment they can be.
Verification. Before terminating the old agreement, confirm the data is out, complete, and usable; obtain certified destruction; and confirm final invoicing. Terminating before verification has cost more than one company a dataset.
The concessions providers actually give
It helps to know, going in, which asks are realistic. Based on how these negotiations typically resolve:
Usually granted, ask every time:
- Chronic failure termination right
- Caps on scheduled maintenance hours and advance notice requirements
- Fixed cross connect pricing for the term
- Right of first refusal on adjacent colocation capacity
- Access list maintained by the customer, updatable immediately
- Notice of legal process for customer data, and cooperation
- Third-party audit reports and annual security questionnaire
- Root cause analysis within a defined period
- Data export in a documented format
- Transition period at the contract rate
- Certified data destruction
- Ramped commitment during a cloud migration
- Deprecation notice for production services
- Shortfall roll-forward on committed spend
- Affiliate aggregation toward a commitment
Sometimes granted, worth pushing:
- Redundancy maintained during maintenance, or single-path time counting against availability
- Egress waiver for an exit window
- Capacity reservation for a specific instance family
- Price protection against list increases on production services
- Gross negligence carve-out from the consequential damages exclusion
- A security supercap
- Base rate escalator capped at CPI
- Utility pass-through limited to documented tariff increases, auditable
- Regulator access and the regulated-customer addendum
- Non-disturbance from the provider's landlord
- Lien limited and equipment removal carved out
Rarely granted, and usually not worth the time:
- A liability cap approaching the customer's actual outage exposure
- Uncapped SLA credits
- Removal of the sole-remedy language entirely
- Full on-site customer audit of a multi-tenant facility
- Termination for convenience without charge in a capital-intensive colocation deal
- Commitments about the conduct of other tenants
- Contractual protection against noisy-neighbour performance variance
The pattern is consistent: providers will give process, notice, transparency, flexibility, and exit — all of which cost them little and are worth a great deal to a customer — and will not give money-for-outages, which would require them to underwrite customers' businesses. A negotiation aimed at the first column succeeds. One aimed at the third consumes weeks and ends where it started.
When the answer is architecture, not contract
A recurring pattern in these negotiations is a customer trying to buy, through contract terms, a level of assurance that no infrastructure agreement provides.
The honest framing to give the business: the contract cannot make you continuous. It can make the provider transparent, give you notice, give you a remedy that changes the provider's incentives, and give you a way out. What keeps you running when a facility loses power is having somewhere else to run.
That reframing changes the procurement decision. A customer with a genuine continuity requirement should be buying two facilities or two regions and designing for failover, and should be spending its negotiating effort on the terms that make a second site affordable and a migration feasible — capacity growth rights, portable data formats, egress terms, transition periods — rather than on a liability cap it will never collect.
It also changes the budget conversation. A second site costs real money. A limitation-of-liability negotiation costs legal fees and produces, at best, a marginally higher cap on a remedy that will not approach the loss. Put the money where it works.
A short word about the paper nobody reads
Two documents in every infrastructure deal are signed without being read, and both matter.
The service description or product schedule. This is where the actual scope of what the provider will do is defined, and it is frequently drafted by a product team rather than a lawyer. Read it against the customer's requirement document line by line. Discrepancies found here are free to fix; discrepancies found in an incident are not.
The acceptable use policy. It governs what the customer may run, and breach of it is usually a termination event, often without cure. For most customers it is unobjectionable. For customers in adjacent-to-restricted businesses — security research, adult content, gaming, cryptocurrency, high-volume messaging, scraping — it can prohibit the customer's actual business. Read it, and if the business does anything the policy could be read to prohibit, get a written carve-out before signature rather than a reassuring email from a salesperson.
Provider financial health, and what to do about it
Data centre operators are capital-intensive businesses, frequently leveraged, sometimes owned by funds with defined holding periods. Cloud providers at the top of the market are not a credit concern; providers below that tier can be.
Diligence at contracting:
- Ownership structure and, where relevant, the sponsor's typical holding period
- Financial statements or, for a private operator, at least a bank reference and a credit report
- Whether the provider owns or leases each facility, and the term of any ground or building lease
- Existing mortgages or facility-level financings
- Whether the operator has sold and leased back its facilities
Contractual protections:
- Change of control notice, and a termination right if the acquirer is a competitor of the customer or fails a stated standard
- Non-disturbance from the building landlord, or at minimum confirmation that the provider's lease runs beyond the customer's term
- A covenant to maintain the facility's certifications and to notify on any lapse
- A right to terminate on a material adverse change in the provider's ability to perform, defined by objective triggers rather than a general standard
- Limits on the provider's lien over customer equipment
Operational protections:
- Keep an inventory of the customer's equipment in the facility, with serial numbers, so that removal can proceed quickly if it must
- Keep a current copy of every certificate, report, and notice the provider has given
- Keep the migration plan current — the difference between a nine-month scramble and a six-week move is whether somebody maintained the runbook
If the provider files. Under 11 U.S.C. § 362, the automatic stay prevents the provider from cutting power or denying access on account of prepetition debts, which buys time. Whether the arrangement is a lease of nonresidential real property or a services contract determines what happens on rejection, and the difference is between a statutory right to remain in possession and a prepetition damages claim. Counsel should know the answer before it matters, and the answer is influenced by choices made at contracting — a demised private suite with exclusive possession is a materially better position than cabinets on an open floor.
The one-page summary
Prepare it at signature and keep it current. It goes to infrastructure, finance, security, and the executive who will be woken up during an outage.
INFRASTRUCTURE AGREEMENT SUMMARY — [Provider] / [Facility or account]
What we have: [kW committed at [redundancy] / committed spend of $X over Y years]. What we pay: [rate and structure]. Escalation: [mechanism and cap]. Availability commitment: [%]. Excluded: [maintenance limits]. Credit: [amount, cap, claim deadline — put this deadline in the incident runbook]. Chronic failure right: [trigger and consequence]. Growth: [ROFR / expansion terms and notice]. Access: [who, hours, escort, emergency]. Term ends: [date]. Renewal notice due: [date — calendared]. Early termination charge: [formula]. Exit: [transition period, egress terms, export format, destruction]. Escalation contacts: [names, roles, numbers, 24×7]. Watch items: [the two or three provisions most likely to cause a problem]. Owner: [name]. Next review: [date].
The line that earns its place is the credit claim deadline, sitting in the incident runbook where the person managing an outage at 4 a.m. will see it. Credits are forfeited by process failure far more often than they are denied on the merits.
Common mistakes, in the order they cost the most
Buying square feet instead of kilowatts. The customer specifies cabinets, the provider prices cabinets, and nobody establishes usable continuous load. The deal is short from the day it is signed and the shortfall surfaces during a hardware refresh, when there is no leverage left.
Skipping the exclusions. A 99.999% commitment with unlimited scheduled maintenance is a marketing number. The exclusions are the commitment.
Ignoring the notice period. A twelve-month non-renewal notice on a three-year agreement means the decision must be made at month twenty-four. Customers discover this at month twenty-six.
Not modelling egress. In a cloud estate of any size, data transfer is a material line and the primary economic barrier to leaving. A customer that has never computed it does not know what its exit costs.
Letting the technical team commit. Leverage evaporates the moment a provider learns the migration is scheduled.
Treating incorporated policies as boilerplate. They are unilaterally amendable terms of the contract. Attach them, date them, and constrain changes.
Never claiming credits. A process nobody built means credits nobody collects.
Believing the contract provides continuity. It provides a remedy and an exit. Continuity is architecture.
Negotiating the liability cap instead of buying insurance. Weeks of legal time for a cap that will still be two orders of magnitude below the loss, when a contingent business interruption endorsement would have cost less and paid more.
Terminating before verifying. Confirm the data is out, complete, usable, and certified destroyed — then terminate. Not the other way round.
Multi-provider and hybrid estates
Most organizations of any size end up with a hybrid estate: some workloads in colocation, some in one cloud, some in another, plus SaaS. That has contracting consequences that a single-provider negotiation does not surface.
Interdependence. A workload split across a colocation facility and a cloud region depends on the interconnect between them, which is often a third contract with a network provider. When something fails, three providers will each point at the other two. The protection is a clear demarcation in each agreement, monitoring the customer controls at each boundary, and — practically — a named escalation contact at each provider who can be brought onto one call.
Inconsistent terms. Different agreements will have different notice periods, incident notification timelines, security commitments, and audit rights. For a regulated customer, the binding standard is the strictest one its regulator imposes, and every agreement in the chain must meet it. Maintain a matrix.
Data location across providers. A commitment that data stays in a jurisdiction is only as good as its weakest link, including backups, logs, and support access.
Aggregate exposure. Each agreement caps liability separately, and the aggregate of the caps is still far below the cost of a correlated failure. This is another argument for putting the money into insurance and architecture.
Renewal calendar. Staggered renewals across four providers with different notice periods is a governance problem in its own right. One calendar, one owner, reminders at notice-period-plus-six-months.
The organizations that handle hybrid estates well treat the contracts as a portfolio rather than a series of unrelated negotiations: one standard set of asks, one matrix of what each provider actually gave, one owner, and one renewal calendar. That is administrative work rather than legal work, and it is what separates an estate that can be reasoned about from one that can only be discovered during an incident.
What good looks like
A well-negotiated infrastructure agreement has a few recognizable features.
The capacity commitment is stated in the unit the customer actually consumes, warranted at the point of delivery, with a growth right. The escalation mechanism is separated into a capped base escalator and an auditable, documented pass-through. The service level defines unavailability in observable terms, caps maintenance, preserves redundancy during it, and carries a chronic-failure termination right alongside the credit. Cross-connect and consumption pricing is fixed or bounded. Access is 24×7 for a list the customer controls, and cannot be suspended without notice, cure, and a removal carve-out. Incorporated policies are attached, dated, and protected by a change-of-terms provision. Legal-process and data-export rights are express. Liability is capped, but confidentiality, indemnity, gross negligence, and security breach are carved out, and the customer has bought insurance for the rest. And the exit provisions — transition period, assistance, export format, egress terms, equipment removal, certified destruction — are in the agreement rather than in a hope.
None of that requires unusual leverage. It requires knowing which twelve provisions matter and asking for them in the eight weeks when asking is still possible.
One habit worth adopting
Keep a running file, per provider, of everything the provider has told you that is not in the contract.
The solutions architect's statement that the facility has never had a full outage. The account manager's assurance that egress is always waived on exit "in practice." The security engineer's answer about where support personnel are located. The slide showing four carriers when the contract names two.
None of it is binding. All of it shapes what the customer believed it was buying, and some of it turns out to be wrong. When a discrepancy surfaces — usually during an incident or a renewal — the file converts a frustrating conversation into a specific one: here is what we were told, on this date, by this person, and here is what the contract says. Providers respond to that. They respond much less well to a general sense of grievance.
The habit costs nothing. Save the decks, date them, and note who said what on which call. It is the cheapest leverage in the relationship.
Related documents
- Data center colocation and cloud infrastructure agreements: power, space, capacity, and the service you actually bought
- Data center agreement review checklist
- Infrastructure agreement toolkit: SLA schedules, power commitments, and exit provisions
- Responding to a software license audit: a practical guide
- Cloud and SaaS agreements: service levels, data rights, security, and exit