# A draft MSA for Ken to correct

*For Ken, via Dil. Written 2026-08-17. **Not legal advice, not been to a lawyer,
and not in force.** Strike through what is wrong and send it back.*

---

## Why you are reading a draft instead of your own document

Ken said he needed a day to write these. **A draft you can cross out is a shorter
day than a blank page**, so Dil asked for one.

⚠️ **Two things I could not do and did not fake.** I have never seen Customer
Agreement v5 — it is not in the repo and not published anywhere I can reach, so
these clauses are **not** extracted from it. And I am not a lawyer. What I *can*
be accurate about is **what the system actually does**, and every clause below is
written from that.

**Where each one came from:** the four exposures already identified on the launch
board, in the replies to *"MSA Needs To Be Reworked For Booked Solid"* — by the
people who found them, not by me inventing risks.

**There are four and you said two or three.** That is deliberate: crossing one out
is a minute's work, inventing a fifth is not.

---

## How to see them

They render on the real page, in the real layout, with the real button behaviour:

```
MSA_DRAFT_PREVIEW=true   in the server .env, then: pm2 restart q
```

Then open **`bookedsolidinspector.com/enroll.html`**.

> ⚠️ **While that switch is on, NOBODY CAN ENROLL.** The server refuses every
> checkout and shows *"Enrollment is paused while the Master Service Agreement is
> being reviewed."* That is deliberate — it means the draft can sit on the live
> page for you to read without a customer being able to agree to wording nobody
> approved. **Turn it off when you are done.** It is a review switch, not a soft
> launch.

You will also see a dark red **DRAFT — not in force** banner above the boxes. If
you can see the clauses and not the banner, something is wrong; tell me.

---

# The four clauses

## ☑ 1 · Service availability

> I understand that Booked Solid Inspector does not promise a specific uptime
> figure, and that if the service is unavailable my calls are forwarded to the
> backup number I provide during setup. I understand that if I do not provide a
> backup number, there is nowhere for those calls to go.

**Why it is worded that way.** This is §6.2 — the clause that is **blank** in v5.
The recommendation on the board, 10 August, was to name **no uptime percentage**:

> *"We have no uptime measurement at all, so any figure is one we could not defend
> and a client would hold us to. The agreement should describe **what happens** —
> calls transfer to a number you choose — rather than promise a number."*

**Everything it describes is real.** The failover was proven on 8 August against a
dead stream host: the call carried past the failed connection in **4 milliseconds**
and the second leg connected. The backup number is the one the client gives on the
onboarding form.

⚠️ **The second sentence is the important one and it is currently true of everybody.**
Neither Chad nor Ted has submitted an onboarding form, so neither has a backup
number recorded, so neither has failover. The clause makes that the client's
responsibility, which is fair — but it also means the setup checklist has to chase
it.

---

## ☑ 2 · Contact lists

> I confirm that I have permission to contact every person on any list I provide,
> that I am responsible for how those contacts were obtained, and that messages
> sent through Booked Solid Inspector go out under my name and on my behalf.

**Your own words on why**, from the 11 August spec:

> *"Damages run $500–$1,500 per message. A client uploading a purchased list of
> 5,000 contacts creates seven figures of theoretical exposure — sending under his
> name, from your infrastructure."*

⚠️ **This does not replace the tick-box at upload, and both should stay.** The
upload already blocks without an attestation and stores the wording, the file
name, the row count, the timestamp and the IP. Your own rule is that a dated
consent *at the moment of the act* is worth far more than one agreed months
earlier. This is the agreement-level half of the same protection.

---

## ☑ 3 · My number is mine

> I understand that my phone number remains mine. Service does not begin until the
> number has finished transferring to Booked Solid Inspector, and I can move it to
> another provider at any time by asking — we will release it within **[NUMBER OF
> BUSINESS DAYS]** and will not hold it against an unpaid balance.

**Two separate jobs in one clause.**

The first sentence prevents a billing argument nobody caused: carriers reject
ports routinely for clerical reasons — a name not matching their records exactly,
a wrong account number, a PIN never set. Without it the clock starts at signature
and runs through a rejection.

The second is the counterweight, and it matters more than it looks:

> *"Once a client ports his number in, it lives in our Telnyx account and he
> cannot un-port in an emergency — that takes days. So a clear port-out clause is
> not a courtesy, it is what makes the port-in reasonable. **A vague port-out
> clause is the strongest single argument a client has for never porting in.**"*

⚠️ **`[NUMBER OF BUSINESS DAYS]` is yours to set.** How a port-out actually runs is
documented in `resources/procedure-port-out.md`. How fast we *promise* to release
is a commercial decision, not a technical fact, so I left it blank rather than
guess.

---

## ☑ 4 · Calls are recorded

> I understand that calls answered on my behalf are recorded and transcribed, that
> callers are told this at the start of every call, and that the recording and
> transcript are attached to the job record. Recordings are kept for **[RETENTION
> PERIOD]** and are available to me and to Booked Solid Inspector staff supporting
> my account.

**This one was not on the board and I think it belongs in the agreement.** From
the same reply:

> *"Josh now tells every caller the call is recorded, and the E&O application
> requires the recording and transcript attached to the job. That means sensitive
> customer audio in our systems, which is a data-breach exposure the policy has to
> cover and the MSA has to describe — retention period, who can access it, what
> happens to it when a client leaves."*

**The recording notice is real and verified** — it opens 25 of the 28 calls
reviewed today (the other three were cut off by the caller), and a test pins it.

⚠️ **`[RETENTION PERIOD]` is yours.** Telnyx keeps recordings 12 months; what *we*
promise a client is a different question.

⚠️ **And I have deliberately not said the two-party-consent question is answered.**
Josh announcing the recording at the top of every call is the strong position, but
whether that satisfies every state a client works in is for counsel — and it is
already on the list for the LegalZoom lawyer alongside the AI-disclosure question.
**Do not let this clause imply it has been settled.**

---

## What to send back

Any of these is a complete answer:

1. **"Clause 3 is wrong, here is the right wording"** — I paste it in.
2. **"Drop clause 4"** — deleted.
3. **"Here is the real MSA, use these three"** — best outcome, and it takes the
   guesswork out entirely.

⚠️ **And there is a second thing you owe that is easy to miss.** Your own 11 August
spec says:

> *"A checkbox pointing at a 404 is worse than nothing — it proves the client
> couldn't have read it."*

**Right now there is no MSA published anywhere.** `bookedsolidinspector.com/msa.html`
returns the marketing homepage, which is exactly that case. So it is **two things,
not one**: the clause wording, **and** the agreement itself at a real URL for the
boxes to link to. Send me the document and I will publish it.

---

## What happens when you approve it

Three deliberate steps, so this cannot become live by accident:

1. The approved text moves **into** `MSA.clauses` — the array customers are
   actually bound by. The draft file is not it.
2. `version` is set to that date.
3. `MSA_DRAFT_PREVIEW` goes off and the guard test is deleted.

Until all three happen, nothing binds anybody. **Leaving the preview switch on is
not shipping the agreement — it is leaving enrollment switched off.**

---

*Code: `api/enroll/msa-draft.js` (the clauses), `api/enroll/acknowledgments.js`
(the gate). Eight tests cover it, including one that fails if a draft is ever
accepted and one that fails if somebody fills the real array without approval.*
