MELISSA A. TULI Data & AI Exhibits Case study Contact
Contracts &
Legal Ops
CPCM · CPSM San Antonio, TX

Contracts that say yes to everything hold where the risk is real and give where it isn't.

I'm Melissa Tuli. 10+ years in contracts. I build legal and contract functions from the ground up, and I become the expert leadership trusts and depends on to make the call. My work spans federal contracting, construction tech, fintech, enterprise cloud and SaaS, and multi-unit operations.

Every company, client and counterparty name is redacted for now. The work is here in full.

Test 01 · InsuranceDoes it push liability past what we can insure?
Test 02 · RevenueDoes it erode the commercial premise of the deal?
Test 03 · PrecedentCan the rest of the portfolio live with it as the new floor?

Every ask I see goes through those three. A hard no on any of them and I hold. If all three clear, the room to negotiate is real and I treat it that way.

§ 1Recitals

How I got here

I've spent more than a decade in contracts. I started in contract administration, then moved to the buy side managing supplier and facilities contracts for a regional restaurant chain. Then enterprise SaaS and datacenter contracting at a global cloud and datacenter company through an IPO, where I learned what a contract portfolio looks like when it's large enough that one bad precedent spreads everywhere. Today I'm the person companies bring in when there's no contracts function yet and they need one that actually works.

What ties it together is one job: controlling material expansion. Liability creeps. Data rights creep. Scope creeps. A clause that looks harmless on one deal becomes the floor on the next fifty. My work is catching that early, explaining it in plain language to sales and leadership, and building the playbooks and systems so the same call gets made the same way whether I'm in the room or not.

WHEREAS I care more about the function outliving me than about any one deal; and WHEREAS I'd rather give a counterparty a clean yes on governing law in five minutes so I can spend three weeks on the indemnity that matters; NOW, THEREFORE, the rest of this page.

§ 2Engagements

Where the work happened, by industry

10+ years across four industries. Each one taught me what a different kind of risk looks like on paper.

Federal, public sector & construction tech

Director of Contract Management

Name withheld · Federal, state/local and commercial project management and SaaS

  • Built the contracts department from the ground up: intake, drafting, negotiation, and the governance that keeps a multi-vehicle federal and commercial portfolio accurate as it grows.
  • Led evaluation, procurement and implementation of the company's CLM platform. Wrote the templates, playbooks and triage board that sit on top of it, plus an automation that files every executed agreement to the right repository without anyone touching it.
  • Draft and negotiate enterprise SaaS MSAs, professional services agreements, federal subcontracts, task orders, teaming agreements, NDAs and JV agreements. Leadership's primary advisor on risk, liability and compliance strategy.
  • Own FAR/DFARS compliance: a 319-clause matrix, a compliance calendar, flowdowns, and the regulatory tracking that keeps federal vehicles in good standing.
  • Rewrote the SaaS platform's public legal stack when it launched AI features: Terms of Service, a new data rights and AI section, Privacy Policy, Information Security page and sub-processor disclosures.
Fintech & regulated financial services

Legal Operations Consultant

Name withheld · Fintech SaaS, fraud dispute resolution for banks and credit unions · Read the case study

  • Built legal operations from the ground up as the company scaled. The go-to expert for leadership, Sales and Finance on contract risk and deal strategy. Own legal ops end to end: contracts, intake, vendor and matter management, documentation, reporting and the corporate insurance program.
  • Built the MSA Deviation Playbook (18 provisions, three approval tiers plus Hard Stops) and the Deal Desk that applies it to every customer deal.
  • Built AI-assisted workflows with Claude that handle contract intake and first-pass playbook application, so review time goes to the deals that need it.
  • Negotiate data rights, AI/ML usage, DPAs and BAAs with regulated financial institutions, and flag third-party AI vendor risk anywhere it touches consumer financial data.
  • Track Regulation E, Regulation Z and consumer data-privacy guidance, and turn changes into template and position updates.
Enterprise cloud & SaaS

Supplier Manager III

A global multicloud leader, from hypergrowth through IPO

  • Full contract lifecycle across sales, product, finance, HR, marketing and datacenter operations: NDAs, MSAs, SaaS masters, SLAs, privacy and partner/reseller agreements.
  • Drove $20M+ in annual savings through term consolidation and partnership restructuring.
  • Consolidated contracts for acquired subsidiaries through the IPO transition. Owned the global purchasing policy.
Multi-unit restaurant operations

Contract Manager

Texas's favorite 2 a.m. burger stop (yes, that one)

  • Supplier and facilities contracts, sourcing and cost analysis across regional maintenance vendors. Standardized the PO and amendment process.
§ 3Data Rights & AI

Who owns the data, what the model sees, and what gets deleted

This is where most of my recent work has gone. Two very different settings: a construction-tech platform that needs aggregated data to power benchmarking, and a fintech platform whose customers answer to bank examiners. Same discipline, different pressure.

Construction tech & federal SaaS

Keeping the right to learn from data without owning anyone's secrets

Wrote the AI terms before the AI shipped

Drafted a new data rights and AI section for the platform's Terms of Service, updated the Privacy Policy and Information Security page, disclosed the LLM provider as a sub-processor, and built a gap tracker so IT and Finance could confirm every statement before it went live. Open items were named, not buried: a contractual no-training commitment from the model provider, a stated retention period, and which negotiated enterprise MSAs needed amending.

Drew the line on inputs, not outputs

An enterprise general contractor's GRC team wanted to restrict aggregation. Benchmarking only works if usage is combined across projects, so the right to aggregate stayed. The concession went where it actually cost nothing: no identifiable client data goes into models, and only aggregated, de-identified data comes out.

Separated two things everyone kept blending

Deleting data at termination and opting a project out of aggregation are different obligations with different costs. Kept them in different clauses so a fee attached to one couldn't leak into the other.

Found the back door in our own template

"Derivatives" in the confidentiality definition plus a return-on-request clause meant a client could demand destruction of aggregated analytics. Carved aggregated, de-identified data out of Confidential Information. Same review caught a survival clause that silently dropped the confidentiality and client content sections.

Promised only what engineering can do

Clients self-serve deletion of live data any time. Backups purge on the standard retention cycle. Before signing, I checked that the contract matched what the security team had already told the client in writing and what the Privacy Policy says.

Fintech · Banks and credit unions

Giving examiners what they need without becoming the bank's insurer

Data rights and AI/ML usage in regulated deals

Negotiate data use, AI/ML usage and privacy terms with banks and credit unions whose counsel drafts for their examiners. Every ask has a regulatory driver. The work is finding language that satisfies the supervisory interest without expanding our risk.

Third-party AI vendor risk

Flag and paper any AI vendor that touches consumer financial data, on both the customer and vendor side, so our commitments to banks and our vendors' commitments to us actually line up.

Breach notification that means something

48 hours from confirmation, with a reasonable-belief trigger and a preliminary report at day five. Pre-confirmation 24-hour clocks turn every SOC alert into a reportable incident and a paper trail of breaches that never happened.

SOC 2 Type II as the audit right

On-site audits of a multi-tenant platform expose every other customer. An independent Type II report is what examiners actually want to see, and experienced bank counsel accept it once the architecture is explained.

DPAs, BAAs and regulatory tracking

Own the DPA and BAA program and track Regulation E, Regulation Z and privacy guidance as it applies to dispute resolution, pushing changes into templates and standard positions.

Built reference · Data Rights & AI Playbook

The playbook I built for data and AI terms

A working reference for reviewing the data and AI provisions of any SaaS, services or platform agreement. It's written from neither side, so it works whether I'm the provider or the customer. Eleven parts, from vocabulary through a red-flag register and a one-page review checklist.

The one idea it's built on

Everything turns on one move: defining certain data as "not Customer Data." Once data gets relabeled as Aggregated Data, Derived Data or AI Output, it usually falls outside every deletion, return, confidentiality and ownership protection the customer negotiated. Follow the relabeling and you've found the heart of the deal.

Every data rights section is a ladder. Each rung grants more and risks more.

Tier 1 · Lowest riskService delivery

Use data to run, secure and support the service. Watch for "develop new features" tucked in.

Tier 2 · CommercialAggregated data

De-identified, combined across customers for benchmarks. Fine if both parts are real.

Tier 3 · Commercial+Derived data

Models, scores and insights, often with no multi-customer test. The most negotiated rung.

Tier 4 · Highest riskConsumer intelligence

Identifying data combined across institutions. Pulls in GLBA, FCRA and state privacy law. Never assumed.

Market positions from both seats, and where they usually land.

IssueProvider asksCustomer asksUsual landing
Derived data ownershipOwns all aggregated and derived data, including rights to commercialize and license itOnly truly de-identified, multi-customer insights; no single-customer commercializationProvider owns it, but anything commercialized externally has to pass the multi-customer test, and re-identification is prohibited
New AI featuresAdvance authorization for current and future AINotice and a real opt-out for any new automated-decision feature30-day notice plus a feature-specific opt-out that doesn't degrade the base service
Data security liabilityEverything inside the general capUncapped for data and confidentiality breachesSuper-cap at the greater of 12 months' fees or a figure tied to cyber insurance
Consortium intelligenceBroad license; customer carries GLBA and FCRA riskUS-only, fraud-and-dispute purpose only, named identity providerPurpose-limited, US-only, with an FCRA scope limit and separately signed authorization for identifying data

From the red-flag register: traps I look for in every draft.

High

Ownership that contradicts itself. Provider owns everything, then leftover "work for hire" language hands it to the customer. Template mash-up.

High

A sensitive right that only lives in an internal draft. If the signed version doesn't authorize the processing, nothing does.

Medium

An expansion dressed up as a "clarification." Recitals say "confirms," operative terms add training, commercialization and perpetual survival.

Medium

Silently uncapped data liability. Often the largest exposure in the deal, decided by what the cap doesn't say.

Also in the playbook: an ownership map across five asset types, what survives termination, sub-processor listing strategy and the "do not train" control, and a 20-point review checklist.

Data terms fail quietly. Nobody fights over a definition. Then two years later it means you can't use your own analytics.

§ 4Exhibits

The actual redlines

Two representative negotiations from my portfolio. Counterparties are anonymized, and figures and facts are changed. Each issue shows what the counterparty asked for, what we agreed to, and why. Tap an issue to open it.

The systems behind them

A redline is one deal. These are how the same judgment gets applied to every deal, by people who aren't me.

Exhibit C · Governance

Deal Desk Framework

Every customer deal, every size, goes through the desk. Seeing everything is the only way to tell a quiet drift from a loud outlier. Triage is binary and borderline deals never get the fast path.

FAST LANE · same day

Company paper, standard pricing, non-regulated customer, at most one Tier 1 fallback.

STANDARD · 24–48 hrs

Any regulated customer, Tier 2+ ask, custom paper, custom data or SLA terms. Tier 3 runs 3–5 days.

Six lenses on every deal. The first three are vetoes.

VetoInsurance
VetoRevenue integrity
VetoOperational feasibility
ShapesPrecedent risk
ShapesStrategic value
ShapesCustomer reasonableness
Exhibit D · Positions

Negotiation Playbook

Standard position, approved fallback, plain-language risk note and approval tier for each common deviation. Sales can act on Tier 1 alone. Everything else routes through Contracts before a word goes to the customer.

Tier 1Contracts, pre-approved fallback
Tier 2Contracts + Finance
Tier 3C-suite
Hard StopWe don't do this

Any approved language that isn't already in the playbook opens a revision ticket. Ad hoc language nobody writes down is the biggest governance failure in a SaaS contracts function.

Exhibit E · Procurement

Legal Technology Evaluation

Three contract AI / CLM platforms scored on weighted criteria, then the winner's own MSA run through buy-side review before signing.

Platform APlatform BPlatform C
AI reviewLLMRulesLLM
SOC 2Type IIType IIType I only
Renewal alertsYesYesNo
Exit / export30 days, assisted60 days, manual14 days, CSV
VerdictRecommendConditionalNot recommended

A Type I-only SOC 2 on the system that will hold every contract the company signs was disqualifying on its own.

Exhibit F · Execution

Deal Desk Build-Out Roadmap

The plan to stand the desk up without losing Sales' trust or creating a new bottleneck. Five phases, written exit criteria at each, a RACI, a risk register and a change management plan. 16–20 weeks to steady state.

01Foundation
02Pilot
03Rollout
04Tooling
05Steady state

Nine intake fields on every deal, Fast Lane included. Incomplete submissions go back to Sales.

§ 5Federal

FAR, DFARS and the vehicles that depend on them

On the government side the risk isn't a single counterparty. It's a clause you didn't flow down, a filing deadline you missed, or a status you lost without noticing.

Clause matrix

319 FAR/DFARS clauses sorted into a three-tier framework by what they actually require of the company, tied to a compliance calendar.

Flowdowns

Flowed new deviation clauses to subcontractors at the master subcontract level, where the relationships actually live, instead of chasing task order by task order.

Schedule mods

Finalized a GSA Multiple Award Schedule baseline modification after working through SIN mapping, EPA rate formatting and out-year pricing alignment.

Property & status

Drafted government property management procedures for DCMA under a defense IDIQ, and wrote the analysis for when the company qualifies as a nontraditional defense contractor and what would change that.

Small business

Redlined an SBA Mentor-Protégé joint venture agreement, and track proposed SBA size standard rules that could change eligibility.

Subcontractors

Audited the repository and found 24 contracts with no subcontractor records. Built a CMMC tracking template for the sub base. Standing rule: a subcontract never shows the prime's total value or ceiling.

§ 6Credentials

Certifications & education

Certified Professional Contracts Manager (CPCM), NCMAHeld
Certified Professional in Supply Management (CPSM), ISMHeld
AI Governance Professional (AIGP), IAPPIn progress
Master of Legal Studies, Texas A&M University School of LawIn progress
AAS, Paralegal Studies, Northeast Lakeview CollegeIn progress
BS, Business Administration, University of the Incarnate WordComplete
§ 7Execution

In witness whereof

This page constitutes my offer. If you're building a contracts or legal ops function, or you have one that needs to grow up, acceptance by email is effective on receipt. No consideration required.

By
Melissa A. Tuli
Title
Contracts & Legal Operations
Email
mtuli1105@gmail.com
Location
San Antonio, Texas · Remote

Résumé available upon request. Contact me!