Skip to content

Home services and trades

Questions to ask any AI vendor before connecting your field service software

By SourceX Editorial · Updated

Short answer

Before connecting an AI vendor to ServiceTitan, Housecall Pro, Jobber or FieldEdge, ask twelve questions across seven areas: access scope, retention, training use, subprocessors, exit and audit logs, plus security. The decision rule: if a vendor cannot state in writing what it reads, where the data goes and how it is deleted, do not connect it.

Key takeaways

  • Grant the narrowest access a tool needs, and prefer read-only scopes unless write-back is the point of the tool.
  • A promise not to train on your data means little until you read the product improvement and aggregated data clauses.
  • Subprocessors, including outside model providers, inherit access to your records, so ask for the list.
  • Know how to revoke tokens, export outputs and confirm deletion before you sign, not after.

What should contractors ask an AI vendor before connecting?#

Contractors should ask an AI vendor what the tool will read, what it will write, where the data goes, how long it stays and how to get out. Those answers decide whether a call summary tool, an estimating assistant or a dispatch optimizer is safe to connect to the system that holds every customer, job and invoice you have.

Field service platforms connect outside tools through APIs, marketplace apps or a dedicated user account. Each route grants different access, and vendors do not always explain which one they use. The checklist below works for any route, including AI features built into the platform itself.

The twelve-question checklist#

The twelve-question checklist groups questions by area. Ask them in writing and keep the answers with the contract, because what a sales rep says and what the terms say do not always match.

A vendor does not need perfect answers on every row. Two red flags in access scope or training use, though, are usually enough to pause until the contract changes.

The twelve-question checklist
AreaQuestionA good answerA red flag
Access scopeWhich records will the tool read: customers, jobs, invoices, recordings, payments?A specific list tied to the feature you are buyingFull account access requested by default
Access scopeWill the tool write back to records, and which ones?Write access only where the feature needs it, with loggingWrite access to everything for convenience
Access scopeDoes it connect through an API token, a marketplace app or a user login?A named integration method with scoped permissionsA shared admin username and password
RetentionHow long do you keep our data and the outputs you generate?A defined retention period and a deletion processKept as long as needed, with no definition
RetentionWhat happens to our data in backups after deletion?Backups expire on a stated scheduleNo answer about backups
Training useDo you or your model providers train on our data?No, stated in the contract, including for product improvementOnly a statement on the website
Training useDo you use aggregated or de-identified data from customers?A clear definition and an opt-outBroad rights to aggregated data with no definition
SubprocessorsWhich subprocessors, including AI model providers, receive our data?A published list with notice of changesNo list available
SubprocessorsWhere is the data processed and stored?Named regions and hosting providersIt varies, with no commitment
ExitHow do we revoke access and get our outputs if we cancel?Token revocation, export of outputs and written deletion confirmationData deleted at the vendor's discretion
Audit logsCan we see a log of what the tool read and changed?Logs available to admins in the app or on requestNo logging of integration activity
SecurityWhat independent security assessment can you share?A recent audit report or a detailed security questionnaireA general statement that data is secure

Access scope: read, write and which records#

Access scope matters most because it decides how much of your company a tool can see. A call summary tool needs call recordings and the related customer and job; it does not need invoices, payment details or the price book.

Prefer integrations that use scoped API permissions or marketplace apps over tools that ask for a user login. A login usually carries everything that user can see, and if it is an admin account, that means everything. If a vendor needs an account, create a dedicated one with the narrowest role your platform allows, and never share an employee's credentials.

Write-back deserves its own review. A tool that adds job notes or tags is low risk. A tool that changes prices, creates invoices or edits customer records needs approval steps and a log.

Training use and retention: read past the headline#

Training use is where marketing and contracts most often diverge. A website may say the vendor does not train on customer data, while the terms reserve rights to use data for product improvement, analytics or aggregated insights. Read those sections and ask whether they cover your recordings, transcripts and proposals.

Ask the same question one level down. Many AI tools send text to an outside model provider through an API, and the vendor's agreement with that provider controls whether your data is retained or used there. Retention also covers outputs: summaries, call scores and drafted quotes are new records about your customers and need the same rules.

Published terms show how much these answers vary. Notion states that its LLM providers use zero data retention by default for Enterprise workspaces, while for other plans they retain customer data for 30 days or fewer before deletion, so the same feature can behave differently by plan. Zendesk's AI Services Addendum states that the customer is the sole owner of its service data, including AI input and AI output. Ask each vendor to point to the equivalent clause in its own terms, for your plan, rather than a general assurance.

Exit and audit logs: plan the end at the start#

Exit planning decides whether you can leave a vendor cleanly. Before signing, confirm each step below and who performs it.

Audit logs help while the tool is running too. A periodic look at what the integration read and changed catches misconfigured permissions early, before much call data has flowed somewhere it should not.

  • Revoke the API token or uninstall the marketplace app in your field service platform.
  • Disable any dedicated user account the vendor used.
  • Export outputs you want to keep, such as summaries, scores and tags.
  • Request written confirmation of deletion, including from subprocessors where the contract allows.
  • Check the audit log for any activity after the cancellation date.

Illustrative: a multi-branch plumbing company vets a call summary tool#

Illustrative: a fictional plumbing and drain company with several branches wants a tool that summarizes booking calls and adds notes to jobs. The vendor's demo is strong, and its sales rep says customer data is never used for training.

The COO sends the twelve questions. The answers show the tool asks for an admin login, keeps transcripts indefinitely and passes them to an outside model provider under terms the vendor cannot share. Its standard terms also reserve rights to aggregated call data.

The COO asks for a scoped marketplace integration, a defined retention period and contract language excluding training and aggregated use. The vendor agrees to the first two; the company runs a limited pilot at one branch and raises the third point again at renewal.

How SourceX approaches access to your systems#

SourceX approaches system access the opposite way from most software vendors: nothing is connected and nothing is shared during the initial assessment. The fit check collects metadata, such as which platform you run, years of history and record families, not files or credentials.

If a licensing project proceeds, the supplier controls exports, and each step of the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, needs the supplier's approval. Large datasets can stay in the company's own storage or ship on encrypted drives.

Frequently asked questions

Do these questions apply to AI features built into our field service platform?

Yes, though the answers come from your platform agreement rather than a new vendor. Built-in AI features may rely on outside model providers and may be governed by product terms or addenda that differ from your main contract. Ask your account manager which terms apply and whether each feature can be switched off.

Who in a contracting company should own AI vendor reviews?

Usually the COO or operations lead, with help from whoever administers the field service platform and, for contract terms, counsel. The owner should approve any tool that reads call recordings, payments or the full customer list. Keep one register of connected tools so nothing is forgotten when staff change.

What if a small vendor cannot answer the security question?

Small vendors may not have a formal audit report. Ask for a completed security questionnaire, details on encryption, access controls and incident response, and the names of hosting and model providers. Limit the tool's access to the records it truly needs until you are comfortable, and revisit at renewal.

Should we pilot an AI tool before signing a longer contract?

Yes, where the vendor allows it. Limit the pilot to one branch, one call queue or one job type, give the tool the narrowest access that still tests the feature, and agree in writing what happens to pilot data if you do not continue. Judge the pilot on your own records, not the demo account.

How is licensing data different from connecting an AI tool?

Connecting a tool gives a vendor ongoing access to live records so it can provide a service. Licensing is a defined transfer of prepared records under a contract that states permitted use, term and restrictions, with personal and confidential details removed first. Both need rights and privacy review, but the risks and approvals differ.

Sources

  • Notion's AI security page states that by default Notion and its AI Subprocessors do not use Customer Data to train any models, and that embeddings stored in vector databases are deleted within 60 days after a page or workspace is deleted. Source
  • Zendesk's AI Services Addendum states that, as between the parties, the customer is the sole owner of all Service Data, including Customer AI Input and AI Output. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify