ERP implementation SOW confidentiality: what may a partner say?
Implementation MSAs and SOWs usually treat client business information as confidential, so an ERP consultant making a SourceX introduction should share only basic fit information, and only with the client's permission. Never share records, configurations or project documents. This is general information; confirm with counsel.
What is the short answer?
It depends on your contract, but the safe rule is simple: introduce, do not disclose. A typical implementation MSA or SOW defines "confidential information" broadly, and the client's data, processes and system configurations almost always fall inside it. An introduction needs none of that. It needs a company name, a rough size and a sponsor who has agreed to a conversation.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting, because your agreements may say something different.
What do implementation confidentiality clauses typically cover?
The wording varies, so read yours. These are common features, not a statement of what any specific contract says:
| Clause feature | What it usually means | Effect on a referral |
|---|---|---|
| Definition of confidential information | Business, technical and financial information disclosed or learned during the engagement | Project details are off limits |
| Permitted use | Only to perform the services | Using what you learned to assess licensing value is not performing the services |
| Permitted disclosure | Staff and subcontractors with a need to know, or as required by law | A third party like SourceX is outside it |
| Publicity or reference restriction | No naming the client as a customer without consent | Do not name the client in your outreach |
| Return or destruction | Materials returned at the end | You may hold no copy to share |
| Survival | Duties continue after the engagement ends | A finished project does not release you |
| Data processing terms | Personal data handled under written instructions | Processing for a new purpose is outside the instructions |
The Federal Trade Commission staff have stated that companies' promises not to use customer data for undisclosed purposes, such as training models, are enforceable. That is staff guidance, not a rule. The post is about AI companies' own commitments, not about consultants, but it shows why confidentiality promises are taken seriously.
What can you say in an introduction?
Think of a three-level ladder:
- Green: basic fit information, with permission. Company name, approximate headcount, years in operation, industry, the sponsor's name and contact.
- Amber: general observations, with permission. That the company runs an ERP and several other systems, without naming configurations or versions beyond what the client is happy to share.
- Red: never. Data, exports, screenshots, design documents, integration maps, pricing, internal issues, and anything learned under the engagement.
If you are unsure which level a fact falls under, treat it as red and ask the client.
How do you handle it step by step?
- Re-read the confidentiality and publicity clauses in the MSA and SOW.
- Decide whether you need your counsel's view; if the wording is unclear, you do.
- Ask the owner or CFO for permission to introduce them, in writing.
- Send only green-level details via the referral form or your referral link.
- Let SourceX run qualification, inventory, rights review and contracting with the client directly.
- Do not attend data discussions unless the client asks you to and your contract allows it.
Why is an implementation partner well placed anyway?
You know when a legacy system is being retired, which is the moment records are most at risk of being lost. You know the sponsor. You have credibility. None of that requires disclosing anything. The ERP AI agents guide explains why process histories matter to model builders, and the Infor records page shows how one ERP family's history looks. The consulting project archives question addresses your own firm's materials, which is a separate topic from introducing a client.
What about your own firm's materials?
Your project archives, templates and internal notes may include client information. Whether you can license any of it depends on your client contracts and ownership terms, which is a different decision. A work-product clause may give the client ownership of deliverables. Read those clauses before assuming anything.
What can you tell a client about your own firm?
When a client asks what you may disclose, the same ladder works in reverse. Statements about your own staff, rates and methods are yours to share. Statements about another client's project are not. Keep a short note in each engagement file of what the client has permitted, and when, so that a later introduction does not depend on memory.
Illustrative scenario
Illustrative: a fictional ERP consultancy finishes a distribution client's migration. In the closeout meeting the partner asks the CFO, using the permission script above, whether she would like an introduction. The CFO says yes, and the consultancy submits her name, the company's rough size and years in business. The consultancy shares no project documents and does not attend the later inventory calls.
How do rewards work, and do they raise a conflict?
Partners earn 25% of eligible platform fees SourceX actually collects, capped at $100,000 per referred company, and only after the buyer pays and SourceX receives its fee. No reward is guaranteed. Some consulting agreements restrict referral compensation or require disclosure of financial interests in recommendations. If yours does, address that before the introduction and disclose the arrangement to the client where appropriate. The rewards page describes the program side.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Naming the client in a case study | Likely breaches the publicity clause | Ask for written consent |
| Sharing a system screenshot "for context" | Discloses confidential configuration | Share nothing visual |
| Assuming the engagement ended the duty | Survival clauses apply | Check the term |
| Introducing through the project team | Staff may not be authorized | Go to the sponsor |
| Mentioning reward amounts to the client | Not needed and can mislead | Disclose the existence of the arrangement, if required |
Questions to put to your counsel
- Does our MSA treat the existence of the engagement as confidential?
- May we pass a client's name to a third party with the client's written consent?
- Do our professional rules or insurance require disclosure of referral rewards?
- Does any data protection addendum restrict how we describe the client's systems?
- Should the client confirm the permission on a letterhead or by email?
Next step
Check your agreements, then register as a partner. Use the network opportunity finder to list clients you might ask, and review who qualifies. Related pages include the ERP consultant referral page, the HubSpot solutions partner page and additional revenue streams for MSPs. Confirm with your own counsel before acting.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can I mention a client's name to SourceX?
Only with the client's permission and consistent with your agreements. Many MSAs restrict naming a client or disclosing the engagement. Ask the sponsor in writing first. If your contract is unclear, ask counsel. A company can also apply directly at sourcex.si/apply without you naming anyone.
Does an ended engagement release me from confidentiality?
Not necessarily. Many confidentiality clauses survive termination for a stated period or indefinitely. Check the survival language in your agreement, and ask counsel if it is ambiguous. Treat client information as confidential until you know otherwise.
Can I share the ERP vendor and version?
Treat it as amber. Name and version may be harmless in some contracts and sensitive in others. Ask the client, and do not share configuration details, integrations or customizations. If the client prefers, they can describe their own systems directly to SourceX.
What if the client wants me on the calls?
That is the client's choice and your contract may allow it. Stay at the introduction level, avoid describing records, and let the client's team and SourceX discuss inventory and scope. Never export or handle data on their behalf.
Is a referral reward a conflict of interest?
It can be, depending on your agreements and professional rules. Disclose the arrangement to the client where appropriate and check whether your engagement terms or professional body require it. This is general information, not legal, tax or financial advice.
Related pages
- AI agents for ERP: why process histories matter to model builders
- Infor CloudSuite and SyteLine data: what records fit a SourceX review?
- Can an implementation consultancy license its own project archives?
- SourceX referral rewards and payout conditions
- Map your network to potential US data referral opportunities
- Which US businesses are a fit for a SourceX data licensing introduction
Free resources
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- Referral earnings calculator — Hypothetical partner earnings with the per-company cap.
- Cash conversion cycle calculator — DIO, DSO, DPO and the cash conversion cycle.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment