Skip to main content
Tretanz Infotech

Agency Partnership

White label MSA, NDA, and IP: what agencies must get in writing

This is not legal advice. It is the operational paper agencies should have in place before a white label development partner sees a client name, a Figma file, or a repo. Cover NDA timing, MSA versus SOW, IP assignment, credentials, subcontractors, and the clauses that protect margin and brand.

Agency team discussing white label msa nda ip for agencies

If a white label partner starts work on a handshake, you do not have a partnership. You have a hope. The client will still treat your agency as the contracting party. Hosts and app stores will look at who paid, who has the login, and whose name is on the repository—not at the Slack thread that promised a contract later.

This article is an operational checklist, not legal advice. We are not your counsel. Have a lawyer licensed in your jurisdiction review anything you sign. What follows is the paper agency owners and delivery leads should insist on so the commercial relationship matches how white label development actually works.

Paper does not replace diligence. Use how to vet a white label development partner to decide whether someone is fit to receive work. Use this checklist to decide whether you are allowed to send them work. Those are different jobs.

If you already know you want branded delivery behind your agency, a white label development partner for agencies should be willing to put NDA, MSA, IP, and SOW language in writing before the first brief lands. Reluctance here is information.

Treat paper as brand risk, not admin

Your client hired your agency, not a network of subcontractors. When a launch slips, a staging URL leaks, or ownership of a plugin is disputed, the conversation lands in your inbox. Paper is how you decide in advance who can speak, who owns the files, and who pays to fix a defect after go-live. Agencies delay it because the pipeline is hot. That is exactly when it matters: a pilot still exposes names, brand files, and credentials.

If you cannot point to a signed assignment of IP and a written change process, you do not have a white label model. You have a freelancer with extra steps.

— Agency partnership operating principle

The three documents and what each is for

Agencies often ask a partner to “send a contract.” That request is too vague. You want three instruments that do different jobs. Mixing them into one messy PDF is how SOW scope fights become MSA fights, and how IP language gets leftover in a statement of work that expires.

NDA, MSA, SOW — who owns which job

DocumentJobWhen to signTypical failure if missing
NDA (mutual)Stop names, files, and pricing leaking during evaluationBefore you share a client identity or a real briefPartner lists your client as a logo; you cannot prove harm
MSA / master servicesRelationship rules: IP, liability, insurance, subcontractors, terminationBefore any paid work, including a paid pilotEvery project renegotiates fundamental rights
SOW / work orderThis project: scope, fee, dates, revision rounds, acceptanceBefore kickoff of that project or retainer period“We thought that was included” becomes your margin

Keep the MSA stable. Put the variable commercial terms in the SOW. If you change IP assignment per project, you will forget which client’s work is actually yours. If you put unlimited liability in every SOW, you will stall every kickoff while someone “checks with legal.”

NDA: sign it before names, not after the deck

A capabilities call does not need an NDA. A conversation that includes a client’s industry, pipeline, or a confidential Figma file does. The operational rule is simple: if you would be embarrassed to see the information in the partner’s public case studies, do not send it until a mutual NDA is signed.

What the NDA must actually cover

NDA operational checklist

  1. Mutual confidentiality—your agency’s clients and the partner’s methods both matter
  2. End-client identities, briefs, designs, credentials, and commercial terms listed as confidential
  3. A clear purpose: evaluation and, if engaged, performance of services for your agency
  4. No public case studies, logos, or “worked with” claims without your written consent
  5. Return or destruction of materials if you do not proceed
  6. A survival period long enough that a launch six months later is still covered
  7. Standard exclusions (public information, independently developed, legally compelled) so the document is signable

One-way NDAs that only protect the partner are a tell. You are the party introducing client relationships. If they will not protect those names, they are not a white label partner. They are a vendor shopping for logos.

MSA: lock the relationship rules once

If how white label development works is the operating manual, the MSA is the permission structure. Process without paper still leaks: a helpful developer joins the client Slack “just this once,” and now your partner has a relationship you do not control.

Clauses agencies should insist on seeing

MSA topics that belong in writing

TopicWhy it is operationalWhat “good” looks like in practice
Status as subcontractorStops the partner selling around youNo direct solicitation of your named clients for overlapping services during the term plus a defined tail
White-label / non-disclosure of roleProtects your brand in client channelsPartner staff use your tools and emails only as you specify; no partner branding in deliverables
Point of contactStops five people briefing five peopleNamed relationship owner on each side
InsuranceYour client’s MSA may flow this downPartner carries commercial general liability and cyber/professional cover at levels your counsel sets
TerminationYou must be able to exit a bad fitTermination for convenience with a notice period, plus termination for cause; prepaid unused retainer handled
Governing law / venueDisputes are expensive when venue is a surpriseA jurisdiction both sides can actually use—not a default in a country where you have no counsel

Non-solicit language should be specific. A ban on ever hiring anyone who touched a ticket is often unenforceable and always hostile. A term about not soliciting named end clients for overlapping delivery, for a reasonable tail, is a business point counsel can draft. If a partner will only sign their paper, read it as if you were the client: refuse unlimited liability, a claim on your internal tools, or a right to publicize the work.

IP assignment: the client paid you, so you must own the work

This is the clause agencies skip and then panic about at handoff. Your client contract almost certainly says they own custom work they paid for, or that you assign it on payment. If your partner never assigned it to you, you may be selling rights you do not have. Operational target: upon full payment for a SOW, custom deliverables are assigned to your agency (or onward to the client—counsel picks the chain). The partner keeps pre-existing tools. Third-party software stays under its own licenses. That split is normal. Keeping custom client code after you pay is not.

IP operational checklist

  1. Written assignment of custom code, design implementations, content models, and documentation to your agency on payment
  2. License back to the partner only if needed for their internal tools—not a surprise retained interest in the client site
  3. Pre-existing materials listed or defined so you know what is not assigned
  4. Open-source and third-party components disclosed; you get enough license rights to run and maintain the site
  5. No partner claim to your agency brand, client lists, or briefs
  6. Moral-rights waivers where your jurisdiction cares about them
  7. Work-for-hire language only if counsel says it fits—do not assume a US phrase works everywhere

The U.S. Copyright Office circular on works made for hire is a public primer on a US-specific phrase—not advice, and not a worldwide magic spell. Have counsel write the assignment that matches where the work is actually performed.

Credentials, repos, and who holds the keys

IP on paper is worthless if the partner’s personal GitHub owns the repo and the hosting invoice is in a freelancer’s Gmail. White label operations need a credential policy that matches the MSA.

  1. 01

    Agency-owned accounts by default

    Hosting, domain, CMS, app stores, analytics, and error tracking live in accounts your agency (or the client, via you) controls. The partner gets least-privilege access.

  2. 02

    Repositories under your org

    Create the repo in your GitHub/GitLab org. Invite the partner. Do not accept “we’ll transfer it at the end.” Transfers fail when people quit.

  3. 03

    A written handoff at close

    SOW close includes: access removed, passwords rotated where they were shared, env vars documented, and a list of third-party apps still connected.

  4. 04

    No shared personal logins

    If someone is using a personal Figma or a personal OpenAI key on a client project, you do not control continuity. That is an ops defect, not a personality quirk.

Put the credential standard in the MSA or an operations exhibit. Then enforce it in the first sprint, not at launch week. The process we run with agencies assumes staging and production access are visible to the account team from the start—because invisible access is how agencies get held hostage.

Subcontractors, staff, and “who is actually building”

You vetted a company. They may still use specialists. That is not automatically bad. Undisclosed subcontracting is. Your client may have asked you not to use unnamed third parties. Your insurance and confidentiality promises may assume you know who touched the files.

Get in writing: whether the partner may subcontract, whether you must approve named subs, and that every sub is bound to confidentiality and IP terms at least as tight as the partner’s. If your client’s MSA forbids subcontracting, your partner MSA must match—or you cannot put that client on that partner.

Change, delay, and the clauses that protect margin

Legal paper cannot invent a brief you never wrote. It can stop a fight about whether a late CRM field is “a small tweak.” The MSA should point to a change-order process. The SOW should define revision rounds, what a round is, and how extra work is priced. That commercial detail belongs next to how to run revision rounds without killing margin—and it belongs in writing, not in a kickoff anecdote.

Scope language that either holds or fails

Phrase in the SOWWhat usually happensBetter operational substitute
Unlimited revisions until happyPartner hours explode; you absorb themTwo rounds of consolidated feedback; extras quoted
As soon as possibleNo one is late, so everyone isA date, a dependency list, and what happens if content is late
Includes SEO / includes integrationsEveryone imagined a different productNamed integrations, named templates, named environments
Bug-freeUnprovable; weaponized at launchDefined acceptance tests plus a warranty window for defects vs new requests

Liability caps belong in the MSA, sized to the relationship. Counsel sets the numbers; you insist numbers exist. Delay is usually a stack of dependencies: content, APIs, approvals. The SOW should say what happens when the client (through you) is late. If the partner’s date is fixed and assets are not, you will pay for idle time or a crash at the end.

Warranty, support, and what “done” means

Launch is not a disappearing act. If you sell the client a 30-day bug window, buy a 30-day bug window. Mismatch here is how agencies donate senior time. The MSA should allow SOWs for both build and care so you are not inventing terms on a Friday night.

Acceptance and warranty, in writing

  • Staging review by your agency before the client sees it
  • Written acceptance or a deemed-acceptance period if the client goes silent
  • Defect versus change-request definition
  • Warranty window and response targets for severity
  • What happens to unused retainer hours if you also run a monthly capacity agreement

What you should refuse—and what you should not demand

Partnership paper is a negotiation. Walking away is allowed. So is not asking for fantasy terms that no competent studio will sign.

Pros

  • + Refuse: partner retains custom client IP after you pay
  • + Refuse: partner may publicize the client without consent
  • + Refuse: partner may contact the end client to upsell
  • + Refuse: no cap, or unlimited personal guarantees from your founders for ordinary web work
  • + Refuse: production starts before MSA + SOW

Cons

  • − Do not demand: the partner can never work with another agency in your country
  • − Do not demand: they assign their entire internal design system to you
  • − Do not demand: unlimited liability for indirect damages on a $12k brochure site
  • − Do not demand: they fire staff you dislike as a contract right
  • − Do not demand: they accept your client’s entire enterprise MSA unmodified if you have not even shown it to them

If a candidate pushes back on NDA, IP assignment, or white-label communication, stop. That is not a “legal personality.” It is a business model that needs your clients as their marketing. Compare that signal with the red flags in how to vet a white label partner. Diligence without paper is a vibe. Paper without diligence is a well-documented accident.

A signing sequence that does not stall the pilot

The goal is not to spend six weeks in redlines while the client waits. The goal is to never put client files in a channel that is not covered. Run paper in parallel with scoping.

  1. 01

    Mutual NDA before the real brief

    Capabilities call can happen first. Named client, files, and credentials cannot.

  2. 02

    MSA redlines while the SOW is estimated

    Do not wait for a perfect SOW to start MSA review. The relationship terms rarely depend on page count.

  3. 03

    SOW with rounds and acceptance

    Price, dates, deliverables, change process. Attach the brief. No production until both sides sign.

  4. 04

    Pilot, then retainer addendum

    Move to monthly capacity with a retainer SOW. Do not rewrite the MSA unless the relationship actually changed. Store executed files where account managers can see the revision cap.

When you are ready to see how Tretanz handles agency paper and delivery together, book a partnership discovery call. Bring your template or your open questions. The useful conversation is whether the operating model and the documents describe the same company.

Where this sits next to vetting, pricing, and process

Contracts do not make a weak partner strong. They make a strong partner safe to scale. Stay in the vetting checklist until they can deliver. Use white label pricing models to decide how to buy capacity. Use when white label is the wrong model if the model itself is the issue. Paper is the last mile of a commercial decision—not the first slide of a sales deck.

FAQ

Frequently asked questions

Straight answers for agency owners evaluating white label development partnerships.

Continue reading