A 60-day evergreen clause does not send a calendar invite. It just sits in section 14.2 of a contract nobody has reopened since the vendor was onboarded two years ago, and it renews itself on schedule whether or not the price went up, whether or not the vendor's risk profile changed, whether or not anyone on the team still remembers why the deal was signed. Procurement teams of two or three people, managing dozens of active vendor contracts against a headcount that never grows as fast as the vendor list does, live with this problem permanently: renewals happen on autopilot because there is no time to build a real review gate, supplier risk gets mapped for the vendor you're signing but never for the subprocessors that vendor quietly depends on, and a routine purchase order for a $6,000 tool sits in an approval queue for three weeks because the workflow treats every purchase like a $500,000 one. None of this is a strategy problem. It is a process and staffing problem, and it is exactly the kind of problem that a chatbot answering questions in a browser tab cannot touch.
Why a chatbot and an autocomplete tool both miss this
Ask ChatGPT or Claude.ai to help with a vendor renewal and it will draft you a negotiation email, summarize a contract you paste in, or list generic best practices for procurement. What it will not do is sit inside your actual vendor list, notice that Contract #47 renews in eleven days, cross-reference the last cost review against this year's budget, and flag that nobody has looked at the vendor's own subprocessor list since onboarding. A generalist chatbot has no persistent view of your vendor portfolio. It answers the question you typed and forgets everything the moment the tab closes. It cannot build you a renewal calendar with 90/60/30-day gates, because it has no concept of your calendar, your vendor count, or your approval chain in the first place.
Cursor and GitHub Copilot solve an entirely different problem: writing code faster inside an editor. Procurement work is not code. There is no autocomplete for "should this vendor renewal go to legal review" and no IDE for a RACI matrix. Even when procurement teams reach for these tools to draft a spreadsheet formula or automate a Slack notification, the tools have no model of vendor risk, no concept of contract renewal cadence, and no way to reason about whether a 12% price increase blows through this year's software budget. The mismatch is structural: procurement needs a system that treats vendor management as an ongoing operational discipline with recurring gates, not a one-off document you ask a chatbot to summarize once.
Keel: the ops engineer that owns the vendor lifecycle
Keel is tonone's operations engineer, built for process design, vendor management, legal ops, and compliance work, the exact surface area procurement teams live in every week. Where a generalist tool treats each renewal as an isolated question, Keel treats vendor management as a system with recurring inputs: a portfolio of active contracts, a renewal calendar, an approval chain, and a compliance posture that has to hold up whether the auditor asks about it or not.
Keel starts from an operations reconnaissance pass, not a blank page, because a vendor renewal decision made without seeing the whole portfolio is a decision made with one eye closed.
The intake step is keel-recon. It audits process documentation, active vendor contracts, compliance posture, and cross-functional friction points before anything gets redesigned. For a procurement team, this means Keel starts by finding every contract with a renewal or notice date inside the next quarter, flagging the ones with no documented owner, and surfacing the approval workflows that currently exist only as tribal knowledge in someone's head. This is the step that catches the evergreen clause before it fires.
From there, keel-vendor does the work procurement teams usually do by hand in a spreadsheet at 11pm the night before a renewal deadline: a vendor selection scorecard, a contract review checklist, renewal tracking across the full portfolio, and a consolidation audit that flags when three different teams are paying for overlapping tools. Instead of a single renewal decision made in isolation, keel-vendor produces a standing view of every vendor relationship, scored against cost, risk, and redundancy, so the team is deciding from a portfolio view rather than reacting to whichever contract happens to expire first.
The approval bottleneck gets fixed with keel-process. Rather than a generic "streamline your approvals" suggestion, this skill documents the actual current process (who touches a purchase request, in what order, with what SLA at each step), then redesigns it as a proper SOP with a RACI: routine purchases under a defined threshold get a single approver and a 48-hour SLA, purchases above the threshold or touching a new data processor route through legal and security review with a 10-business-day SLA, and every step has a named owner instead of a queue nobody is accountable for. That is the difference between a three-week approval and a two-day one: not more headcount, a workflow that matches the actual risk of the purchase instead of treating all purchases identically.
Chain: the subprocessor risk that lives past tier one
Every vendor you approve brings its own vendors with it, the subprocessors, the embedded libraries, the third-party services a SaaS tool quietly depends on to run. Most procurement reviews stop at the vendor's own security page and never go further, because going further means auditing a software supply chain, which is not a procurement skill, it's a security engineering one. Chain is tonone's supply chain security specialist: SBOM generation, dependency scanning, and third-party risk analysis. For procurement, Chain's job is to look past the vendor you're signing and into what that vendor is built on, the tier-two risk that a standard vendor security questionnaire never surfaces.
Concretely, chain-scan designs the dependency scanning program that checks a vendor's published SBOM (or its trust center disclosures) for known CVEs and license violations in the libraries the vendor's own product depends on. When a vendor's trust center lists an embedded analytics agent or a bundled open-source component, Chain checks that component against current CVE databases. If the vendor is running a version with a disclosed, unpatched vulnerability, that is a fact procurement needs before signing a renewal, not six months after a breach notification arrives.
The vendor questionnaire tells you what the vendor says about itself. Chain tells you what the vendor's own supply chain says about the vendor.
Mint: the cost review autopilot skips
The other thing an evergreen renewal skips is a cost review. Mint is tonone's finance engineer, covering P&L, budget, unit economics, and board reporting. In a procurement context, Mint's role is narrower and specific: check the renewal price against this year's approved budget line, flag the variance, and put a number on what the increase actually costs against plan, rather than letting a 12% bump slide through because nobody compared it to the software budget line it's supposed to fit inside.
This is deliberately a two-agent handoff, not a solo Mint task: Keel identifies which renewals are coming up and what changed in the contract terms, Mint checks whether the new price fits the budget or requires a variance conversation with finance leadership before anyone signs. Neither agent is guessing at the other's job. Keel doesn't try to reason about budget variance thresholds, and Mint doesn't try to redesign an approval workflow. Each stays in its domain and hands off a clean input to the other.
Worked example: an evergreen clause with 11 days left
Fenwick Outdoor is a 150-person direct-to-commerce outdoor gear company with two people running procurement and ops against roughly $4.2M in annual vendor spend across 60-plus active contracts. Nobody owns a renewal calendar; contracts get flagged when a vendor emails asking to confirm the next term, which is exactly what happened with Loop Analytics, a customer data platform under a $340,000 annual contract with a 60-day evergreen auto-renew clause. The renewal notice window was already down to 11 days when someone noticed.
Keel's recon pass finds the contract, confirms there's no assigned owner past the original signer (who left the company eight months earlier), and pulls the current terms: a proposed 12% increase to $381,000, no updated security questionnaire on file since onboarding, and a subprocessor list that references a third-party ETL vendor Fenwick has never independently reviewed. Chain runs a scan against Loop Analytics' published trust center disclosures and finds that the embedded ETL agent bundles a library version with a CVE disclosed 87 days earlier, patched by the library maintainer but not yet reflected in Loop Analytics' own release notes. Mint checks the $381,000 figure against Fenwick's software budget line and finds it puts total SaaS spend 9% over the approved annual plan, past the threshold that requires CFO sign-off rather than a procurement-level approval.
Keel, Vendor Renewal Gate: Loop Analytics ($340k -> $381k)
Recon: 11 days to auto-renewal. No named owner since Feb.
Security questionnaire: last updated at onboarding, 22 months stale.
-----------------------------------------------------------
Chain: subprocessor scan
Embedded ETL agent v3.4.1, CVE-2026-11029 (patched upstream
in v3.4.2). Loop Analytics release notes do not reference the
patch. Risk: unpatched dependency in a system that touches
customer PII.
Action: request patch confirmation before renewal, or hold
renewal 15 days pending vendor response.
Mint: budget variance check
Proposed renewal: $381,000 (+12%)
Approved FY software budget line: $2.1M, currently at 94%
utilization before this renewal
With renewal: 103% of approved line
Threshold: >100% requires CFO sign-off, not procurement-level
approval
Keel: process recommendation
Hold auto-renewal. Send 15-day extension request to Loop
Analytics citing pending security patch confirmation (this also
buys the budget conversation time).
Route to CFO for sign-off given 103% budget line utilization.
Assign new contract owner: Head of Data, effective immediately.
Update vendor record: security questionnaire due within 10
business days of renewal signature.
-----------------------------------------------------------
Next: Keel schedules the 90/60/30-day gate for this vendor going
forward so this never again gets caught with 11 days left.None of this required the procurement team to become security engineers or FP&A analysts. Keel found the contract and built the workflow gate that will prevent an 11-day scramble on the next renewal. Chain answered a question procurement teams structurally cannot answer themselves: is the software this vendor runs on actually patched. Mint answered the question that autopilot renewal always skips: does this fit the budget, and if not, who needs to sign off. Three specialists, three narrow jobs, one coordinated recommendation instead of a renewal that happens because nobody stopped it in time.
An evergreen clause is not a decision. It is the absence of one. Keel's job is to make sure a decision gets made before the clause makes it for you.
Keel vs the alternatives
| Capability | Tonone | Generalist chatbot | Cursor / Copilot |
|---|---|---|---|
| Persistent vendor portfolio view | Yes, keel-recon and keel-vendor track the full contract list with renewal dates and owners | No, answers only the single question or document pasted in | No, no concept of a vendor portfolio at all |
| Renewal workflow redesign with SLAs | Yes, keel-process builds a RACI and approval SLA matched to purchase risk | No, gives generic best-practice advice, not a workflow tied to your team | No, autocomplete has no process modeling capability |
| Subprocessor / software supply chain risk | Yes, chain-scan checks vendor SBOM disclosures against known CVEs | No, cannot inspect a vendor's technical dependency chain | No, editor autocomplete does not reason about vendor security posture |
| Budget variance check on renewal pricing | Yes, Mint checks the new price against the approved budget line and utilization | No, no access to your budget or approved spend plan | No, no financial reasoning capability |
| Coordinated multi-domain handoff | Yes, Keel, Chain, and Mint hand off cleanly across process, security, and finance | No, single-turn answers with no memory across domains | No, one autocomplete model, no specialist coordination |
Start with keel-recon on your actual vendor list before anything else. It will surface which contracts renew in the next 90 days and which have no current owner, that list alone is usually enough to justify the workflow redesign that follows.
1. Add to marketplace
2. Install Keel
Frequently asked questions
What does Tonone's Keel do for procurement teams?+
Keel is tonone's operations engineer, handling vendor management, process design, and legal ops. For procurement, it builds a persistent vendor portfolio view with renewal dates and owners, redesigns approval workflows with SLAs matched to purchase risk, and coordinates with Chain and Mint for security and budget review.
Can AI catch a vendor contract before it auto-renews?+
Yes. Tonone's keel-recon skill audits your active vendor contracts to surface upcoming renewal dates, missing contract owners, and stale security questionnaires, the gaps that let an evergreen clause fire without review.
What is chain-scan and how does it relate to procurement?+
chain-scan is a Tonone skill that checks a vendor's published SBOM and trust center disclosures against known CVEs and license issues. For procurement, this surfaces subprocessor and software supply chain risk that a standard vendor security questionnaire does not catch.
How does Mint help with vendor renewal decisions?+
Mint checks the proposed renewal price against your approved budget line and utilization, flagging when a price increase pushes total spend past a threshold that requires CFO sign-off rather than procurement-level approval.
Why can't ChatGPT handle vendor contract renewal review?+
ChatGPT and other generalist chatbots have no persistent view of your vendor portfolio. They answer the single question or document you paste in and forget it afterward. They cannot track a renewal calendar, contract ownership, or budget thresholds across dozens of vendors.
How do Keel, Chain, and Mint work together on one vendor renewal?+
Keel identifies the vendor, its renewal terms, and any workflow gaps. Chain audits the vendor's software supply chain for unpatched dependency risk. Mint checks the new price against the budget. Each agent stays in its own domain and hands off a clean input to the next.
Is Tonone free to use for procurement and ops work?+
Yes. Tonone is MIT-licensed and free. You pay only for the Claude Code token usage during the work itself, and Keel's outputs include the workflow and process artifacts a procurement team can reuse on every future renewal.
What is keel-process and how does it fix slow approval workflows?+
keel-process documents your current purchase approval chain and redesigns it as a formal SOP with a RACI, assigning SLAs based on purchase risk rather than treating every request identically. Routine purchases get fast, single-approver paths while higher-risk purchases route through legal and security review.