The whole structure of build, operate, transfer points at handover. Treating that as the goal rather than as one available outcome produces the specific failure it was designed to prevent: a system with a named owner who cannot run it.
Declining is a decision, not a default
Deciding not to transfer is an explicit choice about the operating model, made where a proposed recipient cannot or should not take the stated responsibility.
Three different decisions get merged and need separating: deferral, a narrower transfer, and long-term external operation. Each carries different review conditions and different reversal points.
The threshold question is which obligation is unmet — authority, willingness, task competence, staffing, access, rights, money, or a dependency that cannot be supported internally. Then whether missing evidence or a demonstrated limitation is at issue, because those need different responses.
And then whether a funded, scheduled remedy is credible. An intention to hire is not a filled support rota. A training plan without protected time is not a capability. The test is whether the gap closes before the transfer date, not whether someone has agreed it should.
Two things outsourcing does not do: resolve a failed product hypothesis, or make an unacceptable system acceptable. If the prototype should not exist, moving who operates it changes nothing.
Managed operation is a model, not a fallback
Permanent managed operation means deliberately choosing sustained external operation with no planned near-term transfer of all operating tasks. Permanent does not mean irrevocable or exempt from later appraisal.
Delivery-model choice is an appraisal of in-house, market, and mixed options — including internal capability, transition difficulty, and whole-life costs — and the published models distinguish internal delivery, a bridge while capability develops, fixed-term borrowing of capability, and outsourced delivery.
Choosing it well means specifying both sides. The supported workload, service hours, change process, incident coordination, data responsibilities, and exclusions. And the buyer’s retained decisions: product priorities, acceptance, risk decisions, spending authority.
The retained capability is the part that fails quietly. The buyer needs enough internal knowledge to evaluate performance, authorise changes, and make procurement or exit decisions, plus the information and access the agreement actually permits — with a stated response for when evidence is missing.
Comparison uses a common scope and horizon. Managed operation at 48,000 in supplier fees plus 12,000 in buyer oversight and 6,000 in agreed changes is 66,000 against an internal alternative estimated at 60,000 for equivalent scope. Those numbers do not settle it: service quality, transition costs, uncertainty, and feasible exit remain to be assessed, and a cheaper base fee can accompany materially different obligations.
The exit plan is maintained regardless, with specific deliverables, time, costs, permissions, and receiving options — and parts of it tested, such as an authorised export and reconstruction exercise, acknowledging what stays dependent on supplier cooperation. A written plan and a demonstrated migration are different things.
The failure mode this avoids
An orphaned prototype has continuing use, dependencies, or obligations for which adequate accepted ownership is missing. It can be orphaned for a subset of duties while a nominal owner exists on the org chart.
That is what a forced transfer produces. The acceptance was recorded, the owner was named, and the duties — incidents, changes, evaluation, billing, credentials, data retention and deletion, supplier relationships, user communication — have no one who is both authorised and equipped.
A prototype whose project has ended, with a scheduled job still running and storing personal data, and a former developer who knows the code but has no authority over the account or the retention decision, is the standard shape. The knowledge, the willingness, the authority, and the funded capacity are four separate things, and the volunteer who can fix one issue is not the long-term owner.
The correction assigns those specific decisions through the organisation’s authorised roles and then compares a funded receiving arrangement, reduced exposure, or retirement. A new label on the same gap is not closure.
Re-engagement is not a verdict
Where the vendor is called back after transfer, four explanations compete: new scope, planned specialist support, a later change, and inability to perform an obligation already accepted. The contact does not identify which.
A recipient hiring its original supplier to add a newly required integration six months later has commissioned work outside the accepted transfer scope, and that alone demonstrates nothing about the handover. If the same review finds the recipient still cannot perform the originally accepted release procedure, that is a separate finding requiring its own evidence and remedy.
A specialist task can stay external deliberately. Repeated inability to perform an agreed internal task is a capability question.
The rule
What stays fixed is that every surviving duty has an owner who has accepted it and can perform it. What changes is where that owner sits, and internal is not automatically better.
The record states which obligation prevents transfer now, which remedy is funded, and which event would justify reconsidering. A temporary continuation gets a purpose and a decision point. A lasting model gets sustained funding and governance.
Not to be confused with
A recommendation. No delivery model is universally best, and the incentives run both ways — some organisations insource reflexively, others accumulate vendor dependence without appraising it.
A contractual right. None of this establishes an entitlement to extend an agreement, and no minimum team size follows from it.