A North American marketing consultancy had won three briefs its own staff could not build. One was a measurement app built on its analyst’s own method, with nobody to build around it. One was a person downloading a survey workbook from Drive every month and re-running a notebook by hand. One was a research tool it wanted to run under its own name. Turn a brief down and the fee goes back, and so does the account behind it. Hire for all three and three salaries outlive the work.
You know the shape. You win work that needs a skill you do not staff. Your client buys from you, not from whoever holds the keyboard.
| Measure | Figure | Period or check date |
|---|---|---|
| Engineering disciplines delivered | 3 | 23 Aug 2025 to 16 Mar 2026 |
| Repositories in the client's own account | 3 of 3 | checked 20 Sep 2026 |
| Outside sources wired into the research tool | 8 | at its last commit, 17 Feb 2026 |
| First commit to production on that tool | 11 days | 6 to 17 Feb 2026 |
Hiring for all three would have cost three salaries
Subcontracting has its own bill. The subcontractor becomes a dependency you cannot unwind, holding code you never read. The real question is not who types the code. It is where the code lives.
Each brief was messier than it looked. The first arrived on 23 August 2025 as 130 files in one commit. The commit message said “Fix login bug.” The code had no login in it. A repository is the folder holding the code and its history. The survey repository opens with 28 monthly workbooks, March 2023 to July 2025, with December 2023 missing. Our pipeline hardcodes a fix for a typo in the client’s own filenames. Somebody had been catching that typo by eye. Source: the first commit in the client’s survey repository, read 20 September 2026.
We deleted three months of our own work rather than defend it. In November 2025 we started rebuilding a statistics library from scratch. On 24 February 2026 we deleted it, 21 minutes after a better replacement landed. The client’s real analysis shipped three weeks later.
The consultancy’s analyst keeps the method, and we build around it
The four-phase logic in the measurement app is the consultancy’s analyst’s work. The commit that added it says so, in the client’s own repository. We did not write it.
We built around it instead. A geo test gives the campaign to some markets and withholds it from others, then compares the two. The app runs inside a container, a package that carries everything it needs to run. Its statistics libraries are pinned to one archive dated 28 February 2024, so the app rebuilds the same way every time.
Then there was the data. An export can drop a row when nothing happened in a market that day. The method needs every day for every market, because a missing row and a zero are different facts. Our step fills those gaps with zeros. The test ran 5 treated markets against 203 to 206 control markets, over a 32-day run-up and a 15-day window.
The report argued against its own headline. One model produced the flattering result, but its comparison group did not match the period before the test. The model we shipped did match it. The gap fell from 0.4313 to effectively zero, and its result was weaker. We shipped the weaker one, named the flaw, and specified the test that would settle it.
A monthly job that was a person became a scheduled pipeline
A scheduled job replaced that routine. It reads the folder, puts each file into the same columns, and loads the rows into a database table split by month. It retries once a day for the first seven days of the month, until the export lands.
The part worth copying is that the job is idempotent. Idempotent means running it twice changes nothing the second time. One check skips a file already handled. Another check skips a row already stored.
Two limits travel with that guarantee. Google Sheets files carry no such check, so they get reprocessed on every run. A corrected row lands beside the old one, not in place of it.
This stream is delivered code. Nothing shows it running yet, so this page claims no hours saved.
Research comes out as a branded deck, not raw data
The third build is a research platform the consultancy runs itself. Eight sources feed it, from Reddit and TikTok to Google Trends and web search.
A run comes out as a PDF and a deck in the consultancy’s own brand voice. A deck the client can read is the deliverable.
It reached production in 11 days, 6 to 17 February 2026. Nine of those commits were fixes against the live server.
What changed, what did not, and the rows nobody measured
| Measure | Before | After | Window or check date |
|---|---|---|---|
| Monthly survey processing | by hand, Drive to notebook | scheduled job | code complete 12 Dec 2025 |
| Analysis environment | one analyst's machine | container rebuild, one command | from 24 Feb 2026 |
| Repositories in the client's account | not established | 3 of 3 | checked 20 Sep 2026 |
| Hours saved per month | not measured | not measured | no run history exists |
| End-client business result | not measured | not measured | no repository records one |
| Reports produced on the platform | not measured | not measured | no usage data reaches us |
Two facts belong beside it. The platform runs on our servers, not the client’s, so custody and hosting differ here. And no client engineer ever committed, so the handover rests on the docs, the deploy script and the container.
Owning the source is not the same as being able to run it. Before asking who owns the repository, ask what travels inside it. An architecture guide, a deploy script, tests, a container that rebuilds it in one command. Custody without those is a zip file with your name on it.
What we would run differently, and who should not hire this
We would add automated tests from day one, because two of these repositories have none. We would agree what gets measured before the build starts. And we would book a handover session with an engineer on the client’s side.
This is for you if you run an agency, sell work you do not staff, and want to keep the fee and the account.
It is not for you if you need a continuity commitment. Build activity stopped on 16 March 2026, with one person per discipline. It is not for you if you need an end-client revenue number, because this one has none.

Questions and answers
What is white-label software development?
Building software that ships under another firm’s brand, with the source code in their account. Here that meant three repositories in the consultancy’s own GitHub organisation.
Who owns the analytical method and the code?
The consultancy’s analyst owns the four-phase method, and the commit that added it says so in their repository. The container, the data repair and the report sit there too.
Can you prove the survey pipeline saved time?
No. The code is complete, scheduled and covered by 20 unit tests, but nothing shows it running. Until the client confirms a run, it claims no hours.
If we own the repository, can we run it without you?
Partly. Each repository carries a setup guide or a deploy script, and the measurement environment rebuilds in one command. One service still sits on our servers. No engineer on the client’s side has committed.
