Activities: provision of test/dev environments, sandbox data masking, seed data, system configuration baselines.
Configuration and customization (depends on scope; typically 4–12+ weeks)
Configuration: module setup, workflows, business rules, user roles, dashboards.
Customization: extensions, custom fields, scripts, or microservices (if supported) to meet unique processes.
Deliverable: configured system with sample data and validated scenarios.
Data migration (2–8+ weeks, parallel where possible)
Activities: data cleansing, mapping from legacy systems, ETL jobs, validation and reconciliation, rollback plans.
Integrations (3–12 weeks, can run in parallel with config)
Activities: connectors to ERP, CRM, HR, payroll, BI, etc.; API validation; end-to-end test scenarios.
User acceptance testing (UAT) and change readiness (2–6 weeks)
Activities: test scripts, defect triage, training materials, change management plans.
Customisation
Configuration vs customization
Configuration: most common path; no coding required. Includes workflows, business rules, field mappings, UI layouts, roles/permissions, dashboards, reports.
Customization: requires code changes, scripts, or custom modules/add-ons; may involve API usage, webhooks, or microservices.
Typical customization options
Data model extensions: custom fields, entities, relationships.
Process automation: custom workflows, approvals, SLA calendars, escalation rules.
Integrations: native connectors, REST/SOAP API integrations, middleware-based orchestration.
Reporting/BI: custom reports, scheduled data extracts, data marts.
Compliance and security: custom access controls, data retention policies, audit trails.
Limitations and governance
Upgrade compatibility: heavy customizations may require rework after upgrades.
Performance impact: poorly designed custom logic can affect latency and scalability.
Vendor support: some customizations are fully supported; others may be covered under premium support or require professional services.
Data points to request from vendor
A list of supported customization scenarios and any restrictions by edition or plan.
Developer/API access limits, rate limits, and sandbox availability.
Case studies or references where similar customizations were implemented.
Estimated effort ranges for common customization types (e.g., 10–40 hours for a small workflow change; 2–8 weeks for a medium integration).
Additional Costs
Upfront/setup fees
Initial license/ subscription setup: one-time onboarding or activation fees.
Implementation services: discovery, design, configuration, data migration, integrations; often billed as a project or fixed-price engagement.
Data migration and integration fees: if complex, external services may bill separately.
Licensing and subscription
Per-user, per-feature, or tiered pricing; some vendors charge based on usage or data volume.
Possible minimum contract length (e.g., 12 months) or annual prepayment discounts.
Training
End-user and admin training materials; onsite or remote training sessions; sometimes bundled in onboarding.
Maintenance and support
Annual maintenance/recurring support fees: typically a percentage of list price (e.g., 15–25% annually) or a flat rate.
Support levels: standard, premium/24x7, enterprise; response/resolution SLAs vary by tier.
Included updates: major/minor releases; some vendors include release notes, upgrade windows.
Professional services and custom work
Additional costs for custom development, integrations, data migration beyond standard scope.
Project management, change management, and training beyond standard package.
Other potential costs
Data storage overages or additional sandbox environments.
Third-party integration costs (licenses for connectors, middleware).
Compliance audits, security assessments, or penetration testing for regulated industries.
Currency or regional pricing adjustments, taxes, and VAT.
Training
New-employee onboarding
Self-paced learning: role-based e-learning modules, short tutorials, and quick-start guides.
Guided onboarding: step-by-step tours within the product, sample data, and scenario-based exercises.
Administrator and power-user training
Admin training: configuration, user management, security roles, permissions, and basic maintenance tasks.
Advanced workflows: automations, integrations, reporting dashboards, and performance tuning.
Training formats
Online courses and video tutorials, live virtual classrooms, and in-person sessions (where feasible).
Sandboxed practice environments or test tenants to allow hands-on experimentation without impacting production.
Training materials and cadence
User manuals, API/docs for developers, release notes, and knowledge base articles.
Regular refresher sessions aligned with major releases or feature rollouts.
Certification and enablement
Optional certification tracks for admins, developers, or power users.
Security Measures
Access and identity
Role-based access control (RBAC) with least-privilege permissions.
Multi-factor authentication (MFA) and SSO (SAML/OIDC) options.
Regular review of user access and automated provisioning/de-provisioning hooks (SCIM where supported).
Data protection
Data-at-rest encryption (e.g., AES-256) for stored data.
Data-in-transit encryption using TLS 1.2/1.3.
Field-level encryption or sensitive-data masking for highly confidential data (where applicable).
Data residency and privacy
Options for regional data storage or data residency compliance (subject to product/edition).
Compliance mappings (SOC 2, ISO 27001, GDPR readiness) and data processing addendums where relevant.
Data integrity and governance
Audit logs, immutable change history, and tamper-evident records for critical actions.
Data retention policies, backup and restore procedures, and disaster recovery planning.
security testing and patching
Regular vulnerability scans, penetration testing by third parties, and prompt security patches.
Patch/upgrade windows aligned with maintenance terms to minimize downtime.
Third-party risk management
Vetting of connectors/integrations, vendor risk assessments, and security reviews for critical integrations.
Updates
Release frequency
SaaS products: typically quarterly to bi-monthly minor updates, with major releases on a less frequent cycle (e.g., every 6–12 months) depending on the vendor.
On-premises: updates tied to maintenance windows and customer approval; can be less frequent and require manual upgrade work.
Update types
Minor patches: security fixes, bug fixes, small enhancements; delivered online with minimal downtime.
Feature releases: new capabilities or modules; usually documented in release notes and may require training.
Major upgrades: architectural changes, data model changes, or deprecations; often require planning, testing, and potential migration work.
Update management
Automatic vs. opt-in: SaaS platforms often push updates automatically with a staged rollout; customers may control release channels or opt out for critical environments.
Release notes and communication: advance notice of upcoming changes, compatibility notes, and known issues.
Compatibility and rollback: vendor-supported rollback options or hotfixes if a release introduces a critical issue.
Testing and staging
Sandbox or staging environments to test prior to production updates.
Customer-led UAT or validation windows for larger feature deployments.
Data Ownership and Portability
Data ownership
You (the customer) typically own all data you or your users upload or generate within the Cirrus platform.
Licenses should not grant Cirrus any ownership rights over your data; expect explicit language that data remains your property and is used only to provide the service.
Data usage rights
Access to data for the purpose of delivering the service, and for providing support and maintenance.
Provisions for data analytics or aggregated, de-identifie.
Data portability
Access to raw data in common formats (e.g., CSV, JSON, SQL dumps) on request, typically with a defined turnaround time.
Regular data export capabilities from the UI or via API, including full data and metadata (schema, relationships).
End-of-service data migration assistance: a defined process and timeline for exporting data when you terminate the contract, including any fees.
Data retention and deletion
Clear data retention policies (how long data is kept post-termination) and the process to request deletion.
Secure deletion practices and certification (e.g., cryptographic erasure) if required.
Data localization and cross-border transfers
Options for regional data residency, data sovereignty assurances, and compliant cross-border data transfer mechanisms (e.g., SCCs/DPAs for GDPR, where applicable).
Scaling Up / Down
Elastic scaling (cloud/SaaS)
On-demand expansion of user licenses, storage, and compute resources
Clear pricing model for scaling (per-user, tier-based, or usage-based), with notice periods if applicable.
SLA implications: ensure performance SLAs hold at larger scales; any tiered limits should be documented.
Scaling down
Pro-rated credits or refunds for unused licenses/agreement re-scoping when reducing footprint (subject to minimum terms).
Data deprecation windows: ability to reduce data retention or deactivate users without losing data immediately.
Migration and downgrades
If you move to a smaller plan, process for data compatibility, feature access changes, and any reconfiguration needed.
Governance and planning
A formal change-management process for scale changes, including approvals, budget alignment, and impact assessments.
Roadmap alignment
Commitments on feature availability and performance expectations as you scale, and any impact on support tiers.
The terms & conditions for contract renewal and cancellation
Renewal terms
Auto-renewal vs. opt-in renewal; renewal notice periods (e.g., 60–90 days before term end).
Price adjustments at renewal (premiums, CPI-based increases, sunset of legacy pricing).
Term length options (monthly, annual, multi-year) and any volume-based discounts.
Cancellation rights
Early termination options and associated fees (e.g., early termination charges, pay-through for remaining term, or no-penalty cancellation with notice).
Data return or export obligations upon cancellation; transition assistance windows and fees if any.
Renewal/manufacturer changes
Right to approve or reject changes to terms, pricing, or modules at renewal.
Notification requirements for material changes (scope, data handling, security controls) prior to renewal.
Data handling upon termination
Final data export window, accepted formats, and delivery method.
Post-termination support windows (if any) and associated costs.
Billing and refunds
Invoicing terms, payment methods, and refund policies for prepayments or unused services.
Service levels and support continuity
Continuity of support during the transition period; any changes in support levels at renewal.
Compliance
ISO/IEC 27001: Information security management system (ISMS) cert
SOC 2 Type II: Security, Availability, Confidentiality, Processing Integrity, Privacy
SOC 1 (if applicable) for financial controls
GDPR readiness and data processing addenda (DPA) for EU data
HIPAA/HITECH (for healthcare data) if handling PHI, with business associate agreements
PCI DSS relevance if processing payment data (usually not for core SaaS unless payment handling is done in-scope)
CSA STAR, ISO 27701 (privacy management)
NIST CSF alignment (more common in regulated industries)