Power users / analysts: building dashboards, prompts, automations
End users: how to interact with the UI, run/runbook tasks, consume insights
Self-paced enablement
Access to an online knowledge base, tutorials, and video guides
Step-by-step walkthroughs for common use cases
Workshops and PoVs
Proof of value sessions to validate use cases before full rollout
Customized workshops focusing on industry-specific workflows
Security Measures
Data in transit and at rest
Encryption: TLS for data in transit; AES-256 or equivalent for data at rest
Access control
SSO/SAML and/or OIDC for centralized authentication
Role-based access control (RBAC) and attribute-based access control (ABAC) options
SCIM provisioning for automated user lifecycle management
Data residency options
Local data residency or region-specific storage where available
Audit logging
Immutable logs for user actions, data access, and configuration changes
Data governance
Data tagging, lineage, and cataloging capabilities to track data usage
Privacy compliance
Support for GDPR, CCPA, HIPAA (as applicable), and other regional regulations
Security certifications
Relevant certifications (e.g., ISO 27001, SOC 2 Type II) depending on vendor offering
Updates
Deployment approach
Cloud/SaaS: updates rolled out by the vendor with minimal user effort; often non-disruptive and included in subscription
On-premises/private cloud: updates scheduled by the customer with vendor guidance; can require testing and staged rollouts
Change management
Release notes detailing new features, deprecations, and migration steps
Optional early access or beta programs for previewing features
Backward compatibility and migration
Compatibility guidance for workflows, prompts, and data models
Migration assistance for breaking changes, with runbooks and code samples if needed
Notification and training
Advance notices for major changes
Updated training materials and quick-start guides aligned with new capabilities
Data Ownership and Portability
Customer ownership of data: The customer generally retains ownership of all data they provide or generate within the Dimmo AI platform.
Dimmo AI rights: Dimmo AI typically has the right to process and store data solely to operate, maintain, and improve the service under the contract, and to provide necessary support.
Data usage limitations: Data should be used to deliver the service and for agreed analytics; any broader use usually requires explicit consent or is governed by the terms of the agreement.
Scaling Up / Down
Right-sizing: Ability to add more users, increase data volume, or enable additional features/modules.
Pricing impact: Typically reflected in a revised quote or addendum; may be tiered by seat count, data volume, or feature set.
Implementation/transition: May require a brief change order, with updated onboarding activities and potential timeline adjustments.
Flexible tiering: Possibility to reduce seats, data volume, or feature scope at a defined cadence.
Cost adjustments: Proration or credits for unused capacity; minimum commitments may apply depending on contract.
Notice periods: Often requires advance notice (e.g., 30–90 days) to adjust subscription and renewal terms.
The terms & conditions for contract renewal and cancellation
Renewal type: Typically auto-renewing unless canceled; term lengths commonly 12 months, with multi-year options.
Term renegotiation: Opportunity to revise scope, add or remove modules, or adjust governance commitments at renewal.
Termination for convenience: Many enterprise contracts allow termination with notice after a minimum term, often with an exit plan for data and services.
Termination for cause: Immediate termination for material breach, non-payment, or repeated SLA failures; cure periods usually specified.
Data transition: Offboarding support and data export assistance during/after termination; defined timelines for access to export your data.
Migration support: Possible professional services or assisted offboarding to minimize business disruption.
Fees on termination: Possible early termination fees or pay-for-performance clauses, depending on the agreement.
Compliance
ISO 27001: Information security management system standard.
SOC 2 Type II: Security, availability, processing integrity, confidentiality, and privacy controls.
HIPAA/HITECH: Protective measures for handling protected health information (where applicable).
GDPR/CCPA readiness: Data protection and privacy requirements for EU/UK and California residents.
PCI-DSS: If handling payment card data (less common for AI platforms unless processing payments).
CSA STAR: Cloud security alliance controls for cloud providers (optional, depending on vendor).
Data residency certifications: Regional data storage compliance (e.g., data center locations, residency options).