Notifications: Custom alerts, escalations, and channels (email, SMS, in-app).
Service-level agreements: Custom SLA definitions and enforcement.
Data points to capture:
End-to-end process maps for core use cases (onboarding, service provisioning, incident management).
SLA targets, escalation paths, and notification rules.
Role-based access requirements.
Additional Costs
Initial setup and implementation
Discovery/consulting fees: Business process mapping, architecture design.
Configuration & data migration: Field mappings, data cleansing, migration scripts
Integrations: API development, middleware, licensing for connectors.
Customization: Any bespoke development, UI tweaks, or automation.
Training: Admin and end-user training materials and sessions.
Typical range: from a few thousand to tens of thousands of dollars/euros, scaling with complexity and number of integrations. For large deployments, 5–15% of total licensing cost is not unusual upfront.
Licensing and subscription
User licenses: Named users vs. concurrent licenses; role-based pricing.
Tiered features: Core platform vs. add-ons (analytics, AI assistants, advanced automation, telephony integrations).
Usage-based add-ons: API calls, data storage, or event processing.
Typical pricing model: monthly or annual per-user fees, with volume discounts.
Hardware and infrastructure (if applicable)
Cloud-based platforms minimize hardware needs; on-prem or hosted instances may incur server, storage, and networking costs.
Ongoing maintenance and support
Support plans: Standard, Premium, or Enterprise SLAs; 24/7 support, response times.
Maintenance windows and updates: Regular software updates, security patches, and upgrade services.
Data storage and backups: Retention policies and backup services.
Typical ranges:
Support: 10–20% of annual license cost per year (varies by tier and response times).
Maintenance/updates: often bundled with support; otherwise 5–15% of license cost annually. Training renewal or ongoing enablement can be additional.
Training
Structured onboarding program
New-user onboarding tracks: Admins, power users, and general users.
Role-based labs: Hands-on practice in a sandbox environment.
Live training sessions
Instructor-led webinars or in-person sessions: Functional areas (provisioning, ticketing, integrations, reporting).
Q&A and hands-on exercises.
Self-service resources
Online knowledge base: Articles, FAQs, how-tos.
Video tutorials and step-by-step guides.
Community forums and user groups.
Certification and competency programs
Role-specific certifications for admins or advanced users
Change management and adoption support
Operational playbooks, best practices, and rollout checklists.
User adoption coaching and KPI dashboards to track uptake.
Security Measures
Access control and identity
RBAC/ABAC policies: Role-based and attribute-based access controls.
MFA (Multi-Factor Authentication): Enforced for admins and/or all users.
Single Sign-On (SSO): SAML, OAuth, or OpenID Connect integration with corporate IdP.
Data protection
Encryption:
At-rest: encryption of storage with strong algorithms (e.g., AES-256).
In-transit: TLS ≥ 1.2/1.3 for all data exchanges.
Data residency options: Regional data centers or data localization capabilities.
Data governance and lifecycle
Audit logs: Immutable or tamper-evident logs for admin actions, configuration changes, and data access.
Data retention and deletion: Policies for retention periods and secure deletion routines.
PII handling: Data minimization, masking, and support for data redaction in logs and exports.
Compliance and certifications
Regulatory coverage: GDPR, CCPA, HIPAA (if applicable), PCI-DSS considerations for payment data, etc.
Vendor security assessments: SOC 2 Type II, ISO 27001, or equivalent, and regular third-party security reviews.
Data breach response: Incident response plan, notification timelines, and escalation contacts.
Operational security
Change management: Controlled deployment with test/prod separation and change windows.
Backup and disaster recovery: Regular backups, RPO/RTO targets, and tested recovery procedures.
Network security: Firewalls, intrusion detection, vulnerability management, and patching cadence.
Updates
Regular minor updates: Monthly or quarterly for bug fixes and small enhancements.
Major releases: Annually or semi-annually, introducing new features and architectural changes.
Emergency patches: As-needed security or critical fixes outside the regular cadence.
How updates are delivered and managed
Deployment model:
SaaS: Updates are applied by the vendor with minimal downtime, often in a rolling fashion.
On-prem/private cloud: Updates managed by customer or via vendor-managed upgrade services.
Upgrade windows and downtime: Planned maintenance windows, with advance notice and rollback plans.
Backward compatibility and deprecations: Clear deprecation timelines for APIs, plugins, or workflows; migration guides provided.
Release notes: Detailed documentation of new features, changes, and any breaking changes.
Change control for customers: Preview programs or sandbox environments to test updates before production
.
Customer responsibilities
Testing in sandbox before production upgrade.
Reviewing release notes and preparing a compliance/validation plan for new features.
Coordinating integrations: Ensuring external systems remain compatible after updates.
Data points to confirm
Official update schedule (frequency, window length).
Availability of a staging/test environment for upgrades.
Process for emergency patches vs. planned releases.
Backup/rollback procedures and success criteria for upgrades.
Communication channel and notice lead times for updates.
Data Ownership and Portability
Data ownership
Customer ownership of data: The customer retains ownership of all data uploaded into TeleCMI, including content in tickets, orders, contacts, and uploaded documents.
Licensing to data: TeleCMI typically requires a license to process and store data during the term of the contract, solely for the purpose of providing the service.
Data usage rights: TeleCMI may be allowed to use aggregated, de-identified data for product improvement or benchmarking, provided it cannot be traced to a specific customer.
Data rights on termination: Upon contract termination, customers should have the right to extract and export their data in a usable format within a defined period.
Data portability
Export formats: Availability of exports in common formats (CSV, JSON, XML) for core entities (customers, services, tickets, invoices).
Data richness: Access to related data, attachments, and metadata; support for relational exports preserving links between entities.
API access: Ongoing API availability during wind-down; rate limits and authentication method documented.
Data retention window post-termination: Defined window (e.g., 30–90 days) to retrieve data after cancellation, with secure deletion timelines.
Data deletion guarantees: Clear statements on deletion of customer data from TeleCMI systems after wind-down, including log and backup purge where feasible.
Scaling Up / Down
Scaling terms to confirm
User license flexibility: Ability to add or remove named or concurrent licenses; prorated changes; minimum contracts for add-ons.
Capacity-based scaling: If the platform uses quotas (API calls, storage, connectors), terms to increase/decrease capacity without penalties.
Cost implications: How pricing adjusts with scaling (tiered pricing, volume discounts, mid-term adjustments).
Lead time: Notification and approval timelines for scaling actions (e.g., 30–60 days advance).
Downgrades: Policies and potential penalties for reducing scope or downgrading licenses mid-term.
BOperational impact
Implementation work for scaling: Any reconfiguration, data migrations, or downtime expectations when scaling.
SLAs consistency: Ensuring uptime and support levels remain consistent when scale changes.
Contract alignment: Whether scaling triggers renegotiation of term length or payment terms.
Data implications during scaling
Storage and retention: How increased storage affects pricing and data retention windows.