Environment readiness: Determine cloud region, tenancy model, and integration approach (API-first, prebuilt connectors, or iPaaS).
** integrations**: Connect to HRIS/payroll, ATS, LMS, time tracking, payroll, and identity providers (SSO). Plan for data sync frequency and data mapping.
Data model mapping: Roles, skills taxonomy, job families, competencies, projects, and employee profiles alignment.
Security configuration: Roles, permissions, data access controls, audit logging.
Customisation
Skills taxonomy and ontologies: Create, map, and curate skills, competencies, and job families to match your organization’s terminology.
Talent marketplace rules: Configure matching logic, eligibility, and priority for internal gigs, projects, or gigs across teams.
Workflows and approvals: Customize stages (application, manager approval, upskilling path) and notification rules.
Branding and localization: Adjust UI branding and language/locale per region.
Dashboards and reports: Build/modify executive dashboards, operational reports, and data visualizations.
Learning & development associations: Tie gigs to recommended learning paths, courses, and certifications.
Recommendations and nudges: Tune AI-driven suggestions, confidence levels, and diversity goals.
Data model alignment: Map your HRIS/ATS/LMS data schema to Gloat’s data model (profiles, roles, skills, projects).
SSO and identity: SAML/OIDC, SCIM provisioning, and user lifecycle automation.
Security policy customization: Role-based access controls, data masking, and audit policies.
Integrations: Prebuilt connectors for common systems; custom API integration to exchange data (profiles, projects, learning records, timesheets, payroll status where permitted).
Additional Costs
Per-user or per-seat pricing: Often tiered by administrator vs. end-user access, with volume discounts for large enterprises.
Per-tenant/organization pricing: For multi-region deployments, there may be separate regional charges.
Term length incentives: Annual commitments may include discounts vs. monthly terms.
Implementation fees: One-time charges for kickoff, discovery, data mapping, integration work, and training.
Professional services: Advisory, change management, workflow design, and data migration support.
Integration costs: Custom connectors or middleware if out-of-the-box connectors aren’t sufficient.
Training
Admin and platform ownership training
Comprehensive admin/tenant setup training covering configuration, governance, security, and data mappings.
Access controls, SSO/SCIM provisioning, and audit log management.
Manager and end-user enablement
Role-based training for managers (how to post/approve gigs, review candidates, and run reports).
Guided onboarding for employees on how to discover opportunities, request gigs, and track learning paths.
Learning resources and formats
Self-paced e-learning modules covering core workflows and best practices.
Quick-start guides, playbooks, and in-app tooltips to reduce time-to-value.
Knowledge base with step-by-step tutorials and FAQs.
Change management and adoption support
Adoption playbooks, communication templates, and success storytelling to drive engagement.
Change champions program to accelerate local buy-in.
Hands-on support during rollout
Hypercare period after go-live with real-time support and issue triage.
Training for pilot users ahead of broader rollout, with feedback loops to improve configuration.
Ongoing support options
Tiered support plans (e.g., Standard, Premium/Enterprise) with defined SLAs.
Access to a customer success manager (CSM) or designated success team (often part of premium packages).
Regular health checks, quarterly business reviews (QBRs), and roadmap sessions.
Security Measures
Identity and access management
SSO/SAML or OpenID Connect (OIDC) for centralized authentication.
SCIM provisioning for automated user lifecycle management.
Role-based access control (RBAC) and fine-grained permissions.
Data protection and privacy
Data encryption at rest and in transit (industry-standard cryptography).
Data minimization and masking for sensitive fields where appropriate.
Privacy protections aligned to GDPR, CCPA, and other regional regulations; data subject rights handling as applicable.
Data residency and governance
Options for data localization in specific regions or tenants.
Clear data ownership, retention schedules, and deletion procedures.
Audit logs and tamper-evident records for compliance monitoring.
Security governance and assurance
Regular security assessments, vulnerability management, and penetration testing.
Compliance attestations and certifications (e.g., SOC 2, ISO 27001, as applicable).
Change management controls for security-related updates and patches.
Operational security practices
Secure software development lifecycle (SDLC) with patching and incident response processes.
Regular backups and disaster recovery planning.
Monitoring and anomaly detection for access and usage patterns.
Updates
Update cadence
Gloat typically releases product updates on a regular cadence (weekly to monthly minor updates) with larger releases on a less frequent basis (quarterly or biannual for major features).
Release processes
Hybrid approach: continuous improvements deployed to staging/test environments first, followed by production after validation.
Feature flags or opt-in controls for new capabilities to minimize disruption for customers.
Communication and planning
customers are notified in advance about upcoming releases, deprecations, and breaking changes.
Release notes detailing new features, enhancements, and any configuration implications.
Change management for customers
Guidance and best practices for adopting new features.
Optional early-access programs or pilot opportunities for upcoming features.
Maintenance windows and impact
Planned maintenance windows or off-hours deployments to reduce user impact.
Backwards compatibility considerations and deprecation timelines documented in release notes.
Data Ownership and Portability
Data ownership
Per typical enterprise agreements, the customer retains ownership of their data stored in the Gloat platform.
Gloat acts as a data processor to process customer data in accordance with the contract and applicable privacy laws.
Data access and export rights (portability)
Customer should have the right to export their data in a commonly usable format (e.g., CSV, JSON) for offline analysis or migration.
Metadata about governance rules, approvals workflows, and automation rules.
On termination or expiration, there is usually a defined data export window and a process to obtain a complete data dump.
Data retention and deletion
Clear retention periods after contract termination (e.g., data remains accessible for 30–90 days for export; then deletion).
Deletion/destruction processes with confirmation and audit trails.
Data transfer and localization
Provisions for data residency and regional tenancy if applicable.
Cross-border data transfer mechanisms aligned with GDPR/CCPA and standard contractual clauses (SCCs) where relevant.
Subprocessor disclosures
List of subprocessors and dependencies; customer rights to receive updates and, in some cases, object to specific processors for data protection reasons.
Scaling Up / Down
Elasticity model
Pricing and capacity typically scale with user seats, tenants, or workload; terms should allow adjusting seat counts and regions without renegotiating the core contract.
Up-sizing (scaling up)
Procedures for increasing license footprint, additional regions/tenants, or additional modules (e.g., expanding from internal mobility only to include internal gigs/projects)
Lead time and onboarding of new users, data migrations, and potential phased rollouts.
Down-sizing (scaling down)
Procedures for reducing user licenses, downgrading regions, or deactivating modules.
Possible proration of fees for partial-year reductions and minimum commitment terms.
Migration and data compatibility
Support for migrating data between tiers or configurations without data loss.
Consistency of data mappings and taxonomies during scale changes.
Notification and governance
Minimum notice periods for scale changes (e.g., 30–90 days).
Impact on SLAs, support levels, and training needs during scale transitions.
The terms & conditions for contract renewal and cancellation
Renewal structure
Auto-renewal vs. manual renewal; renewal notice period (e.g., 60–120 days before term end).
Price adjustments at renewal (strongly negotiate for transparency; potential caps or agreed multi-year pricing).
Termination for convenience
Termination rights after initial term with notice period; any early termination penalties, decommissioning assistance, and data export rights.
Cancellation process
Step-by-step process, including data export deadline, transition assistance, and access after termination for a defined grace period.
Data export on termination
Required data export formats, delivery method, and timeline after termination.
Deletion of data from Gloat systems post-export or post-grace period with confirmation.
Transition support
Post-termination support window for onboarding to a new system (handoff of data, knowledge transfer, and access to historical analytics if needed).
Fees and refunds
Any non-refundable upfront fees, remaining balance handling, and refund policies (if any) upon cancellation.
Service levels post-renewal
If renewal under a new term, confirm SLAs, support levels, and roadmap commitments.
Audit rights
Right to audit terms or to receive status reports during renewal negotiations.
Data privacy and compliance continuity
Continuity of privacy protections and data handling obligations during and after renewal.
Compliance
SOC 2 (Security and/or Type II) – commonly requested for SaaS providers handling sensitive data.
ISO 27001 – information security management system certification.
ISO 27701 or equivalent for privacy information management (where applicable).
GDPR/CCPA readiness and data processing addenda (DPA) with Standard Contractual Clauses (SCCs) for transfers, if handling data of EU/UK/other regions.
HITRUST (less common for pure talent platforms, but possible for healthcare/regulated industries).