Metric and calculation customization: most platforms support custom metrics, calculated fields, and named measures.
Data model extensibility: ability to map new sources, create data hierarchies, and define relationships (e.g., customers, products, regions).
Dashboard customization: bespoke layouts, visuals, filters, drill-downs, and saved views.
Alerts and scheduling: custom alert conditions, thresholds, and delivery channels (email, Slack, Teams).
Roles and permissions: granular access controls by user, group, data domain.
Branding and localization: themes, logos, language localization, and regional date/number formats.
Automation and APIs: programmatic data ingestion, webhook integrations, and API-driven dashboard management.
Governance and lineage: lineage tracking, data source ownership, and change auditing.
Additional Costs
Setup/implementation fee (one-time): covers discovery, design, onboarding, and initial data connector development. Can range from a few thousand to tens of thousands of dollars, depending on scope.
Monthly/annual subscription (TCO):
Per-user pricing (e.g., per named user or per active user)
Per-data-source or per-connection pricing
tiered plans based on features, data volume, or number of dashboards
Data processing/usage fees: if the platform charges based on data volume, query count, or data processed.
Maintenance/annual renewal: ongoing access to software, updates, and support.
Support charges: levels of support (standard, premium/24x7), response times, and dedicated CSMs. Sometimes included with higher tiers; otherwise billed separately.
Training and enablement: optional paid training for admins or power users.
Professional services: for complex integrations, advanced analytics, data migration, or custom development (hourly rates or project-based).
Extras: dedicated sandbox, data governance add-ons, security/compliance packages (e.g., SOC 2, ISO 27001), single sign-on (SSO) setup, and data residency options.
Training
Admin training: how to manage users, permissions, connectors, data refresh schedules, and platform governance.
Power user training: building and modifying dashboards, creating calculated metrics, advanced filters, and ad-hoc reporting.
End-user training: how to read dashboards, interpret metrics, set up alerts, and export/export schedules.
Role-based curricula: separate tracks for executives, data analysts, data engineers, and IT/security staff.
On-demand resources: knowledge base, product docs, video tutorials, and sample dashboards.
Live sessions: instructor-led webinars, Q&A sessions, and office-hours for hands-on help.
Hands-on sandbox: a safe environment for practice without impacting production data
Change-management enablement: guidance on adoption, best practices, and governance policies.
Security Measures
Access control and identity
Authentication methods: support for SSO (SAML, OAuth), MFA enforcement, and password rotation policies.
Authorization: role-based access control (RBAC), fine-grained permissions by user, group, data domain, and dashboard.
Session security: short-lived tokens, idle timeout, and automatic logout.
Data protection
Encryption at rest: disk/file-level encryption for stored data (e.g., AES-256 or equivalent).
Encryption in transit: TLS 1.2/1.3 for all data in transit.
Data masking and privacy: options to mask sensitive fields in dashboards or exports.
C. Data residency and governance
Regional data residency options: ability to store data in specific regions or clouds.
Data lineage and impact analysis: visibility into data origins, transformations, and dependencies.
Audit logs: immutable logs of data access, changes, and administrative actions.
Compliance and certification
Security framework mappings: SOC 2 Type II, ISO 27001, GDPR/CCPA readiness, HIPAA (if applicable), etc.
Third-party assessments: penetration testing, vulnerability scanning, and monthly or quarterly security review reports
Data retention and deletion policies: configurable retention windows and secure deletion processes.
Updates
Typical release models
Minor releases: frequent, often weekly or bi-weekly; include bug fixes, small enhancements, and UI improvements.
Major releases: less frequent (quarterly to semi-annually); introduce new features, architectural changes, and sometimes deprecations.
Patch/hotfix releases: as-needed for critical issues, deployed quickly to production.
How updates are managed
Update process: usually a staged approach (dev -> staging -> production) with a compatibility/rollback plan.
Backward compatibility: vendor typically communicates deprecated features and provides migration guides.
Release notes: publicly available summaries detailing new features, fixes, and any breaking changes.
Change management for admins: admins receive advance notice and may have a sandbox environment to test before production rollout.
Change window expectations: scheduled maintenance windows for disruptive updates, if any.
Data Ownership and Portability
Data ownership
Ownership of data you provide: Confirm that your organization retains ownership of all data you feed into the platform.
Right to use data: The vendor should have a non-exclusive, non-transferable license to process your data solely to provide the service and for related support, with no broader ownership claim.
Data rights upon termination: Clear statement that you can retrieve or export your data in a commonly used format (e.g., CSV, JSON, dashboards export) for your own use after termination, within a defined period.
Data portability
Data export formats: Availability of export options for raw data and transformed metrics,
Raw data extracts from connectors
Metadata about data models and definitions
Dashboards, reports, and configurations (exportable templates)
Data retention after termination: How long data remains accessible post-termination and under what conditions (e.g., grace period, secure deletion timeline).
Data deletion policy: How data is securely erased at customer request and after contract ends (methods and certifications, e.g., NIST/ISO, if applicable)
Data transfer mechanisms: Supported data egress methods (API access, scheduled exports, SFTP/secure file transfer).
Interoperability and standards: Support for open formats and APIs to enable easier migration to another system.
Data governance and privacy
Data residency: Ability to store data in a specific region/country and any constraints.
Data minimization and masking: Options to mask or redact sensitive fields in exports or dashboards.
Auditability: Logs and reports showing who accessed what data and when, aiding portability and compliance.
Scaling Up / Down
Upward scaling: Typically allowed with a written amendment or addendum; review notice periods, pricing adjustments, and onboarding for new features.
Downward scaling: Often allowed, sometimes with minimum terms or notice; verify if there are penalties, deprovisioning steps, or retained support for a grace period.
Minimum commitment: Any minimum term or minimum spend that persists during scaling.
Migration effort: Effort and timeline to add/remove data sources, dashboards, or user licenses.
Data latency and performance: Ensure scaling does not negatively impact data freshness, query performance, or dashboard responsiveness.
Security/compliance impact: Any changes in security posture or governance when scaling (e.g., additional regions, new data domains).
The terms & conditions for contract renewal and cancellation
Renewal terms
Renewal type: Auto-renewal vs. manual renewal; renewal notice window and process.
Price adjustments: How price changes are communicated and applied at renewal (notification period, cap on increases).
Term length options: Annual, multi-year terms, and associated discounts for longer commitments.
SLA alignment: Renewal may come with updated SLAs or support terms.
Cancellation and termination
Termination rights: Notice period, grounds for termination (convenience vs. for cause), and any early termination penalties.
Data retrieval post-termination: Timeline and method to export data, and whether access to the platform is retained during wind-down.
Data deletion on termination: How and when data is securely deleted, and any retention of anonymized or aggregated data.
Transition assistance: Availability of offboarding support, migration services, or a transition period to other systems.
Post-termination support: Availability and pricing for support after termination (if any)
Service levels during renewal
Support continuity: Whether support levels change at renewal and if there are any sunset provisions for older versions.
Migration windows: Any required upgrade paths tied to renewal, with timelines and compatibility notes.
Compliance
Information security management: ISO 27001, SOC 2 Type II (or Type I if applicable), SOC 3
Privacy: GDPR readiness, CCPA/CPRA considerations, data processing agreements (DPAs).
Industry-specific: HIPAA (if handling PHI in healthcare contexts), PCI DSS (if payment data involved).
Cloud and data handling: CSA STAR, ISO 27701 (privacy framework), NIST-based controls.