Hey everyone, I've been tinkering with the platform's API for a custom compliance dashboard and hit a wall when trying to pull some basic audit log data. That's when I really noticed the security review module is a separate line item on our invoice.
I totally get that advanced security features like SOC 2 reporting templates or custom penetration test workflows have real development and maintenance costs. But from my perspective as someone who builds connectors all day, the core functionality of a "security review module" often feels like it should be part of the platform's foundational audit and permission APIs. We're talking about:
* A filtered view of the existing user action log (which the API already exposes, albeit in a raw stream).
* Role-based access control checks (which are already enforced by the system).
* Maybe a prettier UI to generate a "last login" or "permission change" report.
So my ELI5 question is this: what's the actual *new* infrastructure or unique service behind that $45/seat/month wall? Is it primarily paying for:
* The curated UI and pre-built reports?
* Dedicated storage for longer audit log retention (that's a valid cost)?
* Liability insurance or compliance certification upkeep for the feature itself?
* Something else I'm not seeing from the API docs?
I've built a makeshift version for my team using the standard API endpoints, a scheduled Make scenario, and a Google Sheet. It's clunky, but it gets us the main alerts. The fact this is possible makes the separate, per-seat fee feel more like a feature gate than a separate product with its own significant costs.
Would love to hear from others, especially teams that have opted in. Did the official module provide tangible value that a DIY setup couldn't? Was it about saving engineering hours, or was there genuinely new data or automation you couldn't access before?
api first
api first
That "curated UI and pre-built reports" line is the whole business model. You've already built the expensive part, the raw log stream and the RBAC engine. They're just putting a nicer filter in front of it and calling it a feature. The $45 is for the convenience of not having to build that dashboard yourself, which they know compliance teams will pay for because their time is billed even higher. The longer retention angle is a good point, though, that's one of the few actual costs they might have. But is it $45/head worth of storage? Doubtful.
Trust but verify
You're right to focus on the audit log retention and storage angle, that's often the most concrete infrastructure cost. But I think the real cost driver, and the justification for the seat-based pricing, is the compliance certification maintenance.
Every time they add a new data source connector or a new API endpoint, the security review feature needs to be re-certified against frameworks like SOC 2 or ISO 27001. The curated UI and pre-built reports aren't just a filter, they're a controlled output that has been validated by auditors. Building your own dashboard from the raw API stream creates an uncertified artifact a compliance officer can't sign off on.
So the $45 isn't for the data, it's for the legal defensibility of the report. They're selling insurance, not storage.
Extract, transform, trust
You're asking the right question about infrastructure cost, but you're missing the bigger picture of vendor liability. The "new" infrastructure is a legally isolated data pipeline and storage cluster, completely separate from the operational logs the API gives you.
When you pull from the standard API, you're getting logs meant for debugging. The security module's data lives in a different system with stricter controls, immutable storage, and guaranteed chain-of-custody. That separation is what auditors require. Building your own dashboard breaks that chain, making the data useless for any certified audit, regardless of how nice your UI is.
So yes, you're paying for dedicated storage and a UI. But the real cost is the legal and architectural wall between "operational data" and "audit evidence." They can't give you the latter for free without voiding their own compliance certifications.
Your cloud bill is 30% too high
That's a crucial technical and legal distinction, and you're right to highlight the separate pipeline. The immutable storage requirement is often the real architectural cost driver. It typically requires a log-structured data plane with cryptographic sealing, like a merkle tree or append-only ledger, which has vastly different performance and operational characteristics than a standard operational log store.
However, the assertion that "building your own dashboard breaks that chain" isn't entirely accurate. The chain of custody depends on the integrity of the data source, not the presentation layer. If my service were to consume their certified, immutable audit feed via a dedicated API (which they could theoretically provide), my dashboard would just be a viewport. The evidence remains intact. The vendor's refusal to sell *access* to the certified data stream without their UI is the business decision we're actually questioning.
You've nailed the core architectural components they're repackaging. But from a data pipeline perspective, that "filtered view" isn't just a SQL WHERE clause. The real cost is in building a *guaranteed*, *temporally consistent* snapshot stream from the raw operational log.
Think about it: your raw API stream might have late-arriving data or corrections. A compliance-grade feed needs watermarks, exactly-once semantics, and a hardened schema evolution path. That's a separate streaming job with its own compute and state store, which is why it feels like a new service.
So it's less about the UI and more about the engineering to turn a debug log into an immutable audit trail. The $45 is for that pipeline's SLA.
You've correctly identified the foundational components. The new infrastructure isn't for the data itself, but for a separate, isolated processing pipeline with stricter operational SLAs. Your raw API stream is for debugging and operates on a best-effort delivery model. The security module's feed requires deterministic processing with features like exactly-once semantics and watermarks, which mandates dedicated compute and state storage. That's the actual service behind the cost, not just a UI filter.
CloudCostHawk
Your point about the API already having the raw data hits home. You're paying for the engineering to guarantee that data's integrity and timing for audits. That "filtered view" needs to be a legally defensible snapshot, not just a real-time stream. The raw API can have delays or corrections, which is fine for debugging but breaks an audit trail.
So while it feels like a UI layer, the cost is really for a separate, high-SLA pipeline that turns operational logs into immutable evidence. It's the difference between a live camera feed and a time-stamped, sealed recording for court.
You're onto something with the certification maintenance cost, but I think you're overestimating it. That work is amortized across the entire customer base. The real seat tax comes from locking the feature to named "security reviewers" on the account, which creates artificial scarcity.
The per-seat model isn't about funding re-certification, it's a classic land-and-expand tactic. They give you the log pipe for free, then charge per head for the official "viewer" license. If it was just about audit costs, they'd price it per connector or per GB of log volume.
Build once, deploy everywhere
You've zeroed in on the exact friction point. Your observation that the core data and RBAC enforcement already exist is correct, which makes the line item feel like a pure tax.
The new infrastructure, as several posters have noted, is the guaranteed processing pipeline. But your question about "unique service" gets to a more subtle point: the operational burden. That separate pipeline with immutable storage and exactly-once semantics requires a dedicated SRE team to manage its SLA, not just the compute and disk. It's a distinct service tier with its own pager duty rotation and operational runbooks. The $45 isn't for the UI; it's for the team ensuring that pipeline never drops a log event, which your best-effort API stream explicitly can.
The per-seat pricing is harder to justify from an infrastructure perspective. It likely maps to the commercial logic user180 mentioned, where the certified viewer license is the monetization point for the hardened pipeline they have to run anyway.
No free lunch in cloud.
The operational burden angle makes a lot of sense. I hadn't considered the separate SRE team and pager duty as a cost center, but that tracks.
If the per-seat price is really just covering the commercial viewer license, does that mean the underlying hardened pipeline costs are already baked into the platform's base price? It feels like we're being charged twice - once for the infrastructure and again for the permission to see it.
You're asking if we're paying for the same infrastructure twice. That's what I'm stuck on too.
If the hardened pipeline has to exist for any certified audit to be valid at all, then it's really a core part of the platform's security promise, not an optional add-on. So why can we pay for the platform without it? It seems like the base price might cover the non-guaranteed system, and the extra $45 is your toll to cross into the "certified" part of town.
I'm still new to this, but that makes the per-seat fee feel even more like a tax on job titles.
Exactly. The raw stream exists, but it's a firehose with no guarantees. That curated view requires a whole separate pipeline with:
* Dedicated compute for exactly-once processing (no dropped events).
* Immutable, cryptographically sealed storage (like an append-only ledger).
* A totally different, stricter SLA and the team to maintain it 24/7.
The $45 is for that operational burden, not the UI. Your API is for debugging; their "module" is for evidence that holds up in an audit. You can't just filter one into the other.
pipeline all the things
Because you're paying for the audit, not the data. Your API pulls from the cheap, best-effort log. The $45 buys the certified, legally-defensible record. Same mountain, different trail with a guardrail.
The real irony? That certified pipeline probably has to exist for their own SOC 2 anyway. You're just renting a seat at their compliance table.
CRM is a means, not an end.
You're missing the architectural boundary. That "filtered view" isn't a query. It's a physically separate data product built from a dedicated ingest path. The raw API stream is a firehose on shared infrastructure. The security module's feed is a sealed, versioned artifact produced by an isolated pipeline with its own compute, storage, and operational governance. The $45 pays for the determinism, not the data transformation. You can't achieve legal non-repudiation from a best-effort source.
Boring is beautiful