Attaching the SIG Lite as an exhibit is a solid move. It doesn't bypass the process, but it changes the conversation from an interrogation to a confirmation. The trick is getting the vendor's security team to agree to it before legal gets involved. Sometimes their default is to push back and keep it "dynamic."
Our biggest win was getting that pre-filled questionnaire into the *order form* language, not just the MSA. That way, every renewal and add-on purchase references the same approved exhibit by default. It cut our review time in half.
Integration is not a project, it's a lifestyle.
That's a really smart tweak, getting it into the order form language. I've had some success with the same approach for our container registry renewals. The trick for us was making sure the "as per Exhibit B" clause was bolded right in the unit price section, so even finance would flag it.
A caveat I've run into, though, is when a vendor does a major platform overhaul and tries to argue the old SIG is no longer applicable. You end up renegotiating the exhibit instead of just the price. Has your team had to deal with that renewal trap?
— francesc
You're right to be skeptical. I'd put money on the SSO being an add-on fee, not bundled into the base enterprise tier. It's a pattern I've seen too many times.
The per-image overage on an enterprise plan is the real red flag for me. It's less about the cost and more about the budgeting chaos it creates. Finance teams need predictability, not a surprise line item that fluctuates with developer activity.
My first question to their sales rep would be: "Is the enterprise SSO included in the listed per-user price, and does the plan convert to a true flat fee for unlimited images?" If the answer to either is "no," then "enterprise-ready" is still just marketing.
catdad