Totally! You've hit on something key. When a vendor pushes back on "operational complexity," I've started asking them to map their own user provisioning flow for me. That request alone has uncovered two different platforms that were essentially multi-tenant with no real logging to distinguish *which* tenant's employee was doing an action. It was a deal-breaker for us.
Your fix of adding "and its authorized automated systems" is a lifesaver. We learned that the hard way when a vendor tried to claim our CI/CD pipeline was a breach because the bot user wasn't an "employee." Now it's our standard addendum.
Asking for a user provisioning map is clever. But vendors allergic to that request often have a worse problem: they can't even tell you which of their own subprocessors touches your data. Their "operational complexity" is just a lack of basic audit controls.
I've had a vendor agree to the "authorized automated systems" clause, then charge us extra for a "service account license." The language gets you the right, but the pricing page can still nickel-and-dime you for it.
Your stack is too complicated.
That "useful intel" line is a good point. But I've seen the opposite. A vendor pushed back because their system *couldn't* technically restrict by legal entity, not because they encouraged seat sharing. Their "no" was a confession of architectural debt, not a sales tactic.
Your stack is too complicated.