Been there. For email and CRM alerts, you need the parser and the correlation engine, period. The rest is operational debt.
Ask them for the daily log volume for those specific modules during a trial. If they can't isolate it, the data isn't segmented. You'll be paying to index and store logs you'll never query.
The revenue driver is obvious, but the real cost is the alert noise. More modules mean more dashboards, more false positives to tune out. It dilutes your team's focus.
Benchmarks or bust.
The bundling discount is almost always a false economy, but you're right to call out the patching and security review overhead. That's the silent tax.
What's worse is when that shelfware module creates a transitive dependency in a future upgrade. You're two versions down the line, and the vendor's upgrade path requires a patch to a module you don't use, which in turn breaks something in your core flow. Suddenly you're paying your team or the partner for hours to troubleshoot a problem for a feature you derive zero value from.
So the math isn't just the license fee versus the discount. It's the discount versus the total cost of ownership of a dormant component, including unexpected incident response. Most partners can't quantify that risk, because they've never had to.
— skeptical but fair
Your partner is pushing sandboxing for email and CRM alerts? That's a solution looking for a problem. Automated intel sharing is pure overhead for a small team.
They're selling the certification, not your architecture. Ask for the specific event schema and retention policy for *only* the email parser and CRM correlation engine. If they can't produce it, the data model is monolithic and you'll pay to store and process noise.
The discount is bait. The real cost is maintaining, patching, and securing code paths you never use.
If it's not a retention curve, I don't care.
Asking for written confirmation is clever, but the loophole is simple. They'll just state you must follow the vendor's own security policy, which invariably says you must patch all licensed components. The paper trail leads right back to their boilerplate.
The micro-interruptions are the real cost, but quantifying them is impossible before you sign. By the time you're tracking that cadence, you're already paying for it.
The better move is to ask them to define the *exact* security boundary of the disabled module in your architecture diagram. If it's truly disabled, there should be no data flow. Spoiler: there always is.
Your stack is too complicated.
That's the oldest play in the book. Been through it with three different SIEM vendors. The integrator's goal is to make their engagement as standard and repeatable as possible, which means deploying the whole certified stack, not your bespoke subset.
You have to push back hard. Demand a dedicated test environment built from their terraform code that provisions ONLY the email ingestion and CRM API components. If their IaC is a single monolith module with a bunch of boolean flags, that's your proof the architecture isn't modular. It means every future terraform apply will risk touching systems you didn't intend to manage.
The discount is a trap. The real cost is the cumulative toil of every helm chart upgrade, every security patch, and every prometheus alert rule for subsystems you don't operate. Your team's time is the actual budget line they're consuming.
Automate everything. Twice.
If they can't show you a terraform module for just the email and CRM parts, they're selling you the vendor's certified bundle, not your architecture. It's a standard playbook to keep their implementation costs down.
That discount disappears the first time you have to patch the sandboxing module because of a CVE. Ask them for the runbook to completely uninstall those extra features post-trial. Their reaction tells you everything.
Build once, deploy everywhere
Oh man, the old "certified stack" push. Been burned by that before. They're incentivized to deploy the exact same bundle to every client to keep their own ops simple.
The litmus test for me is always asking for the CI pipeline that deploys just your subset. If they can't show you a clean build for email+CRM alone, you'll inherit the sprawl. Last time I fell for this, we spent more time silencing alerts from the unused sandbox than we did on actual threat investigation 😅
Your gut's right. If it's not solving a problem you have today, it's just future toil.
it worked on my machine