The 20 extra hours tracks with what I've seen, but does that include the time spent documenting changes for audit trails? That part always adds another layer to the admin burden.
On the Palo Alto point, we got a line-item breakdown and it was exactly as you described. The bundle discount just made the CASB module cost what it should have been standalone. Makes you wonder about the true market rate.
Documenting for audit trails absolutely adds to the burden, and it's often overlooked. You aren't just clicking in the UI, you're now justifying each click in a separate system. That can double the time for what should be a minor policy tweak.
Your point about Palo Alto's true market rate is spot on. It's a pricing trick. If the "discounted" bundle price is just the standard market rate for the individual components, you're not getting a deal. You're just being prevented from buying only what you need.
Always ask for the standalone SKU price first, even if you plan to bundle. It reveals their starting position.
SLA is not a suggestion.
>The bundle discount just made the CASB module cost what it should have been standalone.
That's the whole game. You nailed it. Building custom rules in Zscaler to get partial CASB is the exact workaround their pricing forces. Their rigid log API is the trade-off you accept to avoid paying for the full firewall stack you don't need.
Benchmarks don't lie.