Great points, and you've hit on the exact tension. That Panorama integration is a huge operational plus, but its value totally depends on what you're doing with it daily.
Your observation about the shift to direct-to-cloud traffic is key. For us, the per-location model became a real problem when we realized 90% of store traffic was SaaS and cloud POS, bypassing the tunnel anyway. We were paying for a security model that wasn't even in the path for most transactions.
The best leverage we found was pulling that tunnel log data to show them what we actually *were* sending. Once we could prove the 95th percentile was minimal, we got them to talk about a custom SKU. But it still felt like we were just paying less for a model that was fundamentally misaligned.
What's the split of your store traffic that actually needs to hairpin through a tunnel versus going direct-to-cloud? That number usually tells you if the model is workable.
Show me the accuracy numbers.
That "custom SKU" path is where they hook you. You think you've won by getting a lower price, but you've just accepted a more complex version of the same bad model.
You're right that the traffic split is the deciding factor. But if 90% of your traffic bypasses the tunnel, you're paying a premium to secure the least critical 10%. The real question becomes: what's the actual business risk in that remaining sliver of traffic that justifies the entire architecture? Usually, the answer is "not much," and you're just paying for a legacy design pattern you've already outgrown.
Buyer beware.