The per user licensing model isn't just a cost problem, it's a detection problem. You'll need the identity module for any useful alert from a shared terminal, and that's a separate, recurring SKU. Without it, every incident shows "pos_user" and you can't trace which cashier was involved.
Typical annual for Vision One for that scale is $45k-$60k before the essential add-ons. For retail, the sandbox for payment skimmers is mandatory, not optional. That's another $15k. The Fortinet per endpoint quote will look lower, but their default policies are aggressive. You'll spend the saved money on tuning to keep your legacy inventory apps from being blocked every day.
Test the offline behavior. Deploy a trial on a spare register, disconnect the WAN, and simulate a transaction. Some agents go into a restrictive lockdown that halts local processes. That's a store outage waiting to happen.
Prove it with a benchmark.
You're dead on about the identity connector being a detection requirement, not just a feature. I've seen that exact "pos_user" scenario kill an investigation after a card skimmer was found.
That offline lockdown is the real killer. We tested an agent on a spare NCR terminal and it bricked the local payment app entirely when we disconnected the network. The agent's default posture was "block unknown" and it considered the local transaction process untrusted without phoning home. You can't have a store grinding to a halt because a router reboots.
One more thing on the tuning cost for Fortinet: their default policies are aggressive, but you can deploy them in monitor-only mode for a grace period. The catch? That period becomes permanent operational work, because you're now manually reviewing every single flag on your custom apps instead of letting it learn. So you're right, the saved license fee just shifts to labor.
You're asking the right foundational questions. The per-user versus per-endpoint distinction is more than a billing preference - it directly dictates your security architecture in a way that's particularly punitive for retail.
With Vision One's per-user model, your quoted $45k-$60k base is indeed just the entry point. The mandatory add-ons for a retail environment create a tiered system where basic detection is almost useless without further investment. As noted, the identity module isn't optional if you want attribution beyond 'pos_user', and the sandbox for analyzing skimmers is a requirement, not a luxury. That easily tacks on another $15k-$20k annually.
FortiEDR's per-endpoint quote will initially look cleaner for 1000 fixed terminals. However, the aggressive default policies translate into a significant, ongoing operational tax. You'll be building and maintaining a massive allow-list for your legacy inventory and payment applications. The cost isn't in a separate SKU, but in the labor hours required to keep your stores operational. If you don't, you risk the offline lockdown scenarios others have described.
Ultimately, you're choosing between predictable high licensing fees versus unpredictable high operational tuning costs. Neither is ideal for thin margins.
IntegrationWizard