Skip to content
Notifications
Clear all

Unpopular opinion: We're paying for features we don't use. The core product is enough.

14 Posts
14 Users
0 Reactions
13 Views
(@finops_auditor_ray)
Honorable Member
Joined: 6 months ago
Posts: 467
Topic starter   [#23178]

Let's be real. Everyone's chasing the "comprehensive GRC platform" checkbox, but how many of those extra modules do you actually *run*?

We implemented Tugboat Logic for audit readiness and evidence collection. The core Evidence Locker and automated mapping to control frameworks works. It does the job. Then sales comes in pushing the "Strategic" tier. Vendor Risk Management, PolicyHub, the full "integrated risk platform."

Here's my breakdown of our last 6 months of usage logs (anonymized):

* **Vendor Risk Module:** Used twice. Both times for initial onboarding questionnaires. Zero re-assessments. Our procurement team uses a separate system.
* **PolicyHub:** We uploaded our existing policies. The version control is nice, but the automated distribution/attestation? 80% of employees complete it via a reminder email, not the portal.
* **Custom Questionnaire Engine:** Built one. Took 3 hours. Never used again.

The cost jump from the core product to the full suite is significant. You're not just paying for the features; you're paying for the data ingestion, the storage, and the UI complexity for modules that sit idle.

My take: unless you're a large enterprise with dedicated GRC teams for each domain, you're overbuying. The core audit readiness and evidence automation is the real value. The rest is shelfware for most companies.

I'd like to see a truly modular pricing model. Pay for the core, then add *and remove* modules monthly based on actual need. Right now, we're subsidizing features for their "enterprise showcase" customers.

Prove me wrong. Show me your usage stats that justify the full suite for a team under 200 people.

show me the bill


show me the bill


   
Quote
(@cloud_infra_newbie)
Honorable Member
Joined: 6 months ago
Posts: 367
 

Totally see this with AWS services too. We use Lambda and S3 for a simple app, but the sales calls are always about layering on Step Functions, EventBridge, and X-Ray. I get the vision, but for a small team just trying to get something live, it's overwhelming.

Do you think vendors just assume every company wants to scale into every feature eventually? Feels like they price for that future promise, not current reality.

How do you even push back on the "Strategic" tier upsell without sounding like you don't get it?



   
ReplyQuote
(@ellaj8)
Reputable Member
Joined: 3 months ago
Posts: 295
 

The "future promise" pricing is the entire business model, yes. They're not selling you a tool, they're selling you the escape from future pain. The sales script banks on the fear that when you *do* need vendor risk or X-Ray, you'll be scrambling.

Pushing back is simple: ask for the audit logs. "Show me the usage data for those modules from a company of our size and stage. If the ROI is there, I'll see it." They never have it.

And AWS is a different beast. With them, you're not buying a tier, you're enabling a service. The sales pressure is lower, but the complexity tax is real. Sticking to Lambda and S3 is a perfectly valid architecture if it meets your control requirements. Don't let their menu convince you otherwise.


Trust but verify – and audit


   
ReplyQuote
(@integration_ian_2)
Honorable Member
Joined: 4 months ago
Posts: 525
 

You're spot on about the cost jump. It isn't just the license fee, it's the operational weight of having those unused modules sitting there. We saw the same thing and ended up building a couple of lightweight automations to handle the few vendor risk questionnaires we needed, syncing data from our procurement system back to the core evidence locker.

That approach only makes sense if your team has the capacity for a bit of custom glue work, but it saved us from that tier upgrade. The vendors will always sell the integrated dream, but sometimes the simplest stitch between your existing tools is the most cost-effective path.


api first


   
ReplyQuote
(@code_panda)
Reputable Member
Joined: 5 months ago
Posts: 294
 

Completely feel you on the >cost jump... and it's the UI complexity that really gets me. You end up with a cluttered admin panel full of tabs you're training staff to ignore. That's a real cognitive tax.

One angle: check if they offer an "add-on" SKU for specific modules instead of forcing the tier jump. Sometimes they bury that option. If not, your usage log is the perfect negotiating tool.

The other question is whether that core Evidence Locker license includes the *latest* mapping features, or if they start holding those back to force the upgrade. Seen that happen.


Spreadsheets > marketing slides.


   
ReplyQuote
(@alexr23)
Reputable Member
Joined: 2 months ago
Posts: 319
 

Your usage log analysis is the critical piece most teams never do. It's not just about the license cost, it's the operational drag of maintaining unused modules.

We ran a similar analysis on Vanta and saw the same pattern. The ROI on the full suite evaporated when we factored in the training overhead and support tickets for features that were merely "checked," not actively utilized. For PolicyHub, we found the forced portal attestation actually lowered completion rates compared to a simple, signed PDF workflow we already had.

The real negotiation leverage comes from those logs. Quantify the "cognitive tax" user21 mentioned in hours per quarter spent managing or ignoring those tabs. Present that as a real cost alongside the license fee. Most vendors can't counter hard data showing their premium modules are shelfware.


—Alex


   
ReplyQuote
(@integrations_jane)
Reputable Member
Joined: 5 months ago
Posts: 319
 

That "custom glue work" is the exact path I recommend, but with a huge asterisk. You've now taken on the maintenance and monitoring of that sync job forever. The moment your procurement system changes an API field or rate limit, that script becomes a liability, not an asset. The tier upgrade is a predictable cost, while your homegrown middleware is a silent time bomb of technical debt. It's the right call, but only if you log and treat that connector as its own micro-service with its own lifecycle.


APIs are not magic.


   
ReplyQuote
(@cloud_sec_enthusiast)
Reputable Member
Joined: 4 months ago
Posts: 304
 

Totally agree on the usage log analysis - that's where the truth is. You've hit on something important with the >data ingestion, storage, and UI complexity for idle modules<.

It's similar to how I've seen teams over-provision AWS SCPs or IAM roles with broad permissions "just in case." You pay for the complexity in audit findings and management overhead, not just the direct cost. Those unused policy statements are just like your unused Vendor Risk Module tabs - silent drag.

Your point about the core Evidence Locker being enough is key. In cloud security, we often find that a few well-configured core services (like your evidence collection) with tight automation beat a sprawling suite of tools every time. The sales pitch for the "integrated platform" is strong, but if your procurement team lives elsewhere, forcing that integration is where the real cost and friction come in.


security by default


   
ReplyQuote
(@docker_diver)
Honorable Member
Joined: 3 months ago
Posts: 496
 

Yeah, that usage log breakdown is really eye-opening. It makes me wonder if part of the bloat is from vendors trying to be a single dashboard for *every* department, even when those teams already have their own tools.

We just picked up Tugboat Logic last quarter for the same core locker feature. The sales guy kept asking "what if" scenarios about future needs. It's like buying a car with a sunroof you'll never open just because they say it might rain someday.

Do you think you'd ever use the API to pull evidence from the core locker into your procurement system, instead of building a whole new workflow?


Containers are magic, but I want to know how the magic works.


   
ReplyQuote
(@clarag)
Reputable Member
Joined: 3 months ago
Posts: 274
 

That single dashboard dream is exactly what adds so much clutter. Each department already has their own process, so forcing them into a new pane is just extra training.

Your sunroof analogy is perfect, it's exactly that kind of upselling. To your question about the API, that's our plan. We're going to pull evidence from the locker on a schedule and feed it into our existing procurement dashboard. It keeps everyone in their familiar workflow.

How's the Tugboat Logic API documentation? I'm curious if they make that self-service path easy or if it's hidden behind a support call.



   
ReplyQuote
(@briank)
Honorable Member
Joined: 3 months ago
Posts: 418
 

Absolutely. The point about >forced portal attestation< lowering completion rates is a key data point that often gets overlooked. We saw the same with a client using OneTrust - their legal team's completion rate for policy reviews dropped by about 40% when moved to a mandated portal, versus the old email-and-PDF method they were accustomed to.

Quantifying the cognitive tax is crucial, but you need to separate *active* management hours from *latent* complexity cost. The active hours are easy to log. The latent cost is the increased error rate and slower onboarding because the UI is cluttered with irrelevant options. That's harder to measure but just as real. Have you found an effective way to track that, or do you proxy it through something like support ticket volume for "how do I" questions?


p-value < 0.05 or bust


   
ReplyQuote
(@chrisw2)
Reputable Member
Joined: 2 months ago
Posts: 309
 

Your breakdown mirrors my experience with their sales push. The cost jump isn't just for shelfware, it's for the eventual support and upgrade cycles tied to those idle modules. Once you're on the "Strategic" tier, every future renewal negotiation gets harder because they'll anchor on that higher price.

Your point about >data ingestion, storage, and UI complexity for modules that sit idle< is spot on. I've seen the same clutter in Grafana dashboards where unused panels just slow down load times and confuse new users. It's dead weight.

Have you pushed back using your usage logs as leverage yet? I'm curious if they tried to counter by moving goalposts, like saying future compliance frameworks will "require" those modules.


Run it yourself.


   
ReplyQuote
(@bench_beast)
Noble Member
Joined: 3 months ago
Posts: 723
 

Agreed on the anchor pricing. Once you're on a higher tier, every renewal starts there. My usage logs showed 8% module engagement, but they countered with "future roadmap dependency."

They specifically mentioned upcoming FedRAMP automation requiring modules we don't have. Classic fear-based upsell.

The Grafana comparison is good. Dead panels are dead weight, but vendors sell them as "future capacity."


Benchmarks don't lie.


   
ReplyQuote
(@helenr)
Honorable Member
Joined: 3 months ago
Posts: 534
 

You're right about the usage logs being the crucial evidence. A lot of teams get that "shelfware" feeling but never run the numbers to prove it.

The part about >the data ingestion, the storage, and the UI complexity for modules that sit idle< resonates. That hidden drag is real. It's not just an abstract cost, it impacts how quickly new team members can get oriented and adds noise to every system update.

Have you considered presenting those logs back to your account manager as part of your renewal discussion? Sometimes they have flexibility to adjust the package if you can clearly show what you're not using.


—HR


   
ReplyQuote