Skip to content
Notifications
Clear all

Unpopular opinion: We're paying for features we don't use. The core product is enough.

10 Posts
10 Users
0 Reactions
0 Views
(@finops_auditor_ray)
Reputable Member
Joined: 4 months ago
Posts: 193
Topic starter   [#23178]

Let's be real. Everyone's chasing the "comprehensive GRC platform" checkbox, but how many of those extra modules do you actually *run*?

We implemented Tugboat Logic for audit readiness and evidence collection. The core Evidence Locker and automated mapping to control frameworks works. It does the job. Then sales comes in pushing the "Strategic" tier. Vendor Risk Management, PolicyHub, the full "integrated risk platform."

Here's my breakdown of our last 6 months of usage logs (anonymized):

* **Vendor Risk Module:** Used twice. Both times for initial onboarding questionnaires. Zero re-assessments. Our procurement team uses a separate system.
* **PolicyHub:** We uploaded our existing policies. The version control is nice, but the automated distribution/attestation? 80% of employees complete it via a reminder email, not the portal.
* **Custom Questionnaire Engine:** Built one. Took 3 hours. Never used again.

The cost jump from the core product to the full suite is significant. You're not just paying for the features; you're paying for the data ingestion, the storage, and the UI complexity for modules that sit idle.

My take: unless you're a large enterprise with dedicated GRC teams for each domain, you're overbuying. The core audit readiness and evidence automation is the real value. The rest is shelfware for most companies.

I'd like to see a truly modular pricing model. Pay for the core, then add *and remove* modules monthly based on actual need. Right now, we're subsidizing features for their "enterprise showcase" customers.

Prove me wrong. Show me your usage stats that justify the full suite for a team under 200 people.

show me the bill


show me the bill


   
Quote
(@cloud_infra_newbie)
Reputable Member
Joined: 4 months ago
Posts: 210
 

Totally see this with AWS services too. We use Lambda and S3 for a simple app, but the sales calls are always about layering on Step Functions, EventBridge, and X-Ray. I get the vision, but for a small team just trying to get something live, it's overwhelming.

Do you think vendors just assume every company wants to scale into every feature eventually? Feels like they price for that future promise, not current reality.

How do you even push back on the "Strategic" tier upsell without sounding like you don't get it?



   
ReplyQuote
(@ellaj8)
Estimable Member
Joined: 3 weeks ago
Posts: 108
 

The "future promise" pricing is the entire business model, yes. They're not selling you a tool, they're selling you the escape from future pain. The sales script banks on the fear that when you *do* need vendor risk or X-Ray, you'll be scrambling.

Pushing back is simple: ask for the audit logs. "Show me the usage data for those modules from a company of our size and stage. If the ROI is there, I'll see it." They never have it.

And AWS is a different beast. With them, you're not buying a tier, you're enabling a service. The sales pressure is lower, but the complexity tax is real. Sticking to Lambda and S3 is a perfectly valid architecture if it meets your control requirements. Don't let their menu convince you otherwise.


Trust but verify – and audit


   
ReplyQuote
(@integration_ian_2)
Reputable Member
Joined: 2 months ago
Posts: 246
 

You're spot on about the cost jump. It isn't just the license fee, it's the operational weight of having those unused modules sitting there. We saw the same thing and ended up building a couple of lightweight automations to handle the few vendor risk questionnaires we needed, syncing data from our procurement system back to the core evidence locker.

That approach only makes sense if your team has the capacity for a bit of custom glue work, but it saved us from that tier upgrade. The vendors will always sell the integrated dream, but sometimes the simplest stitch between your existing tools is the most cost-effective path.


api first


   
ReplyQuote
(@code_panda)
Estimable Member
Joined: 3 months ago
Posts: 107
 

Completely feel you on the >cost jump... and it's the UI complexity that really gets me. You end up with a cluttered admin panel full of tabs you're training staff to ignore. That's a real cognitive tax.

One angle: check if they offer an "add-on" SKU for specific modules instead of forcing the tier jump. Sometimes they bury that option. If not, your usage log is the perfect negotiating tool.

The other question is whether that core Evidence Locker license includes the *latest* mapping features, or if they start holding those back to force the upgrade. Seen that happen.


Spreadsheets > marketing slides.


   
ReplyQuote
(@alexr23)
Trusted Member
Joined: 2 weeks ago
Posts: 72
 

Your usage log analysis is the critical piece most teams never do. It's not just about the license cost, it's the operational drag of maintaining unused modules.

We ran a similar analysis on Vanta and saw the same pattern. The ROI on the full suite evaporated when we factored in the training overhead and support tickets for features that were merely "checked," not actively utilized. For PolicyHub, we found the forced portal attestation actually lowered completion rates compared to a simple, signed PDF workflow we already had.

The real negotiation leverage comes from those logs. Quantify the "cognitive tax" user21 mentioned in hours per quarter spent managing or ignoring those tabs. Present that as a real cost alongside the license fee. Most vendors can't counter hard data showing their premium modules are shelfware.


—Alex


   
ReplyQuote
(@integrations_jane)
Reputable Member
Joined: 3 months ago
Posts: 300
 

That "custom glue work" is the exact path I recommend, but with a huge asterisk. You've now taken on the maintenance and monitoring of that sync job forever. The moment your procurement system changes an API field or rate limit, that script becomes a liability, not an asset. The tier upgrade is a predictable cost, while your homegrown middleware is a silent time bomb of technical debt. It's the right call, but only if you log and treat that connector as its own micro-service with its own lifecycle.


APIs are not magic.


   
ReplyQuote
(@cloud_sec_enthusiast)
Estimable Member
Joined: 2 months ago
Posts: 135
 

Totally agree on the usage log analysis - that's where the truth is. You've hit on something important with the >data ingestion, storage, and UI complexity for idle modules<.

It's similar to how I've seen teams over-provision AWS SCPs or IAM roles with broad permissions "just in case." You pay for the complexity in audit findings and management overhead, not just the direct cost. Those unused policy statements are just like your unused Vendor Risk Module tabs - silent drag.

Your point about the core Evidence Locker being enough is key. In cloud security, we often find that a few well-configured core services (like your evidence collection) with tight automation beat a sprawling suite of tools every time. The sales pitch for the "integrated platform" is strong, but if your procurement team lives elsewhere, forcing that integration is where the real cost and friction come in.


security by default


   
ReplyQuote
(@docker_diver)
Estimable Member
Joined: 2 months ago
Posts: 173
 

Yeah, that usage log breakdown is really eye-opening. It makes me wonder if part of the bloat is from vendors trying to be a single dashboard for *every* department, even when those teams already have their own tools.

We just picked up Tugboat Logic last quarter for the same core locker feature. The sales guy kept asking "what if" scenarios about future needs. It's like buying a car with a sunroof you'll never open just because they say it might rain someday.

Do you think you'd ever use the API to pull evidence from the core locker into your procurement system, instead of building a whole new workflow?


Containers are magic, but I want to know how the magic works.


   
ReplyQuote
(@clarag)
Estimable Member
Joined: 3 weeks ago
Posts: 115
 

That single dashboard dream is exactly what adds so much clutter. Each department already has their own process, so forcing them into a new pane is just extra training.

Your sunroof analogy is perfect, it's exactly that kind of upselling. To your question about the API, that's our plan. We're going to pull evidence from the locker on a schedule and feed it into our existing procurement dashboard. It keeps everyone in their familiar workflow.

How's the Tugboat Logic API documentation? I'm curious if they make that self-service path easy or if it's hidden behind a support call.



   
ReplyQuote