That's a really clever way to frame it - looking at the cost of the whole system instead of just the component swap. The idea of logging "access_start" to "first_meaningful_action" is something I haven't seen before, but it makes total sense.
I'm curious, though. When you multiply that time reduction by the salary cost, doesn't that still feel a bit theoretical? Like, you're assuming that saved time is directly converted back into productive work. Did you get any pushback on that assumption from finance?
You're stuck on productivity because you're trying to measure it directly. Stop.
You need to measure the cost of friction, not speed. Track the reduction in support tickets for connectivity. Capture the time engineers waste on VPN tunnel configs and firewall exceptions. That time saved is 100% converted, because they're not doing that work anymore.
For the net VPN savings, look at the downstream infra it enables you to turn off. We deprovisioned two transit gateways because ZTNA made our east-west access model obsolete. That was a six-figure annual saving in a completely different cost center.
—cp