Ways of seeing the product
- Demo
- Any showing of software before purchase. On its own the word says nothing about who is driving or whether the software is running. Always ask which kind. See the six formats.
- Product tour (click-through demo)
- A sequence of captured screens with clickable hotspots. It looks like the product and is not running. Good for seeing the intended workflow; no use for testing behavior.
- Sales demo
- A live presentation of the product by the vendor, normally on a call, by a sales engineer. The only format you can interrupt. See running a sales demo.
- Sandbox
- A working copy of the software kept apart from real use, where nothing you do has consequences. A demo sandbox is loaded with sample data for prospects. A customer sandbox is a copy of a customer's own setup for testing changes. Ask which is meant.
- Self-serve
- Available without speaking to anyone: you register and you are in. The opposite is gated, where a form or a call comes first.
- Trial
- Use of the product for a limited period before purchase, usually so that you can load your own records. May be self-serve or arranged, at no cost or paid. Check what happens to your data when the period ends.
- Proof of concept (POC)
- A short, structured test of one specific question, normally with a sample of real data, judged against criteria written at the start. See the proof of concept plan.
- Pilot
- Real use by a small team for weeks, to test whether people adopt the product. Closer to a purchase than to a demo.
- Reference customer
- An existing customer the vendor arranges for you to speak to. Useful, with the caution that the vendor chose them. Ask for one of your size and industry, and ask them what is slow and what they had to work around.
What is inside a demo
- Environment
- One running copy of the software together with its data. Vendors run several: production for customers, a demo environment for prospects, test environments for their own work. An answer about one does not necessarily hold for another.
- Tenant (workspace, organization, account)
- One customer's separated area within a shared system. In a well-built product, one tenant cannot see another's data. In a demo, ask whether you get a tenant of your own or share one with every other visitor.
- Seed data (sample data)
- Records loaded in advance so that a demo is not empty. It was written to suit the product, which is why it always looks tidy. It tells you what the vendor thinks a typical customer looks like.
- Synthetic data
- Invented records that have the shape of real ones. What you should type into a demo instead of real customer or staff details. See demo data and privacy.
- Module
- A part of a product that can be switched on or sold separately. A demo may include modules your quote does not, or the other way round. Compare the two lists.
- Configuration and customization
- Configuration is changing settings the product already offers. Customization is writing something new for you. "It can be configured to do that" and "we can build that" are different commitments at very different prices.
- Roadmap
- What the vendor intends to build. Not a commitment unless it is in your contract, and not part of what you are evaluating today.
Access and security
- Role and permission
- A permission is one thing a user may do; a role is a named bundle of permissions. Evaluate with the narrowest role, because that is what most of your users will have.
- Audit trail (audit log)
- A record of who did what and when, which ordinary users cannot edit. Check that it records changes to existing records, not only their creation.
- SSO (single sign-on)
- Signing in to the product with your company's existing identity system instead of a separate password. Often sold as an extra. If you need it, ask whether it is included at your price level.
- MFA (multi-factor authentication)
- A second proof of identity at sign-in, such as a code or a passkey. Ask whether you can require it for all users.
- SOC 2 report
- An independent auditor's report on a company's security controls. A "Type 1" report describes the controls at a point in time; a "Type 2" report covers whether they operated over a period. Ask to see the report itself, under confidentiality, not a logo.
- Data residency
- The country or region where your data is stored. Matters if a law or a customer contract restricts where it may be held.
Connecting and moving data
- API
- A documented way for other software to read from and write to the product. Public documentation you can read before buying is a good sign.
- Integration
- A working connection between the product and another system. Ask who built it, who maintains it, and what happens to records when the other system is unavailable.
- Webhook
- A message the product sends to another system when something happens, such as a status change. One of the building blocks of an integration.
- Migration
- Moving your existing records into the new product. Usually the largest hidden cost of a purchase, and the part a demo shows least.
- Export
- Getting your records out in a file another system can read. Check that it includes history and attachments. An export you have tested is your protection against being locked in.
Commercial and contract terms
- SaaS (software as a service)
- Software run by the vendor and used over the internet for a recurring fee, as opposed to software you install and run yourself.
- RFP (request for proposal)
- A written list of requirements sent to several vendors for a formal response. Answers in an RFP are claims; a scorecard records which of them you later saw.
- MSA (master services agreement)
- The main contract between you and the vendor, covering liability, termination and renewal.
- SLA (service level agreement)
- The contractual commitment on availability and support response, with what you receive if it is missed. A figure on a website is a target; a figure in the SLA is a term.
- DPA (data processing agreement)
- The agreement covering how the vendor handles personal data on your behalf. Needed before real personal data goes into any environment, including a proof of concept.
- NDA (non-disclosure agreement)
- A confidentiality agreement. Normal before sharing real data or seeing a security report.
- Auto-renewal
- A contract term that renews the subscription unless you give notice by a set date. Find the date and put it in a calendar before signing.
- Total cost of ownership
- Everything the product costs over its life: license fees, setup, migration, integrations, training and your own staff's time. The quoted price is one part of it.
Using the vocabulary
Most confusion in an evaluation comes from two people using one of these words differently. When a vendor says "we will set you up with a trial", ask whether that means a shared sandbox, a private environment or a structured proof of concept. The checklist and what a demo hides use the terms as defined here.