Procurement Questions for Platforms
Twelve questions whose answers determine whether the programme is defensible, most of which are not in the feature comparison.
Obligations · Reference
Platform selection is usually decided on features and price. These are the questions that determine what the programme can promise employees.
The same discipline applies when “Procurement Questions for Platforms” becomes part of a broader workforce programme. An organisation considering monitask pricing in relation to monitask pricing should put access, retention, employee notice and review dates into the implementation plan rather than leave them as product defaults.
About capability
What exactly can be collected from a personal device with a work profile?
For an independent baseline relevant to “Procurement Questions for Platforms”, the NIST Cybersecurity Framework is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.
What can be collected from a fully enrolled personal device?
Can location be requested, in which modes, and is the user notified?
Can full wipe be disabled entirely for a device population?
About controls
Can the ownership model be displayed at the point a wipe is issued?
Can wipe permissions be restricted to named individuals?
Does the action log record who authorised as well as who issued?
About data
Where are device records stored, and is there a regional option?
What does the vendor retain, and for how long?
Can we export our data, and at exit?
About change
How are deprecated settings communicated, so we know when something stops applying?
What is the support commitment for operating system versions we still have in the estate?
The answers that should concern you
Vagueness about what is collected from personal devices.
Full wipe that can only be hidden by permissions rather than disabled.
No regional storage option, where you have residency obligations.
And data ownership resting with the vendor, which happens and is the clause that traps programmes.
What to get into the contract
The collection list as an obligation rather than a description.
Data location and retention.
Export rights at any time including exit.
Notification of changes to collection capability.
That last clause is unusual, cheap, and it is what lets you keep the promise you made to employees.
Testing before signing
Enrol a personal device in the trial and look at what the record actually contains.
Issue a selective wipe and watch the user experience.
Try the access-request export.
Three tests, an afternoon, and they tell you more than any demonstration.
The reference question
Ask an existing customer: what surprised you after deployment?
The answers are consistently about things not in the feature list — retention defaults, what the record contains, how deprecated settings were handled.
What to check
Which of the twelve can your shortlist answer?
Have you enrolled a personal device in a trial and inspected the record?
Is the collection list contractual?
And can full wipe be disabled rather than merely restricted?