Leadership1 distinct publisher3 min readUpdated
One vendor reports buyer questionnaires growing at least tenfold, now demanding customer-controlled identity, exportable logs, data residency and a no-AI-training promise. The build comes before the signature.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The workbook functions as a specification, and it arrives before the money does. Each row asking whether access follows the buyer's own identity provider, whether logs can be exported into their monitoring tools, where the data physically lives and whether any customer content trains an AI model [4] is a build item with a contract date attached to it, and the date falls before signature.
Not every row costs the same. Following Microsoft Entra groups, enforcing MFA and conditional access, and deprovisioning a departing administrator quickly [6] is integration work of a known shape. Making the permission model govern reports, admin views, exports and integrations exactly as it governs the main interface [7] is harder, because every surface that emits data has to agree with every other one. Unlu writes that he is repeatedly asked to show which roles can open compensation-related notes, then show what the export contains, on the logic that an export revealing more than the interface means a boundary has been moved [8]. That is a test a small team can fail quietly for years, because nobody opens the CSV during a demo.
Keys and geography are the expensive end. Encryption at rest and in transit is now the floor [16], and above it sit questions about where keys are stored, who can reach them, how they rotate and who manages them [16]. Customer-managed keys, dedicated environments and regional controls add cost and complexity, and Unlu reports they are entering procurement conversations for regulated industries and large global enterprises [9]. A shared multi-tenant deployment does not acquire per-customer residency through a settings change.
The arithmetic deserves stating plainly. Roughly 20 questions then [2], hundreds of rows across multiple tabs now [3], which is an increase of at least ten times in question count [14]. The older set could be closed by attaching documents the vendor already had [2]; the current set comes with evidence requests [3]. SOC 2, ISO 27001 and penetration tests attest to a prior period and act as the entry requirement [10], while the buyer's exposure is present-tense, which is why the ask is for access reviews, audit trails, incident history and exportable logs on a continuous basis [11].
A caveat about provenance. This is one vendor's account, published as a Forbes Tech Council contribution [15], and Unlu sells performance management software built for Microsoft 365 [1]. A vendor whose product is already wired into Entra benefits when buyers treat Entra alignment as the standard. The one figure not drawn from his own pipeline is Gartner's: sovereign-cloud spending reaching $80 billion in 2026, with a fifth of workloads moving from global providers to local ones [13].
For a small vendor selling into large enterprises, this is an ordering problem more than a budget one. The controls have to exist before the first enterprise deal, so that deal funds none of them and is priced against work already finished, in a category where the stored text includes manager assessments, promotion notes and compensation-related comments [5]. The vendors who lose these cycles will not lose them on price.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Unlu says that when his company closed its first enterprise customers, the security review felt like a procurement step: a spreadsheet of roughly 20 questions on encryption, backups, password policies, access controls and incident response, answered by attaching documents the company already had.
Unlu says security reviews today arrive as Excel workbooks with hundreds of rows, multiple tabs and evidence requests.
Customer-managed keys, dedicated environments and regional controls add cost and complexity, and for regulated industries and large global enterprises they are becoming part of the procurement conversation.
Bora Unlu is the co-founder and CEO of Teamflect, a performance management and employee engagement platform designed for Microsoft 365.
Buyers now ask which roles can open sensitive employee notes, whether access follows their own identity provider, how quickly access can be revoked, whether logs can be exported into their monitoring tools, where the data physically lives, and whether any customer content trains an AI model.
Performance management systems hold manager assessments, promotion notes, compensation-related comments and career plans, content that can affect someone's career.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single self-interested account, no primary documents
All content derives from one Forbes Tech Council contribution written by the CEO of a vendor in the category discussed. The descriptive claims about buyer questions, permission parity, key management and continuous proof are coherent and specific, which lends some weight, but there is no questionnaire artifact, no audit report, no buyer-side confirmation and no linked primary source for the one market statistic offered. Nothing in the cluster can be cross-checked against a second publisher.
One first-party anecdote, no measured breadth
Adoption evidence is limited to a single vendor's disclosure that its own inbound security reviews escalated in length and specificity, plus unquantified assertions that SOC 2/ISO 27001 are 'mandatory in many enterprise sales cycles' and that customer-managed keys and regional controls are 'becoming part of the procurement conversation' for regulated and global buyers. There are no counts of buyers, deals, questionnaires, regions or feature deployments, and the sovereign-cloud number is a forecast rather than observed usage. That supports a low, non-zero adoption reading of the customer-control trend rather than a measured one.
Generalized 'new standard' framing outruns n=1 evidence
The piece presents an industry-wide 'new standard for enterprise SaaS security' and an at-least tenfold questionnaire increase on the strength of one vendor's recollection and one uncited analyst figure, which overstates the evidentiary base. The gap is moderate rather than severe because the underlying mechanics — IdP-bound access, permission parity across exports, key custody, data residency, AI-training terms — are described concretely and the cluster's own dek correctly attributes the tenfold figure to a single vendor rather than the market.
Vendor CEO in a paid contributor channel arguing his own category up
The author sells the exact product class the article says now requires heavy security scrutiny, and the piece appears in Forbes Tech Council, a membership contributor channel that publishes vendor executives without independent verification. A narrative in which enterprise buyers demand customer-controlled identity, key custody, regional hosting and no-AI-training guarantees directly favours an incumbent Microsoft 365-native HR vendor positioned to answer those questions, and the article supplies no disclosure or countervailing view.
Low: coherent but uncorroborated and conflicted
Confidence is constrained by a single publisher, a single self-interested author, and no primary or independent artifacts, with the one third-party statistic unverifiable as supplied. It is not lower because the operational claims are specific, internally consistent and of a kind that practitioners can test directly, and because the cluster framing already hedges the quantitative claim to one vendor.
leadership
Gartner says agents aren't ready; 60% of companies plan to deploy them anyway1 distinct publisher
build
Your change-management evidence assumes a human. Claude does not sign commits.1 distinct publisher
leadership
Your controls passed the configuration check. Nobody asked whether they stop attacks1 distinct publisher
security
A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026