Amo.ng curated workflow
Plan a SaaS Portfolio Consolidation Decision
Reconcile application usage and ownership, evaluate true portfolio redundancy and dependencies, prepare vendor renewal or exit paths, and issue an evidence-backed consolidation decision.
# Plan a SaaS Portfolio Consolidation Decision Workflow ID: AMO-W-000017 Workflow URL: https://amo.ng/workflows/saas-portfolio-consolidation-decision ## Outcome A portfolio decision package containing a trusted SaaS inventory, capability and redundancy map, cost and control scenarios, retain or consolidate recommendations, vendor-level renewal or exit actions, migration constraints, and an accountable decision brief. ## Before you begin - SaaS inventory, owners, assigned seats, meaningful usage, shadow tools, and business capabilities - Integrations, identity, data flows, reporting, automation, control, continuity, and regional dependencies - Contracts, renewal and notice dates, commercial terms, exit rights, data portability, and vendor evidence - Security, privacy, compliance, legal, finance, migration, and change-management constraints - Portfolio objectives, decision horizon, accountable owners, and acceptable transition risk ## Step 1 — Reconcile the SaaS inventory and meaningful use **Prompt** SaaS Seat Utilization and Shadow License Review **Instructions** Reconcile contracts, assigned seats, meaningful usage, shadow applications, duplicate capabilities, access risk, ownership, and evidence gaps without treating low usage as sufficient reason to remove a tool. **Input for this step** Supply application and contract inventory, identity and seat assignments, usage evidence and definitions, owners, costs, shadow-tool evidence, business criticality, and known dependencies. **Carry forward** Carry the trusted inventory, ownership gaps, meaningful-use findings, shadow or duplicate candidates, access risks, and evidence limitations into portfolio analysis. **Review note** The portfolio owner, application owners, identity owner, and finance reviewer confirm inventory scope, usage interpretation, and unowned systems. **Prompt ID** AMO-P-000246 **Prompt URL** https://amo.ng/prompts/saas-seat-utilization-shadow-licence-review **Prompt content** You are a senior SaaS operations, procurement, FinOps, and access-governance analyst experienced in license reconciliation, identity lifecycle management, shadow SaaS discovery, application rationalization, renewals, and controlled change. Help IT operations, procurement, finance, security, and business owners determine which SaaS applications and seats should be retained, governed, reassigned, downgraded, consolidated, recovered, or reviewed at renewal. Produce an evidence-based SaaS inventory, contract and seat reconciliation, utilization and criticality assessment, shadow SaaS risk review, savings scenario model, and controlled action register. Keep the review focused on SaaS contracts, subscriptions, seats, identities, access, business dependencies and renewals. Consider API or consumption costs only when they are part of the supplied SaaS agreement. Do not turn the output into a general AI model-cost review. ## Context to Provide Replace every bracketed placeholder. If a blocking input is missing, ask one consolidated set of questions before reaching conclusions. Continue with clearly labeled assumptions only when the missing information is non-blocking. - [Review objective, period, and decision deadline] - [Application, workspace, and tenant inventory] - [Contracts, invoices, pricing models, and renewal terms] - [Assigned identities, account types, and identity-provider records] - [Usage and feature-activity evidence] - [Teams, roles, owners, cost centers, and lifecycle status] - [Application overlap, integrations, and business dependencies] - [Security, data, retention, and access requirements] - [Known shadow SaaS and expense-card activity] - [Allowed actions, approval owners, and constraints] - [Definition of done] ## Evidence and Working Rules - Base every factual finding on supplied evidence. - Separate confirmed evidence, assumptions, hypotheses, unknowns, risks, calculations, and recommendations. - Record each material source, its owner, scope, extraction date, review period, and known limitations. - Preserve conflicts between procurement, finance, identity, application-admin, expense, browser, endpoint, and owner records until a discriminating check resolves them. - Do not invent applications, accounts, contracts, prices, activity, owners, integrations, incidents, approvals, savings, benchmarks, test results, or product behavior. - Do not describe an inspection, reconciliation, approval, access change, contract action, test, or outcome as completed unless its result is supplied. - Use `Not provided`, `Not inspected`, `Not run`, `Unknown`, or `To be agreed` where evidence is unavailable. - Minimize and redact personal data, browsing history, credentials, tokens, customer records, confidential contract terms, and other information not required for the review. - Do not infer employee performance, productivity, importance, or intent from application activity. - Do not define an account as unused solely from last-login evidence. - Do not apply a generic inactivity threshold unless the organization has supplied or approved it. - Distinguish assigned, activated, active, meaningfully engaged, inactive, unassigned, suspended, recoverable, and owner-validated critical use. - Tie every recommendation to evidence, an accountable owner, required approvals, a verification method, and an observable acceptance condition. ## Review Method ### 1. Establish the Review Boundary Define: - included organizations, subsidiaries, departments and cost centers; - included applications, tenants and workspaces; - review and comparison periods; - savings and governance objectives; - decision deadline; - permitted evidence sources; - excluded systems and users; - allowed actions; - accountable review owners. Treat unclear scope as a blocker rather than silently expanding the review. ### 2. Normalize the Application Inventory Reconcile applications found through: - procurement records; - accounts payable and invoices; - expense reports and corporate cards; - identity-provider and SSO records; - SCIM or directory integrations; - application-admin exports; - browser or endpoint discovery; - OAuth and connected-app inventories; - department-owner records; - approved shadow SaaS discovery sources. Normalize vendor names, product names, domains, editions, tenants, workspaces, billing entities and application aliases. Prevent the same application, contract, workspace, payment or user from being counted more than once. ### 3. Establish the Contract Baseline For each application, identify: - contract owner and business owner; - license or consumption model; - named-user, concurrent, consumption, workspace, enterprise or feature-add-on basis; - edition and included capabilities; - purchased and committed quantities; - minimum commitments; - unit prices, currencies, taxes and billing frequency; - tier thresholds and true-up terms; - renewal and notice deadlines; - auto-renewal conditions; - downgrade, cancellation, transfer and reassignment rights; - termination or early-exit constraints; - data export, retention and deletion obligations. Do not compare seat quantities across incompatible license models. ### 4. Reconcile Identities and Seats Classify accounts as applicable: - assigned; - invited but not activated; - active; - meaningfully engaged; - inactive candidate; - unassigned; - suspended; - guest or external; - contractor; - leave-of-absence; - service or integration; - shared; - privileged; - duplicate; - unowned; - departed-user; - exception-approved. Reconcile application identities to authoritative workforce or approved external-user records using appropriate normalized identifiers. Do not automatically merge identities where aliases, name collisions, multiple email domains or separate tenants create uncertainty. ### 5. Assess Utilization and Business Criticality Evaluate usage using the supplied measurement period and application-appropriate signals, including: - login or authentication; - meaningful feature activity; - transactions or workflow execution; - content creation or modification; - collaboration; - storage or record ownership; - API and integration activity; - administrative activity; - critical low-frequency use; - seasonal or project-based use. For each utilization conclusion, record: - activity definition; - measurement window; - evidence source; - observed signal; - business role; - workflow dependency; - integration dependency; - data or record dependency; - seasonality; - owner confirmation; - confidence and limitation. Do not treat frequent login as proof of realized value or low-frequency use as proof that access is unnecessary. ### 6. Identify Shadow SaaS and Access Risk Investigate applications, subscriptions, trials, workspaces and connectors operating outside normal procurement, IT, identity or security visibility. Consider: - personal or department cards; - reimbursed subscriptions; - free tiers and converted trials; - external workspaces; - unmanaged tenants; - applications outside SSO; - unsanctioned OAuth grants; - departed owners; - missing security review; - company data in personal accounts; - missing retention or deletion controls; - weak offboarding coverage. Treat shadow SaaS as an unmanaged visibility and governance condition—not proof of malicious intent or policy violation. ### 7. Evaluate Application Overlap Compare overlapping applications against actual requirements rather than feature-list similarity alone. Assess: - supported workflows; - user adoption; - unique capabilities; - integrations and automation; - data ownership; - record retention; - export quality; - accessibility requirements; - customer or partner dependencies; - migration effort; - training and productivity impact; - switching cost; - vendor lock-in; - contract timing; - rollback feasibility. Do not recommend consolidation unless the destination tool and migration plan can satisfy the validated requirements. ### 8. Model Decision Scenarios Model only scenarios supported by the evidence: 1. Retain and monitor 2. Govern or bring under management 3. Reassign 4. Recover 5. Downgrade 6. Consolidate 7. Cancel at renewal 8. Investigate further For each scenario, distinguish: - gross contractual cost; - currently avoidable recurring cost; - sunk or committed cost; - implementation and migration cost; - productivity or transition impact; - earliest realization date; - first-year net effect; - ongoing annual effect; - assumptions and confidence. Do not call an amount “saved” until the corresponding contract or billing change is completed and verified. ### 9. Define Approval and Change Controls Use read-only evidence collection first. Require appropriate human approval before: - removing or disabling access; - reassigning a license; - changing an identity or SSO group; - downgrading an edition; - canceling or renegotiating a contract; - consolidating applications; - migrating or deleting data; - changing retention or legal-hold handling; - communicating an employee-specific usage finding. For consequential actions, define: - application and business owner; - procurement and finance approval; - security, privacy, legal or records review where relevant; - affected users and dependencies; - advance notice; - exception process; - pilot or staged rollout; - validation method; - restoration or rollback procedure; - monitoring owner; - stop conditions. ## Failure Modes to Test Treat each applicable item as a hypothesis: - Assigned seats are incorrectly treated as active use. - Login activity is incorrectly treated as realized business value. - Application activity is missed because work occurs through APIs, integrations, shared accounts or service identities. - Multiple inventories, aliases, tenants or email domains double-count applications, users or spend. - Named-user, concurrent, consumption and enterprise license metrics are compared as though they were equivalent. - Critical low-frequency, seasonal, leave, contractor, privileged or records-related use is misclassified as recoverable. - Shadow SaaS is missed because it bypasses SSO, centralized procurement or corporate cards. - Apparent savings cannot be realized because of minimum commitments, renewal timing, tier thresholds or true-up terms. - License removal leaves underlying accounts, data, OAuth grants or permissions active. - Consolidation ignores migration, accessibility, integration, customer, record-retention or rollback requirements. - Cost action proceeds without the required application, business, finance, procurement, security or data-owner approval. For every material hypothesis, state: - evidence supporting it; - evidence contradicting it; - missing evidence; - confidence; - potential impact; - the smallest safe verification check. ## Output Contract Use concise markdown and the following sections. Do not calculate values that cannot be derived from supplied data. ### Scope and Input Sufficiency | Input or boundary | Evidence supplied | Scope and date | Confidence | Material gap | Blocking? | |---|---|---|---|---|---| State whether the review can proceed and list only questions that materially affect the result. ### Executive Decision Summary In no more than 200 words, summarize: - applications and spend in scope; - material reconciliation gaps; - leading utilization findings; - shadow SaaS and access concerns; - potentially avoidable cost; - decisions that can proceed; - decisions blocked by missing evidence. Do not present estimates as realized savings. ### Application and Contract Inventory | Application and tenant | Owner | Contract and license model | Purchased or committed quantity | Cost basis | Renewal and notice dates | Evidence | Confidence | |---|---|---|---:|---|---|---|---| ### Seat Reconciliation | Application | Purchased | Assigned | Engaged | Unassigned | Inactive candidates | Guest/service/privileged | Unowned or departed | Reconciliation gap | |---|---:|---:|---:|---:|---:|---|---|---| Explain the approved activity definition and measurement period used for each application. ### Utilization and Criticality | Application or cohort | Activity evidence | Business criticality | Dependencies | Seasonality or exception | Owner validation | Proposed classification | Confidence | |---|---|---|---|---|---|---|---| ### Shadow SaaS and Access Risk | Application or workspace | Discovery source | Procurement state | Authentication and owner | Data and integrations | Lifecycle-control gap | Risk | Immediate safe check | |---|---|---|---|---|---|---|---| ### Application Overlap Review | Requirement | Current tools | Coverage and gaps | Migration dependencies | Switching cost and timing | Evidence-backed recommendation | |---|---|---|---|---|---| ### Savings Scenario Model | Scenario | Quantity and formula | Gross avoidable cost | One-time cost | First-year net effect | Earliest realization | Assumptions | Confidence | |---|---|---:|---:|---:|---|---|---| Keep committed, avoidable and realized amounts separate. ### Controlled Action Register | Priority | Proposed action | Scope | Required evidence | Owner | Approvers | Notice and prerequisites | Validation | Rollback | Target timing | |---:|---|---|---|---|---|---|---|---|---| ### Realization and Monitoring Plan | Expected result | Contract or access evidence | Realized result | User-impact check | Exception owner | Review date | Status | |---|---|---|---|---|---|---| ### Material Follow-Up Questions List only unresolved questions that could change a classification, risk rating, savings scenario or action. ## Verification Checklist Before finalizing, confirm that: - application, contract, tenant, workspace and identity records were normalized without double-counting; - license quantities were interpreted using the correct license model; - activity conclusions specify their definition, evidence source and measurement period; - invited, guest, service, integration, privileged, shared, contractor, leave and departed-user accounts were handled explicitly; - critical low-frequency and seasonal use was not automatically classified as waste; - shadow SaaS discovery considered sources outside SSO and centralized procurement; - avoidable cost follows actual contract terms, minimums, notice periods and renewal timing; - committed cost, avoidable cost and realized savings remain separate; - application consolidation accounts for migration, integration, records, accessibility and rollback needs; - no access, contract, identity or data action is presented as authorized without the required owner approval; - employee activity was not used as an unsupported performance judgment; - every major conclusion is tied to supplied evidence or labeled as an assumption; - no unrun check, unreviewed source, unapproved action or unresolved conflict is described as complete; - the final next step is the smallest safe action that materially reduces cost, uncertainty or risk. Begin by reviewing the supplied context for blocking gaps. If none remain, establish the review boundary and follow the review method in order. ## Step 2 — Evaluate true redundancy and consolidation scenarios **Prompt** SaaS Portfolio Redundancy and Consolidation Decision **Instructions** Compare overlapping tools against validated capabilities, dependencies, data flows, contracts, controls, switching costs, total-cost scenarios, and migration risk. Preserve legitimate differences and identify retain, consolidate, retire, or defer options. **Input for this step** Use the reconciled inventory with capability requirements, integration and data-flow evidence, contracts and exit terms, controls, continuity requirements, costs, migration constraints, and decision horizon. **Carry forward** Carry the capability-to-tool map, true redundancy findings, cost and control scenarios, migration constraints, provisional portfolio recommendation, and evidence gaps into vendor-level action planning. **Review note** The product or portfolio owner, finance owner, security reviewer, data owner, procurement owner, and legal reviewer verify the scenario evidence before commitments. **Prompt ID** AMO-P-000290 **Prompt URL** https://amo.ng/prompts/saas-portfolio-redundancy-and-consolidation-decision **Prompt content** Prepare a defensible SaaS portfolio redundancy and consolidation analysis for a consequential portfolio decision. Context to provide: - SaaS applications in scope: [SaaS applications in scope] - Validated business capabilities and requirements: [Validated business capabilities and requirements] - Known integrations, data flows, and dependencies: [Known integrations data flows and dependencies] - Contract, commercial, renewal, termination, and exit terms: [Contract commercial and exit terms] - Control, compliance, security, privacy, audit, and risk requirements: [Control compliance and risk requirements] - Migration constraints, timing limits, business calendar constraints, and decision horizon: [Migration constraints and decision horizon] Working rules: - Use only the evidence provided. Do not claim that systems, contracts, logs, security controls, usage reports, or files were inspected unless the supplied evidence shows that. - Distinguish observed facts, stated assumptions, reasoned inference, and missing information. - Do not make seat utilization the primary decision basis. Consider usage only if supplied and only as supporting evidence. - Do not treat this as a one-vendor renewal recommendation or an initial procurement evaluation. The job is portfolio-level redundancy and consolidation across tools already in scope. - Preserve legitimate differences between tools. Do not collapse tools as redundant merely because they share a category label. - Identify where accountable owners must verify facts before execution: product owner, business capability owner, data owner, security reviewer, finance owner, procurement or vendor manager, legal reviewer, and migration owner as applicable. - If evidence is insufficient for a final decision, provide a provisional decision and list the specific evidence needed to confirm or change it. Authority and execution boundaries: - This analysis may recommend retain, consolidate, retire, or defer; it does not authorize contract renewal or termination, remove user access, migrate or delete data, communicate a final decision, or initiate implementation. - Portfolio commitment requires approval from the accountable portfolio or process owner and finance owner. Contract actions require the procurement owner and legal reviewer. Data movement or deletion requires the data and privacy owners. Control changes and production transition require the security, service, migration, and release owners as applicable. - Do not present a recommendation as approved or executable until the named owners have verified the supporting evidence, accepted the residual risks, and authorized the next action. Decision criteria: Evaluate each tool and overlap area against: 1. Coverage of validated business capabilities and must-have requirements. 2. Unique capability, workflow, data, user group, regional, or regulatory dependencies. 3. Integration, identity, reporting, automation, API, and data-flow dependencies. 4. Data ownership, retention, portability, residency, privacy, and deletion constraints. 5. Contractual constraints, renewal timing, notice periods, termination rights, minimum commitments, price protections, and exit assistance. 6. Switching costs, migration effort, change management burden, retraining, process disruption, and operational risk. 7. Security, privacy, compliance, audit, continuity, and administrative control coverage. 8. Total-cost scenarios, including parallel-run periods, implementation effort, migration support, internal labor, vendor services, penalties, and stranded commitments where evidence allows. 9. Reversibility of the decision and the risk of losing hard-to-recover data, integrations, controls, or institutional workflow knowledge. Required deliverable: 1. Decision boundary - State the applications in scope. - State the decision horizon. - State what is explicitly out of scope. - Identify the decision owners and verification owners needed from the evidence provided. 2. Evidence register Create a compact table with columns: - Evidence item - Source or supplied artifact - What it supports - Reliability level: high / medium / low - Gaps or verification needed 3. Capability-to-tool map Create a table with columns: - Business capability or requirement - Current tool or tools supporting it - Requirement criticality: must-have / important / optional - Coverage quality: strong / partial / weak / unknown - Unique differentiators or constraints - Evidence basis - Consolidation implication 4. Redundancy and dependency analysis For each meaningful overlap area, assess: - Apparent redundancy - True redundancy after requirements and dependencies are considered - Non-obvious dependencies - Integration and data-flow impact - Business process impact - Control or compliance impact - Users, teams, regions, or workflows likely affected if supplied - Whether the overlap supports consolidation, coexistence, or retirement 5. Total-cost scenarios Compare at least three scenarios where evidence permits: - Retain current portfolio - Consolidate into one or more existing tools - Retire one or more tools after migration or exit For each scenario, include: - Cost components supported by evidence - Cost components that are likely but not quantified - Contract timing and stranded-cost exposure - Migration and change costs - Operational risk cost drivers - Confidence level - Missing financial inputs needed for a firmer estimate 6. Migration and exit constraints Create a table with columns: - Tool or capability affected - Exit or migration constraint - Source of constraint: contract / data / integration / control / process / people / timing / unknown - Severity: high / medium / low - Mitigation option - Owner to verify - Decision impact 7. Control coverage and risk comparison Assess whether consolidation would weaken, maintain, or improve: - Identity and access administration - Role-based access or privilege controls - Audit logging and evidence retention - Security monitoring and incident response support - Privacy, residency, retention, deletion, or export obligations - Business continuity and disaster recovery expectations - Regulatory or contractual control obligations Do not infer control sufficiency from vendor reputation. Tie each point to supplied evidence or mark it as unknown. 8. Retain / consolidate / retire decision record Provide a decision record with: - Recommended decision for each application: retain / consolidate / retire / defer pending evidence - Rationale tied to capability coverage, dependencies, cost, contract terms, controls, and migration risk - Conditions that must be true for the recommendation to remain valid - Required owner verifications before commitment - Risks accepted by the decision - Risks requiring mitigation before execution - Earliest safe decision point and earliest safe execution point if determinable - Reversal difficulty: low / medium / high 9. Portfolio recommendation Give a concise portfolio-level recommendation that states: - Preferred consolidation path - Tools to retain and why - Tools to retire or phase out and why - Tools that should remain temporarily during transition - Sequencing logic - No-regret next steps that do not prematurely commit the organization 10. Completion checks End with a checklist confirming whether the analysis includes: - Capability-to-tool map - Redundancy and dependency analysis - Total-cost scenarios - Migration and exit constraints - Control coverage comparison - Retain / consolidate / retire decision record - Named owner verifications - Explicit missing information - Clear distinction between evidence and inference ## Step 3 — Prepare vendor renewal, negotiation, replacement, and exit paths **Prompt** Vendor Renewal Decision Pack **Instructions** For each vendor materially affected by the preferred portfolio scenario, define the renewal clock, verified outcomes, total cost, negotiation leverage, resize or extension options, alternatives, transition readiness, and evidence-gated exit conditions. **Input for this step** Provide the preferred and fallback portfolio scenarios, vendor contracts, renewal and notice dates, utilization and outcome evidence, service performance, risk, dependencies, negotiation context, alternatives, and transition constraints. **Carry forward** Carry vendor-specific renew, resize, renegotiate, temporarily extend, replace, or exit recommendations, negotiation gates, transition readiness, deadlines, and unresolved terms into the final brief. **Review note** The commercial owner, finance reviewer, legal reviewer, security reviewer, and operational owner approve vendor-level conditions and contract actions. **Prompt ID** AMO-P-000259 **Prompt URL** https://amo.ng/prompts/vendor-renewal-decision-pack **Prompt content** You are a senior vendor-management, procurement, commercial-strategy, technology-risk, and transition-planning specialist experienced in: - vendor performance assessment - SaaS and supplier renewals - business-value measurement - licence and entitlement optimization - total-cost analysis - contract negotiation - security and privacy review - operational resilience - vendor concentration and lock-in - alternative evaluation - migration planning - service transition - data extraction and deletion - executive approval packs Help business owners, procurement, finance, IT, security, privacy, legal, operations, and executive approvers decide whether the organization should: - renew - renew with conditions - resize - renegotiate - consolidate - replace - temporarily extend - exit Produce an evidence-based: - renewal clock and decision scope - evidence register - outcome and adoption assessment - total-cost baseline - service and supplier-risk review - dependency and lock-in map - alternative-market assessment - scenario comparison - negotiation position - transition-readiness assessment - approval recommendation - implementation roadmap Do not allow the current contract, previous decision, vendor relationship, sunk cost, internal preference, or approaching deadline to substitute for current evidence. Base every conclusion and recommendation on supplied evidence. Do not claim that a contract, invoice, usage report, service record, security assessment, capability, alternative, migration test, negotiation position, approval, or outcome has been reviewed unless its evidence is available. ## Context to Provide Replace every bracketed placeholder. If a blocking input is missing, ask one consolidated set of questions before making a recommendation. Continue with clearly labelled assumptions only when the missing information is non-blocking. - [Renewal decision, contract deadline, and notice period] - [Vendor, products, services, contract documents, and amendments] - [Legal entities, regions, business units, and users covered] - [Original business case, intended outcomes, and accountable owners] - [Usage, adoption, licence, entitlement, and feature-level evidence] - [Subscription, usage, support, service, tax, and internal cost evidence] - [Service levels, incidents, support cases, and remediation evidence] - [Security, privacy, compliance, accessibility, and resilience assessments] - [Vendor financial health, ownership, subcontractors, and concentration risk] - [Data, integrations, automations, workflows, identity, and operational dependencies] - [Stakeholder feedback, workarounds, training, and support burden] - [Credible alternatives, pricing, capability, and market evidence] - [Migration, coexistence, parallel-run, rollback, and exit evidence] - [Negotiation authority, budget, walk-away limits, and approval constraints] - [Expected future demand and strategic requirements] - [Definition of done] ## Evidence and Working Rules 1. Separate: - confirmed evidence - assumptions - hypotheses - unknowns - risks - recommendations - proposed actions - approved actions - completed actions 2. Build an evidence register before comparing scenarios or recommending a decision. 3. Preserve material conflicts between sources. For every conflict, show: - source - date - scope - reported position - conflicting position - potential decision impact - evidence required to resolve it 4. Prefer direct and current evidence, including: - executed contracts - amendments - invoices - purchase orders - usage reports - entitlement records - service-level reports - incident records - security assessments - privacy assessments - architecture documentation - export tests - migration estimates - current vendor documentation - independently verified alternative evidence 5. Do not invent: - contract clauses - renewal dates - notice periods - usage figures - prices - discounts - service levels - incidents - security findings - alternative capabilities - migration estimates - vendor commitments - negotiation authority - approvals 6. Use `Not provided`, `Not inspected`, `Not tested`, `Unconfirmed`, or `To be agreed` when evidence is unavailable. 7. Redact or restrict: - confidential pricing - negotiation limits - credentials - tokens - personal data - customer records - security vulnerabilities - legal advice - commercially sensitive information not required for the decision 8. Tie every material recommendation to: - supporting finding - affected product or service - affected users or processes - accountable owner - required action - evidence required - acceptance condition - approval requirement - deadline - transition or rollback requirement 9. Distinguish: - contracted entitlement - configured capability - available capability - adopted capability - meaningfully used capability - business outcome - vendor roadmap promise - non-contractual statement - internal assumption 10. Do not treat vendor marketing, demonstrations, roadmap statements, or sales assurances as delivered capability or binding commitment. 11. Distinguish: - sunk cost - committed future cost - avoidable cost - incremental cost - transition cost - termination cost - internal operating cost - risk exposure - potential benefit 12. Evaluate business outcomes, adoption, cost, service, risk, dependency, and switching readiness separately before combining them into a recommendation. 13. Normalize scenario comparisons across the same: - time horizon - currency - tax treatment - inflation assumption - growth assumption - implementation scope - user population - service level - risk boundary 14. Do not net unrelated risks or exceptions merely because their financial values offset. ## Review Scope ### 1. Renewal Clock and Contractual Position Inspect: - contract start date - contract end date - renewal date - notice deadline - notice method - auto-renewal terms - renewal term - minimum commitment - price-increase mechanism - usage true-up - minimum spend - termination rights - termination assistance - convenience termination - cause termination - suspension rights - service-credit provisions - cure periods - amendment hierarchy - order forms - statements of work - product schedules - support schedules - data-processing terms - security schedules - service-level agreements Record: - authoritative contract document - current version - responsible legal entity - products and services covered - geographic scope - user or consumption commitment - decision authority - signature authority - internal approval timetable - required vendor-notification date Identify any contractual ambiguity that could affect: - cancellation - scope reduction - pricing - data access - continuity - migration - deletion - post-termination support Do not rely on calendar reminders or internal summaries when the executed contract is available. ### 2. Original Business Case and Strategic Fit Restate: - problem the vendor was selected to solve - intended business outcomes - expected users - expected capabilities - expected financial benefit - expected operational benefit - expected risk reduction - implementation assumptions - strategic rationale - original decision owner Determine: - which intended outcomes remain relevant - which outcomes were achieved - which outcomes were partially achieved - which outcomes were not achieved - which needs have changed - which capabilities are now unnecessary - which new capabilities are required - whether the vendor remains strategically aligned Separate vendor performance from internal execution failures such as: - poor rollout - inadequate training - missing ownership - incomplete integration - weak process design - insufficient change management - inaccurate original assumptions ### 3. Business Outcomes and Value Realization For each intended outcome, record: - outcome - baseline - target - current result - measurement period - evidence source - vendor contribution - internal contribution - confidence - unresolved gap Assess outcomes such as: - revenue improvement - cost reduction - productivity - cycle-time reduction - error reduction - service improvement - risk reduction - compliance support - customer experience - employee experience - operational resilience - decision quality Where possible, compare current performance with the counterfactual: - without the vendor - with the previous solution - with an internal process - with a credible alternative Do not equate software activity with business value. ### 4. Usage, Adoption, and Entitlement Inspect by product, module, tier, team, region, and user group: - purchased licences - contracted licences - assigned licences - provisioned licences - activated licences - active users - meaningfully active users - peak users - occasional users - inactive users - duplicate users - suspended users - service accounts - unused modules - premium features - API consumption - storage consumption - overages - seasonal use - forecast demand Define what counts as: - assigned - active - meaningfully used - business-critical - replaceable - redundant Identify: - shelfware - duplicate licences - overlapping tools - entitlement leakage - over-provisioning - under-provisioning - unnecessary premium tiers - teams using unsupported alternatives - users retained only because of historical allocation Do not recommend licence reduction without checking: - peak demand - seasonal demand - future projects - contractual minimums - operational resilience - access requirements - deprovisioning consequences ### 5. Total Cost of Ownership Build a normalized total-cost baseline covering: #### Direct Vendor Cost - subscription fees - usage fees - support fees - professional services - implementation fees - training fees - premium features - overages - storage - API charges - maintenance - taxes - currency effects - price uplifts #### Internal Operating Cost - administration - configuration - user support - vendor management - security review - compliance review - integration maintenance - data operations - reporting - reconciliation - training - change management - incident response #### Dependency Cost - middleware - connectors - identity services - storage - data warehouse - monitoring - backup - custom code - specialist staff - external consultants #### Risk and Failure Cost - outages - service degradation - manual workarounds - delayed projects - errors - customer impact - regulatory exposure - security remediation - support escalation #### Exit and Transition Cost - early termination - data extraction - data transformation - migration - coexistence - parallel operation - retraining - process redesign - integration rebuild - testing - communication - decommissioning - archive retention Report: - current annualized cost - proposed renewal cost - expected future cost - avoidable cost - non-avoidable cost - one-time transition cost - recurring replacement cost - cost uncertainty - material assumptions Do not compare headline subscription prices without normalizing scope and total cost. ### 6. Service, Support, and Relationship Performance Review: - contracted service levels - observed availability - material incidents - incident duration - affected users - response times - resolution times - root-cause analyses - recurring failures - support case volume - support quality - escalation effectiveness - maintenance communication - release quality - roadmap delivery - implementation support - account management - executive engagement - commercial responsiveness Distinguish: - contracted obligation - observed delivery - service credit - remediation commitment - non-binding promise - relationship perception Determine whether unresolved service problems are: - isolated - recurring - systemic - product-specific - region-specific - support-tier-specific - caused by internal implementation Do not treat relationship quality as a substitute for service evidence. ### 7. Security, Privacy, Compliance, Accessibility, and Resilience Review current evidence for: - security assessment - penetration-test findings - vulnerability management - incident history - breach-notification obligations - encryption - identity controls - privileged access - audit logging - data segregation - subcontractors - hosting locations - data residency - cross-border transfer - retention - deletion - privacy rights - regulatory obligations - certifications - audit reports - accessibility - business continuity - disaster recovery - recovery objectives - backup - restore testing - financial resilience For each risk domain, record: - finding - evidence - severity - affected scope - compensating control - owner - review date - unresolved action - qualified reviewer Do not treat an expired certification, old assessment, or vendor questionnaire as current assurance. Require qualified review where appropriate from: - security - privacy - legal - compliance - accessibility - finance - operational-resilience owners ### 8. Vendor Viability and Concentration Risk Assess: - financial health - ownership changes - acquisition risk - leadership stability - workforce reductions - product investment - support capacity - market position - customer concentration - supplier concentration - subcontractor dependency - geographic concentration - technology concentration - platform dependency - roadmap stability - product deprecation - end-of-life risk - pricing behaviour Separate: - verified public or contractual evidence - vendor representation - market commentary - internal concern - unsupported speculation Determine whether the organization is excessively dependent on: - one supplier - one product - one integration - one data format - one implementation partner - one internal specialist - one region - one authentication provider ### 9. Data, Integration, Workflow, and Identity Dependencies Map: - data stored - data ownership - data classification - data model - export formats - export frequency - export completeness - retention - deletion - archive requirements - APIs - webhooks - connectors - automations - workflows - customizations - identity federation - single sign-on - provisioning - reporting - downstream systems - upstream systems - operational procedures - customer-facing dependencies For each dependency, record: - owner - criticality - replacement difficulty - documentation status - test status - alternative - failure impact - migration requirement - rollback requirement Identify: - proprietary formats - undocumented integrations - unsupported APIs - rate limits - vendor-controlled encryption keys - unavailable exports - incomplete deletion - manual workarounds - single-person knowledge - hidden workflow dependencies Do not declare exit feasible merely because the vendor provides an export button. ### 10. Stakeholder Experience and Change Capacity Collect or inspect evidence from: - business owners - end users - administrators - support teams - IT - security - finance - legal - operations - data teams - customers where relevant Assess: - satisfaction - user friction - training burden - support burden - workarounds - process fit - missing capabilities - excessive complexity - shadow tools - resistance to change - implementation fatigue - migration capacity - competing priorities Separate: - individual preference - isolated complaint - representative experience - measurable operational burden - business-critical dependency Do not allow user sentiment alone to determine the renewal decision. ### 11. Alternatives and Market Evidence Evaluate credible alternatives, including: - direct competitors - adjacent products - internal build - process redesign - vendor consolidation - partial replacement - coexistence - open-source options - managed services - reduced-scope continuation For each alternative, verify: - current product maturity - required capabilities - missing capabilities - security posture - privacy posture - compliance suitability - accessibility - integration support - data migration support - implementation capacity - pricing basis - contract structure - support model - vendor viability - customer references - deployment timeline - transition risk Distinguish: - verified current capability - demonstration - trial result - proof of concept - roadmap promise - vendor estimate - internal estimate - assumption Do not use an alternative as negotiation leverage unless it is credible, approved, and operationally achievable. ### 12. Switching and Exit Readiness Build a transition inventory covering: - data extraction - export validation - transformation - import - historical records - audit records - attachments - metadata - user accounts - permissions - integrations - automations - reports - templates - workflows - training - support - communications - coexistence - parallel operation - cutover - rollback - decommissioning - retention - deletion verification For each transition activity, record: - owner - effort - dependency - lead time - cost - risk - test requirement - acceptance condition - rollback - customer impact Test or obtain evidence for: - export completeness - export format - data reconciliation - alternative import - identity migration - integration compatibility - performance - user workflow - continuity - deletion confirmation Do not assume contractual exit assistance is operationally sufficient without inspecting its scope and limitations. ### 13. Negotiation Position Define: - negotiation objective - preferred scenario - acceptable scenario - walk-away point - required savings - required scope change - required contract changes - required service improvements - required risk remediation - available alternatives - transition lead time - decision deadline - approval limits - escalation path Potential negotiation elements may include: - price - volume tiers - licence flexibility - product scope - price caps - renewal term - termination rights - service levels - service credits - support level - implementation support - migration assistance - security commitments - privacy terms - accessibility commitments - data export - deletion - audit rights - subcontractor notice - roadmap commitments - benchmarking rights - change-of-control rights Classify each term as: - required - strongly preferred - tradeable - low priority - unacceptable Do not reveal internal negotiation limits outside authorized reviewers. ### 14. Approval and Decision Rights Identify: - business owner - budget owner - procurement owner - finance reviewer - IT owner - security reviewer - privacy reviewer - legal reviewer - compliance reviewer - accessibility reviewer - continuity owner - executive approver - signature authority For every material decision, distinguish: - recommendation - review - approval - risk acceptance - commercial authority - signature authority - implementation authority Do not treat attendance, consultation, or silence as approval. ## Failure Modes to Test Treat every failure mode as a hypothesis until supported by evidence. For each material hypothesis, provide: - predicted signals - observed evidence - contradictory evidence - affected products or users - financial or operational consequence - confidence - cheapest safe test - evidence that would change the assessment Test the following failure modes. ### Late Renewal Mobilization Evidence collection starts after the notice or leverage window has materially narrowed. ### Status-Quo Renewal The organization renews because it renewed previously rather than because current evidence supports renewal. ### Adoption-as-Value Error Licence activity or positive sentiment substitutes for measured business outcomes. ### Utilization-Only Resizing Licence reduction ignores peak demand, future requirements, operational resilience, or contractual minimums. ### Headline-Price Comparison Subscription price is compared without internal operations, integrations, taxes, overages, services, risk, and exit cost. ### Sunk-Cost Bias Past implementation effort is treated as a reason to continue future spending. ### Roadmap Reliance Vendor promises are treated as delivered capability or binding contractual commitment. ### Expired Risk Assurance Security, privacy, compliance, accessibility, resilience, or financial evidence is outdated or incomplete. ### Hidden Dependency Undocumented integrations, data models, workflows, identity services, or internal specialists create unexpected switching risk. ### Alternative Underestimation A cheaper alternative excludes migration, dual-running, retraining, integration, validation, and disruption costs. ### False Negotiation Leverage The organization threatens replacement without a credible alternative, approval, budget, or transition capacity. ### Auto-Renewal Exposure The organization misses notice requirements and loses commercial or strategic options. ### Incomplete Data Exit Data exports omit history, metadata, attachments, audit evidence, permissions, or relationships. ### Unsafe Service Reduction Scope or licence reduction disrupts critical users, processes, controls, or continuity. ### Unverified Deletion The vendor claims deletion, but scope, backups, subprocessors, retention, or confirmation remains unclear. ### Concentration Risk A critical process depends on one vendor, product, region, subcontractor, or internal specialist without an effective alternative. ### Unowned Decision Commercial, risk, security, legal, or transition approval has no clearly authorized owner. ## Workflow ### Step 1: Establish the Renewal Clock Confirm: - contract end - notice deadline - approval lead time - negotiation window - procurement lead time - legal-review time - alternative-evaluation time - transition lead time - internal decision deadline Build a backwards timetable from the contractual notice deadline. Treat an unconfirmed notice deadline as a blocker. ### Step 2: Build the Evidence Register List all supplied: - contracts - amendments - invoices - usage reports - outcome reports - service records - incidents - assessments - architecture documents - integration inventories - alternative evidence - migration evidence - approvals For each artifact, record: - source - owner - date - scope - authority - observation - limitation - confidence - next check ### Step 3: Restate the Business Case Compare: - original problem - intended outcome - current need - measured result - vendor contribution - unresolved gap - future requirement Determine whether the business case remains valid. ### Step 4: Assess Outcomes and Adoption Evaluate outcomes and adoption separately. Identify: - realized value - unrealized value - underused capability - redundant capability - unmet need - ownership gap - training gap - process gap - vendor gap ### Step 5: Normalize Total Cost Calculate comparable total cost for: - current state - proposed renewal - resized renewal - negotiated renewal - alternative vendor - partial replacement - consolidation - temporary extension - full exit Use consistent time horizons and assumptions. ### Step 6: Review Service and Risk Assess: - service delivery - support - incidents - roadmap - security - privacy - compliance - accessibility - resilience - financial health - concentration - subcontractors - unresolved obligations Route specialist findings to qualified reviewers. ### Step 7: Map Dependencies and Exit Constraints Map: - data - integrations - identity - workflows - customizations - reports - users - contracts - knowledge - operations - continuity Identify the minimum evidence required to establish exit feasibility. ### Step 8: Evaluate Credible Alternatives Compare only alternatives with sufficiently verified: - capability - security - integration - pricing - implementation - support - viability - transition evidence Label all unverified assumptions. ### Step 9: Model the Scenarios Evaluate: - renew as proposed - renew with conditions - resize - renegotiate - consolidate - partially replace - fully replace - temporarily extend - exit For every scenario, report: - business value - total cost - service impact - risk - dependency - implementation effort - lead time - reversibility - customer or user impact - uncertainty - approval requirement ### Step 10: Test Sensitivities Test material assumptions such as: - user growth - usage growth - price increase - exchange rates - migration delay - alternative implementation cost - service disruption - internal staffing - dual-running period - contract-overlap period - reduced adoption - vendor roadmap delivery Determine whether the recommendation remains defensible under plausible adverse cases. ### Step 11: Prepare the Negotiation Pack Define: - objectives - supporting evidence - required terms - tradeable terms - approval limits - alternatives - walk-away point - decision timetable - no-agreement plan Do not contact the vendor or communicate a decision without authority. ### Step 12: Assess Transition Readiness For replacement, consolidation, resizing, or exit, define: - transition owner - data plan - integration plan - identity plan - user plan - training plan - support plan - parallel-run plan - cutover - rollback - validation - deletion - decommissioning - communication ### Step 13: Issue the Recommendation Recommend one scenario and state: - decision - rationale - evidence - conditions - dissent - assumptions - risks - required approvals - contractual actions - negotiation actions - transition actions - monitoring - next review date ### Step 14: Define Implementation and Monitoring For the selected scenario, define: - action - owner - deadline - dependency - evidence - approval - acceptance condition - monitoring - escalation - rollback or contingency ## Decision and Safety Controls 1. Do not disclose confidential pricing, negotiation limits, personal data, credentials, security findings, or legal advice beyond authorized reviewers. 2. Do not contact the vendor, accept terms, signal a decision, issue notice, trigger cancellation, or commit funds without appropriate authority. 3. Require qualified review where applicable from: - legal - procurement - finance - security - privacy - compliance - accessibility - operational resilience - data owners 4. Validate alternative capability and migration assumptions before using them as negotiation leverage. 5. Protect: - service continuity - customer commitments - data access - audit records - integrations - identity - user support - regulatory obligations through any change. 6. Keep commercial recommendation, risk acceptance, contract approval, signature, and implementation authority with accountable humans. 7. Do not substitute Claude output for qualified legal, financial, security, privacy, procurement, or executive approval. 8. Prefer: - read-only review - limited proof of concept - export test - migration rehearsal - bounded pilot - parallel run - reversible transition before an irreversible decision. 9. Record every exception with: - reason - affected scope - risk - owner - approver - compensating control - expiry - review date 10. Do not allow a temporary extension or exception to become an undocumented default. 11. Stop and escalate when: - the notice deadline is unclear - the contract is incomplete - signature authority is unknown - material risk evidence is unavailable - data exit is untested - continuity cannot be protected - an alternative is materially unverified - migration capacity is unavailable - customer or regulatory harm could result ## Output Contract Return the result using the following sections. Use concise prose for conclusions. Use tables only where they improve scenario comparison, ownership, cost, risk, evidence, or transition tracking. ### 1. Executive Renewal Recommendation Return: - recommended scenario - confidence - decision deadline - strongest supporting evidence - principal risks - material assumptions - required conditions - accountable approver - next safe action ### 2. Renewal Clock and Scope Show: - contract - products - entities - users - term - notice deadline - auto-renewal status - decision owner - approval milestones - constraints - exclusions ### 3. Evidence Register For each artifact, show: - source - owner - date - scope - observation - authority - limitation - confidence - next check ### 4. Outcome and Adoption Review For each outcome or use case, show: - intended outcome - target - observed result - adoption - vendor contribution - unresolved gap - confidence - owner ### 5. Licence and Entitlement Review Show: - product or tier - contracted quantity - assigned quantity - active quantity - meaningful usage - peak requirement - forecast requirement - unused quantity - recommended scope - risk ### 6. Total-Cost Baseline Show: - cost category - current annual cost - proposed renewal cost - avoidable cost - transition cost - future cost - source - assumption - confidence ### 7. Service and Risk Assessment For each area, show: - domain - evidence - current status - severity - unresolved issue - qualified reviewer - required action - decision impact ### 8. Dependency and Lock-In Map Show: - dependency - owner - criticality - replacement difficulty - available alternative - evidence - migration requirement - rollback requirement - risk ### 9. Alternative Assessment For each alternative, show: - alternative - verified capability - capability gap - implementation maturity - total cost - transition time - risk - evidence quality - status ### 10. Scenario Matrix Compare: - renew - renew with conditions - resize - renegotiate - consolidate - replace - temporary extension - exit Across: - business value - total cost - service - security and compliance - dependency - implementation effort - lead time - reversibility - user impact - uncertainty ### 11. Sensitivity Analysis For each material assumption, show: - assumption - base case - adverse case - scenario impact - decision impact - evidence required ### 12. Negotiation Pack Define: - objective - evidence - required term - preferred term - tradeable term - unacceptable position - walk-away point - approval limit - owner ### 13. Transition Readiness Show: - transition activity - owner - dependency - effort - duration - cost - risk - test - acceptance condition - rollback - status ### 14. Recommendation and Roadmap For each action, show: - priority - action - owner - deadline - dependency - required evidence - approval - acceptance condition - contingency - status ### 15. Decision Record State: - final recommendation - decision owner - approvers - dissent - assumptions - accepted risks - contractual action - implementation action - monitoring - next renewal trigger ## Verification Checklist Before finalizing, confirm that: - notice dates and renewal rights are confirmed from authoritative contract evidence - products, entities, users, regions, and contractual scope are explicit - business outcomes and adoption are assessed separately - adoption is not treated as proof of value - direct cost, internal cost, dependency cost, risk cost, and exit cost are included - scenarios use normalized horizons, currencies, scope, and assumptions - vendor roadmap statements are separated from delivered and contracted capability - service and support performance are supported by current records - security, privacy, compliance, accessibility, resilience, and viability risks have qualified reviewers - data, integrations, identity, workflows, and knowledge dependencies are mapped - alternative capabilities are based on current verified evidence - migration estimates include coexistence, validation, retraining, integration, disruption, and decommissioning - data exit includes export completeness, validation, retention, deletion, and confirmation - negotiation positions have credible alternatives and approved authority - the recommendation remains defensible under documented sensitivity cases - every exception has an owner, approver, compensating control, and expiry - final commercial, contractual, and risk decisions remain with accountable human approvers - every major conclusion is supported by evidence or explicitly labelled as an assumption - no unreviewed source, untested capability, unapproved action, or unresolved conflict is described as complete - the final next action is the smallest safe step that materially reduces renewal uncertainty or commercial risk Begin by checking the supplied context for blocking gaps. If none remain, build the renewal clock and evidence register, complete the review in order, compare all credible scenarios, and issue the recommendation. ## Step 4 — Prepare the accountable portfolio decision brief **Prompt** Executive Decision Brief Prompt **Instructions** Synthesize the inventory, portfolio scenarios, vendor actions, migration constraints, costs, controls, uncertainty, and dissent into comparable options and a decision-ready recommendation. **Input for this step** Supply all prior outputs, the decision question and deadline, non-negotiables, decision criteria, affected stakeholders, authority boundaries, and required implementation or transition evidence. **Carry forward** Produce the final retain, consolidate, retire, or defer decision record with approved conditions, vendor actions, migration sequence, owners, risks, evidence gaps, next actions, and re-review triggers. **Review note** The accountable portfolio or process owner makes the decision; contract, data, security, privacy, migration, and release actions remain with their designated owners. **Prompt ID** AMO-P-000011 **Prompt URL** https://amo.ng/prompts/executive-decision-brief-prompt **Prompt content** Prepare an executive decision brief for the following decision. Decision inputs - Decision question: [Decision question] - Decision owner and approval authority: [Decision owner and approval authority] - Decision deadline: [Decision deadline] - Business context: [Business context] - Options already under consideration: [Options under consideration] - Evidence pack: [Evidence pack] - Constraints and non-negotiables: [Constraints and non-negotiables] - Decision criteria and priorities: [Decision criteria and priorities] - Affected stakeholders: [Affected stakeholders] - Risk, authority, and escalation limits: [Risk, authority, and escalation limits] - Definition of a decision-ready brief: [Definition of done] Input requirements Treat the decision question, accountable owner, deadline, known constraints, and at least one credible source describing the current situation as minimum inputs. Financial baselines, operating metrics, forecasts, customer evidence, contracts, policies, prior decisions, stakeholder positions, and option estimates are useful supporting inputs. If the decision question, authority, material constraints, or baseline evidence is missing or contradictory, ask only the questions that block responsible comparison or recommendation. If answers are unavailable, continue only where bounded analysis is safe. Preserve each unresolved item as an unknown, conflict, or assumption; do not manufacture figures, stakeholder agreement, approvals, or evidence. Evidence and tool rules 1. Use ChatGPT to organize supplied material, test reasoning, compare options, calculate only from provided figures, and draft the brief. State any calculation method and show enough working for review. 2. Do not imply access to internal systems, live dashboards, private links, meetings, or external sources unless their contents are actually available in the conversation. A URL alone is not evidence if its relevant content cannot be inspected. 3. Classify material claims as one of: supplied fact, direct observation from supplied material, calculation, stakeholder assertion, assumption, hypothesis, forecast, unknown, or conflict. Cite the file, excerpt, table, date, or source label supplied by the user whenever available. 4. Separate historical results from forecasts and correlation from demonstrated causation. Flag stale data, mismatched periods, inconsistent definitions, selection bias, omitted costs, optimistic adoption assumptions, and unsupported precision. 5. Never describe an option as approved, funded, validated, compliant, tested, launched, communicated, or completed unless the supplied evidence proves that state. Keep proposed, pending approval, blocked, unverified, and executed states distinct. Decision analysis workflow 1. Frame the decision: Rewrite the question as a specific choice to be made by the named owner by the deadline. Define what is in scope, what is excluded, why a decision is needed now, and the consequences of delay or no decision. 2. Establish the baseline: Summarize the current operating and financial position using the most decision-relevant metrics. Record metric definitions, periods, sources, and known data-quality limitations. Distinguish verified baseline values from estimates. 3. Confirm decision rights: Identify the recommender, approver, consulted parties, implementers, and parties who must be informed. Flag conflicting mandates or any action exceeding the stated authority limits. 4. Define evaluation criteria: Convert the supplied priorities into clear criteria such as strategic fit, customer impact, expected value, cash requirement, time to value, operational feasibility, reversibility, compliance exposure, security or privacy impact, workforce impact, and execution risk. Assign weights only when supplied or transparently proposed; do not present invented weights as executive preferences. 5. Build a complete option set: Analyze the supplied options and add a status quo, defer, pilot, staged commitment, or reversible alternative when materially relevant. Do not add artificial options merely to create symmetry. Define scope, prerequisites, dependencies, timing, resource demand, and opportunity cost for each credible option. 6. Normalize the comparison: Use consistent time horizons, units, cost boundaries, discounting assumptions, and metric definitions. Reconcile one-time and recurring costs, benefits, downside exposure, implementation capacity, and displaced work. Identify values that cannot be compared reliably. 7. Test economics and outcomes: Where evidence permits, show formulas and inputs for relevant measures such as incremental revenue, avoided cost, total cost of ownership, contribution margin, payback period, break-even point, or expected value. Use ranges or scenarios rather than false precision. Never invent a return estimate when required inputs are absent. 8. Stress-test the options: Evaluate base, upside, and downside cases; key sensitivities; adoption or demand shortfalls; schedule slippage; cost overruns; dependency failure; vendor or concentration risk; regulatory, legal, privacy, security, reputational, and workforce effects where applicable. Identify assumptions capable of reversing the ranking. 9. Account for stakeholder effects: State who benefits, who bears cost or disruption, likely objections, distributional effects, change-management needs, and unresolved dissent. Do not infer stakeholder consent from silence. 10. Form the recommendation: Recommend one option only when the evidence supports a defensible preference. Explain why it wins against the criteria, what trade-offs are accepted, confidence level, and what new evidence would change the recommendation. If evidence is insufficient, issue a conditional recommendation or a clearly bounded no-recommendation finding. 11. Design execution gates: Translate the recommendation into decision gates, accountable owners, dependencies, resources, approval points, leading and lagging indicators, review cadence, stop-loss thresholds, and rollback or exit conditions. Treat all owners and dates not explicitly confirmed as proposed. 12. Verify decision readiness: Reconcile important claims to sources, arithmetic to inputs, option scores to rationale, recommendation to criteria, risks to controls, and implementation gates to named authority. Report every failed or unperformed check rather than claiming verification. Authority and safety boundaries - Produce analysis and a recommendation, not an approval. Do not authorize spending, sign contracts, change policy, contact stakeholders, publish communications, move data, alter systems, or initiate implementation. - Require explicit human authorization for commitments involving funds, personnel, customers, regulated activity, contracts, production operations, security, privacy, legal positions, or external communications. - Minimize exposure of personal, confidential, privileged, security-sensitive, or commercially restricted information. Recommend redaction or aggregation when detailed data is unnecessary. Do not reproduce secrets or credentials. - Flag where qualified finance, legal, compliance, security, privacy, HR, procurement, or operational review is required. Do not represent the brief as a substitute for those approvals. - Stop at analysis and escalate when evidence suggests unlawful conduct, material safety danger, unauthorized access, sanctions exposure, serious privacy or security risk, an unbounded financial commitment, or a decision outside the named owner's authority. - For difficult-to-reverse actions, prefer staged commitment, pilot controls, backups, rollback planning, and explicit kill criteria where practical. Required output A. Decision header - Decision statement - Accountable decision owner and required approvers - Decision deadline and urgency - Scope and exclusions - Current state of the decision: exploratory, under review, recommended, pending approval, or another evidence-supported state B. Executive position - Recommended option or no-recommendation finding - Three to five reasons tied to evidence and criteria - Material trade-offs being accepted - Confidence level with rationale - Immediate decision requested from the owner C. Baseline and decision trigger Provide the relevant operating, customer, market, workforce, and financial baseline; why action is being considered now; cost of delay; and status quo trajectory. Include source, period, metric definition, and limitation for each pivotal baseline claim. D. Evidence ledger Create a table with columns: ID; material claim; classification; source or calculation; source date or period; reliability or limitation; confidence; and implication. Include contradictory evidence rather than silently resolving it. E. Decision criteria Create a table with columns: criterion; definition; weight or priority; measurement method; threshold; source of priority; and uncertainty. Clearly mark proposed weights. F. Options and trade-off matrix Create a table with one row per credible option and columns: option; scope; strategic fit; expected benefits; full costs; time to value; feasibility; key dependencies; reversibility; principal risks; stakeholder effects; evidence gaps; and criterion-based result. Include status quo or defer when materially relevant. Follow the table with concise explanations for any scoring or ranking. G. Economics and scenario analysis Show applicable formulas, inputs, units, time horizon, and results. Compare base, upside, and downside cases. Identify the variables with the greatest effect on the outcome and any break-even threshold. If economics cannot be calculated, list the missing inputs and avoid numeric conclusions. H. Recommendation rationale Explain why the preferred option is superior to each viable alternative, which disadvantages remain, why they are tolerable, what assumptions the recommendation depends on, and the evidence or event that would reverse it. State meaningful dissent or unresolved objections. I. Risk and control register Create a table with columns: risk; cause; affected objective; likelihood; impact; exposure; early warning indicator; preventive control; contingency or recovery action; proposed owner; escalation threshold; and residual risk. Distinguish existing controls from proposed controls. J. Approval-gated implementation outline Create a table with columns: phase or gate; intended outcome; proposed owner; prerequisites; resources; approval required; target timing; acceptance evidence; stop condition; and rollback or exit path. Do not imply that any phase has begun unless execution evidence was supplied. K. Measurement and review plan Define the baseline, target, metric owner, data source, measurement frequency, leading indicators, lagging outcomes, guardrail metrics, review dates, and trigger for continue, adjust, pause, scale, or stop decisions. Note whether each target is supplied or proposed. L. Verification and acceptance record Create a table with columns: check; expected condition; actual observation from supplied material; evidence reference; result as passed, failed, unperformed, or blocked; and required resolution. At minimum check: - the decision owner and approval path are explicit; - options use consistent scope, units, and time horizons; - pivotal claims trace to evidence; - calculations reconcile to source inputs; - assumptions and forecasts are labeled; - status quo and delay consequences were considered; - recommendation follows the stated criteria; - material downside and affected stakeholders are represented; - authority, specialist-review, privacy, and compliance limits are addressed; - implementation gates have acceptance evidence and stop or exit conditions; - no completion or approval claim exceeds available evidence. M. Open issues and handoff List blocking questions, non-blocking unknowns, evidence conflicts, required specialist reviews, decisions reserved for humans, and the smallest safe next action. End with a concise decision-owner checklist separating: decide now, obtain evidence, seek approval, and defer. ## Completion criteria The workflow is complete when: - The inventory distinguishes assigned access, meaningful use, shadow tools, ownership, and evidence gaps. - True redundancy is assessed against validated capabilities, dependencies, contracts, controls, and migration risk rather than category labels or seats alone. - Affected vendors have renewal, renegotiation, extension, replacement, or exit actions with timing and evidence gates. - The decision brief identifies retain, consolidate, retire, or defer outcomes, owners, conditions, migration sequence, and reversal risk. - No contract action, access removal, migration, data deletion, or communication is represented as authorized or completed without evidence. # Plan a SaaS Portfolio Consolidation Decision Workflow ID: AMO-W-000017 Workflow URL: https://amo.ng/workflows/saas-portfolio-consolidation-decision Use this Amo.ng workflow with your preferred AI tool. Complete the steps in order and carry the specified output forward. Outcome: A portfolio decision package containing a trusted SaaS inventory, capability and redundancy map, cost and control scenarios, retain or consolidate recommendations, vendor-level renewal or exit actions, migration constraints, and an accountable decision brief. Required inputs: - SaaS inventory, owners, assigned seats, meaningful usage, shadow tools, and business capabilities - Integrations, identity, data flows, reporting, automation, control, continuity, and regional dependencies - Contracts, renewal and notice dates, commercial terms, exit rights, data portability, and vendor evidence - Security, privacy, compliance, legal, finance, migration, and change-management constraints - Portfolio objectives, decision horizon, accountable owners, and acceptable transition risk ## Step 1 — Reconcile the SaaS inventory and meaningful use **Instructions** Reconcile contracts, assigned seats, meaningful usage, shadow applications, duplicate capabilities, access risk, ownership, and evidence gaps without treating low usage as sufficient reason to remove a tool. **Input for this step** Supply application and contract inventory, identity and seat assignments, usage evidence and definitions, owners, costs, shadow-tool evidence, business criticality, and known dependencies. **Carry forward** Carry the trusted inventory, ownership gaps, meaningful-use findings, shadow or duplicate candidates, access risks, and evidence limitations into portfolio analysis. **Review note** The portfolio owner, application owners, identity owner, and finance reviewer confirm inventory scope, usage interpretation, and unowned systems. **Prompt** SaaS Seat Utilization and Shadow License Review **Prompt ID** AMO-P-000246 **Prompt URL** https://amo.ng/prompts/saas-seat-utilization-shadow-licence-review ## Step 2 — Evaluate true redundancy and consolidation scenarios **Instructions** Compare overlapping tools against validated capabilities, dependencies, data flows, contracts, controls, switching costs, total-cost scenarios, and migration risk. Preserve legitimate differences and identify retain, consolidate, retire, or defer options. **Input for this step** Use the reconciled inventory with capability requirements, integration and data-flow evidence, contracts and exit terms, controls, continuity requirements, costs, migration constraints, and decision horizon. **Carry forward** Carry the capability-to-tool map, true redundancy findings, cost and control scenarios, migration constraints, provisional portfolio recommendation, and evidence gaps into vendor-level action planning. **Review note** The product or portfolio owner, finance owner, security reviewer, data owner, procurement owner, and legal reviewer verify the scenario evidence before commitments. **Prompt** SaaS Portfolio Redundancy and Consolidation Decision **Prompt ID** AMO-P-000290 **Prompt URL** https://amo.ng/prompts/saas-portfolio-redundancy-and-consolidation-decision ## Step 3 — Prepare vendor renewal, negotiation, replacement, and exit paths **Instructions** For each vendor materially affected by the preferred portfolio scenario, define the renewal clock, verified outcomes, total cost, negotiation leverage, resize or extension options, alternatives, transition readiness, and evidence-gated exit conditions. **Input for this step** Provide the preferred and fallback portfolio scenarios, vendor contracts, renewal and notice dates, utilization and outcome evidence, service performance, risk, dependencies, negotiation context, alternatives, and transition constraints. **Carry forward** Carry vendor-specific renew, resize, renegotiate, temporarily extend, replace, or exit recommendations, negotiation gates, transition readiness, deadlines, and unresolved terms into the final brief. **Review note** The commercial owner, finance reviewer, legal reviewer, security reviewer, and operational owner approve vendor-level conditions and contract actions. **Prompt** Vendor Renewal Decision Pack **Prompt ID** AMO-P-000259 **Prompt URL** https://amo.ng/prompts/vendor-renewal-decision-pack ## Step 4 — Prepare the accountable portfolio decision brief **Instructions** Synthesize the inventory, portfolio scenarios, vendor actions, migration constraints, costs, controls, uncertainty, and dissent into comparable options and a decision-ready recommendation. **Input for this step** Supply all prior outputs, the decision question and deadline, non-negotiables, decision criteria, affected stakeholders, authority boundaries, and required implementation or transition evidence. **Carry forward** Produce the final retain, consolidate, retire, or defer decision record with approved conditions, vendor actions, migration sequence, owners, risks, evidence gaps, next actions, and re-review triggers. **Review note** The accountable portfolio or process owner makes the decision; contract, data, security, privacy, migration, and release actions remain with their designated owners. **Prompt** Executive Decision Brief Prompt **Prompt ID** AMO-P-000011 **Prompt URL** https://amo.ng/prompts/executive-decision-brief-prompt Completion criteria: The workflow is complete when: - The inventory distinguishes assigned access, meaningful use, shadow tools, ownership, and evidence gaps. - True redundancy is assessed against validated capabilities, dependencies, contracts, controls, and migration risk rather than category labels or seats alone. - Affected vendors have renewal, renegotiation, extension, replacement, or exit actions with timing and evidence gates. - The decision brief identifies retain, consolidate, retire, or defer outcomes, owners, conditions, migration sequence, and reversal risk. - No contract action, access removal, migration, data deletion, or communication is represented as authorized or completed without evidence.Copy workflow includes every step and the full linked Prompt content. Use with AI copies a shorter guide with Prompt links; neither action runs the Workflow.
Outcome
A portfolio decision package containing a trusted SaaS inventory, capability and redundancy map, cost and control scenarios, retain or consolidate recommendations, vendor-level renewal or exit actions, migration constraints, and an accountable decision brief.
Before you begin
Have all or some of the following available before you start. The more relevant context you can provide, the stronger the workflow output will be.
- SaaS inventory, owners, assigned seats, meaningful usage, shadow tools, and business capabilities
- Integrations, identity, data flows, reporting, automation, control, continuity, and regional dependencies
- Contracts, renewal and notice dates, commercial terms, exit rights, data portability, and vendor evidence
- Security, privacy, compliance, legal, finance, migration, and change-management constraints
- Portfolio objectives, decision horizon, accountable owners, and acceptable transition risk
Ordered sequence
Workflow steps
Complete the steps in order. For each step, provide the listed context, carry its result into the next step, and pause wherever a review note is shown.
-
Step 1 Reconcile the SaaS inventory and meaningful use
Reconcile contracts, assigned seats, meaningful usage, shadow applications, duplicate capabilities, access risk, ownership, and evidence gaps without treating low usage as sufficient reason to remove a tool.
Prompt: SaaS Seat Utilization and Shadow License ReviewYou are a senior SaaS operations, procurement, FinOps, and access-governance analyst experienced in license reconciliation, identity lifecycle management, shadow SaaS discovery, application rationalization, renewals, and controlled change. Help IT operations, procurement, finance, security, and business owners determine which SaaS applications and seats should be retained, governed, reassigned, downgraded, consolidated, recovered, or reviewed at renewal. Produce an evidence-based SaaS inventory, contract and seat reconciliation, utilization and criticality assessment, shadow SaaS risk review, savings scenario model, and controlled action register. Keep the review focused on SaaS contracts, subscriptions, seats, identities, access, business dependencies and renewals. Consider API or consumption costs only when they are part of the supplied SaaS agreement. Do not turn the output into a general AI model-cost review. ## Context to Provide Replace every bracketed placeholder. If a blocking input is missing, ask one consolidated set of questions before reaching conclusions. Continue with clearly labeled assumptions only when the missing information is non-blocking. - [Review objective, period, and decision deadline] - [Application, workspace, and tenant inventory] - [Contracts, invoices, pricing models, and renewal terms] - [Assigned identities, account types, and identity-provider records] - [Usage and feature-activity evidence] - [Teams, roles, owners, cost centers, and lifecycle status] - [Application overlap, integrations, and business dependencies] - [Security, data, retention, and access requirements] - [Known shadow SaaS and expense-card activity] - [Allowed actions, approval owners, and constraints] - [Definition of done] ## Evidence and Working Rules - Base every factual finding on supplied evidence. - Separate confirmed evidence, assumptions, hypotheses, unknowns, risks, calculations, and recommendations. - Record each material source, its owner, scope, extraction date, review period, and known limitations. - Preserve conflicts between procurement, finance, identity, application-admin, expense, browser, endpoint, and owner records until a discriminating check resolves them. - Do not invent applications, accounts, contracts, prices, activity, owners, integrations, incidents, approvals, savings, benchmarks, test results, or product behavior. - Do not describe an inspection, reconciliation, approval, access change, contract action, test, or outcome as completed unless its result is supplied. - Use `Not provided`, `Not inspected`, `Not run`, `Unknown`, or `To be agreed` where evidence is unavailable. - Minimize and redact personal data, browsing history, credentials, tokens, customer records, confidential contract terms, and other information not required for the review. - Do not infer employee performance, productivity, importance, or intent from application activity. - Do not define an account as unused solely from last-login evidence. - Do not apply a generic inactivity threshold unless the organization has supplied or approved it. - Distinguish assigned, activated, active, meaningfully engaged, inactive, unassigned, suspended, recoverable, and owner-validated critical use. - Tie every recommendation to evidence, an accountable owner, required approvals, a verification method, and an observable acceptance condition. ## Review Method ### 1. Establish the Review Boundary Define: - included organizations, subsidiaries, departments and cost centers; - included applications, tenants and workspaces; - review and comparison periods; - savings and governance objectives; - decision deadline; - permitted evidence sources; - excluded systems and users; - allowed actions; - accountable review owners. Treat unclear scope as a blocker rather than silently expanding the review. ### 2. Normalize the Application Inventory Reconcile applications found through: - procurement records; - accounts payable and invoices; - expense reports and corporate cards; - identity-provider and SSO records; - SCIM or directory integrations; - application-admin exports; - browser or endpoint discovery; - OAuth and connected-app inventories; - department-owner records; - approved shadow SaaS discovery sources. Normalize vendor names, product names, domains, editions, tenants, workspaces, billing entities and application aliases. Prevent the same application, contract, workspace, payment or user from being counted more than once. ### 3. Establish the Contract Baseline For each application, identify: - contract owner and business owner; - license or consumption model; - named-user, concurrent, consumption, workspace, enterprise or feature-add-on basis; - edition and included capabilities; - purchased and committed quantities; - minimum commitments; - unit prices, currencies, taxes and billing frequency; - tier thresholds and true-up terms; - renewal and notice deadlines; - auto-renewal conditions; - downgrade, cancellation, transfer and reassignment rights; - termination or early-exit constraints; - data export, retention and deletion obligations. Do not compare seat quantities across incompatible license models. ### 4. Reconcile Identities and Seats Classify accounts as applicable: - assigned; - invited but not activated; - active; - meaningfully engaged; - inactive candidate; - unassigned; - suspended; - guest or external; - contractor; - leave-of-absence; - service or integration; - shared; - privileged; - duplicate; - unowned; - departed-user; - exception-approved. Reconcile application identities to authoritative workforce or approved external-user records using appropriate normalized identifiers. Do not automatically merge identities where aliases, name collisions, multiple email domains or separate tenants create uncertainty. ### 5. Assess Utilization and Business Criticality Evaluate usage using the supplied measurement period and application-appropriate signals, including: - login or authentication; - meaningful feature activity; - transactions or workflow execution; - content creation or modification; - collaboration; - storage or record ownership; - API and integration activity; - administrative activity; - critical low-frequency use; - seasonal or project-based use. For each utilization conclusion, record: - activity definition; - measurement window; - evidence source; - observed signal; - business role; - workflow dependency; - integration dependency; - data or record dependency; - seasonality; - owner confirmation; - confidence and limitation. Do not treat frequent login as proof of realized value or low-frequency use as proof that access is unnecessary. ### 6. Identify Shadow SaaS and Access Risk Investigate applications, subscriptions, trials, workspaces and connectors operating outside normal procurement, IT, identity or security visibility. Consider: - personal or department cards; - reimbursed subscriptions; - free tiers and converted trials; - external workspaces; - unmanaged tenants; - applications outside SSO; - unsanctioned OAuth grants; - departed owners; - missing security review; - company data in personal accounts; - missing retention or deletion controls; - weak offboarding coverage. Treat shadow SaaS as an unmanaged visibility and governance condition—not proof of malicious intent or policy violation. ### 7. Evaluate Application Overlap Compare overlapping applications against actual requirements rather than feature-list similarity alone. Assess: - supported workflows; - user adoption; - unique capabilities; - integrations and automation; - data ownership; - record retention; - export quality; - accessibility requirements; - customer or partner dependencies; - migration effort; - training and productivity impact; - switching cost; - vendor lock-in; - contract timing; - rollback feasibility. Do not recommend consolidation unless the destination tool and migration plan can satisfy the validated requirements. ### 8. Model Decision Scenarios Model only scenarios supported by the evidence: 1. Retain and monitor 2. Govern or bring under management 3. Reassign 4. Recover 5. Downgrade 6. Consolidate 7. Cancel at renewal 8. Investigate further For each scenario, distinguish: - gross contractual cost; - currently avoidable recurring cost; - sunk or committed cost; - implementation and migration cost; - productivity or transition impact; - earliest realization date; - first-year net effect; - ongoing annual effect; - assumptions and confidence. Do not call an amount “saved” until the corresponding contract or billing change is completed and verified. ### 9. Define Approval and Change Controls Use read-only evidence collection first. Require appropriate human approval before: - removing or disabling access; - reassigning a license; - changing an identity or SSO group; - downgrading an edition; - canceling or renegotiating a contract; - consolidating applications; - migrating or deleting data; - changing retention or legal-hold handling; - communicating an employee-specific usage finding. For consequential actions, define: - application and business owner; - procurement and finance approval; - security, privacy, legal or records review where relevant; - affected users and dependencies; - advance notice; - exception process; - pilot or staged rollout; - validation method; - restoration or rollback procedure; - monitoring owner; - stop conditions. ## Failure Modes to Test Treat each applicable item as a hypothesis: - Assigned seats are incorrectly treated as active use. - Login activity is incorrectly treated as realized business value. - Application activity is missed because work occurs through APIs, integrations, shared accounts or service identities. - Multiple inventories, aliases, tenants or email domains double-count applications, users or spend. - Named-user, concurrent, consumption and enterprise license metrics are compared as though they were equivalent. - Critical low-frequency, seasonal, leave, contractor, privileged or records-related use is misclassified as recoverable. - Shadow SaaS is missed because it bypasses SSO, centralized procurement or corporate cards. - Apparent savings cannot be realized because of minimum commitments, renewal timing, tier thresholds or true-up terms. - License removal leaves underlying accounts, data, OAuth grants or permissions active. - Consolidation ignores migration, accessibility, integration, customer, record-retention or rollback requirements. - Cost action proceeds without the required application, business, finance, procurement, security or data-owner approval. For every material hypothesis, state: - evidence supporting it; - evidence contradicting it; - missing evidence; - confidence; - potential impact; - the smallest safe verification check. ## Output Contract Use concise markdown and the following sections. Do not calculate values that cannot be derived from supplied data. ### Scope and Input Sufficiency | Input or boundary | Evidence supplied | Scope and date | Confidence | Material gap | Blocking? | |---|---|---|---|---|---| State whether the review can proceed and list only questions that materially affect the result. ### Executive Decision Summary In no more than 200 words, summarize: - applications and spend in scope; - material reconciliation gaps; - leading utilization findings; - shadow SaaS and access concerns; - potentially avoidable cost; - decisions that can proceed; - decisions blocked by missing evidence. Do not present estimates as realized savings. ### Application and Contract Inventory | Application and tenant | Owner | Contract and license model | Purchased or committed quantity | Cost basis | Renewal and notice dates | Evidence | Confidence | |---|---|---|---:|---|---|---|---| ### Seat Reconciliation | Application | Purchased | Assigned | Engaged | Unassigned | Inactive candidates | Guest/service/privileged | Unowned or departed | Reconciliation gap | |---|---:|---:|---:|---:|---:|---|---|---| Explain the approved activity definition and measurement period used for each application. ### Utilization and Criticality | Application or cohort | Activity evidence | Business criticality | Dependencies | Seasonality or exception | Owner validation | Proposed classification | Confidence | |---|---|---|---|---|---|---|---| ### Shadow SaaS and Access Risk | Application or workspace | Discovery source | Procurement state | Authentication and owner | Data and integrations | Lifecycle-control gap | Risk | Immediate safe check | |---|---|---|---|---|---|---|---| ### Application Overlap Review | Requirement | Current tools | Coverage and gaps | Migration dependencies | Switching cost and timing | Evidence-backed recommendation | |---|---|---|---|---|---| ### Savings Scenario Model | Scenario | Quantity and formula | Gross avoidable cost | One-time cost | First-year net effect | Earliest realization | Assumptions | Confidence | |---|---|---:|---:|---:|---|---|---| Keep committed, avoidable and realized amounts separate. ### Controlled Action Register | Priority | Proposed action | Scope | Required evidence | Owner | Approvers | Notice and prerequisites | Validation | Rollback | Target timing | |---:|---|---|---|---|---|---|---|---|---| ### Realization and Monitoring Plan | Expected result | Contract or access evidence | Realized result | User-impact check | Exception owner | Review date | Status | |---|---|---|---|---|---|---| ### Material Follow-Up Questions List only unresolved questions that could change a classification, risk rating, savings scenario or action. ## Verification Checklist Before finalizing, confirm that: - application, contract, tenant, workspace and identity records were normalized without double-counting; - license quantities were interpreted using the correct license model; - activity conclusions specify their definition, evidence source and measurement period; - invited, guest, service, integration, privileged, shared, contractor, leave and departed-user accounts were handled explicitly; - critical low-frequency and seasonal use was not automatically classified as waste; - shadow SaaS discovery considered sources outside SSO and centralized procurement; - avoidable cost follows actual contract terms, minimums, notice periods and renewal timing; - committed cost, avoidable cost and realized savings remain separate; - application consolidation accounts for migration, integration, records, accessibility and rollback needs; - no access, contract, identity or data action is presented as authorized without the required owner approval; - employee activity was not used as an unsupported performance judgment; - every major conclusion is tied to supplied evidence or labeled as an assumption; - no unrun check, unreviewed source, unapproved action or unresolved conflict is described as complete; - the final next step is the smallest safe action that materially reduces cost, uncertainty or risk. Begin by reviewing the supplied context for blocking gaps. If none remain, establish the review boundary and follow the review method in order.Input for this step
Supply application and contract inventory, identity and seat assignments, usage evidence and definitions, owners, costs, shadow-tool evidence, business criticality, and known dependencies.
Carry forward
Carry the trusted inventory, ownership gaps, meaningful-use findings, shadow or duplicate candidates, access risks, and evidence limitations into portfolio analysis.
Review note
The portfolio owner, application owners, identity owner, and finance reviewer confirm inventory scope, usage interpretation, and unowned systems.
-
Step 2 Evaluate true redundancy and consolidation scenarios
Compare overlapping tools against validated capabilities, dependencies, data flows, contracts, controls, switching costs, total-cost scenarios, and migration risk. Preserve legitimate differences and identify retain, consolidate, retire, or defer options.
Prompt: SaaS Portfolio Redundancy and Consolidation DecisionPrepare a defensible SaaS portfolio redundancy and consolidation analysis for a consequential portfolio decision. Context to provide: - SaaS applications in scope: [SaaS applications in scope] - Validated business capabilities and requirements: [Validated business capabilities and requirements] - Known integrations, data flows, and dependencies: [Known integrations data flows and dependencies] - Contract, commercial, renewal, termination, and exit terms: [Contract commercial and exit terms] - Control, compliance, security, privacy, audit, and risk requirements: [Control compliance and risk requirements] - Migration constraints, timing limits, business calendar constraints, and decision horizon: [Migration constraints and decision horizon] Working rules: - Use only the evidence provided. Do not claim that systems, contracts, logs, security controls, usage reports, or files were inspected unless the supplied evidence shows that. - Distinguish observed facts, stated assumptions, reasoned inference, and missing information. - Do not make seat utilization the primary decision basis. Consider usage only if supplied and only as supporting evidence. - Do not treat this as a one-vendor renewal recommendation or an initial procurement evaluation. The job is portfolio-level redundancy and consolidation across tools already in scope. - Preserve legitimate differences between tools. Do not collapse tools as redundant merely because they share a category label. - Identify where accountable owners must verify facts before execution: product owner, business capability owner, data owner, security reviewer, finance owner, procurement or vendor manager, legal reviewer, and migration owner as applicable. - If evidence is insufficient for a final decision, provide a provisional decision and list the specific evidence needed to confirm or change it. Authority and execution boundaries: - This analysis may recommend retain, consolidate, retire, or defer; it does not authorize contract renewal or termination, remove user access, migrate or delete data, communicate a final decision, or initiate implementation. - Portfolio commitment requires approval from the accountable portfolio or process owner and finance owner. Contract actions require the procurement owner and legal reviewer. Data movement or deletion requires the data and privacy owners. Control changes and production transition require the security, service, migration, and release owners as applicable. - Do not present a recommendation as approved or executable until the named owners have verified the supporting evidence, accepted the residual risks, and authorized the next action. Decision criteria: Evaluate each tool and overlap area against: 1. Coverage of validated business capabilities and must-have requirements. 2. Unique capability, workflow, data, user group, regional, or regulatory dependencies. 3. Integration, identity, reporting, automation, API, and data-flow dependencies. 4. Data ownership, retention, portability, residency, privacy, and deletion constraints. 5. Contractual constraints, renewal timing, notice periods, termination rights, minimum commitments, price protections, and exit assistance. 6. Switching costs, migration effort, change management burden, retraining, process disruption, and operational risk. 7. Security, privacy, compliance, audit, continuity, and administrative control coverage. 8. Total-cost scenarios, including parallel-run periods, implementation effort, migration support, internal labor, vendor services, penalties, and stranded commitments where evidence allows. 9. Reversibility of the decision and the risk of losing hard-to-recover data, integrations, controls, or institutional workflow knowledge. Required deliverable: 1. Decision boundary - State the applications in scope. - State the decision horizon. - State what is explicitly out of scope. - Identify the decision owners and verification owners needed from the evidence provided. 2. Evidence register Create a compact table with columns: - Evidence item - Source or supplied artifact - What it supports - Reliability level: high / medium / low - Gaps or verification needed 3. Capability-to-tool map Create a table with columns: - Business capability or requirement - Current tool or tools supporting it - Requirement criticality: must-have / important / optional - Coverage quality: strong / partial / weak / unknown - Unique differentiators or constraints - Evidence basis - Consolidation implication 4. Redundancy and dependency analysis For each meaningful overlap area, assess: - Apparent redundancy - True redundancy after requirements and dependencies are considered - Non-obvious dependencies - Integration and data-flow impact - Business process impact - Control or compliance impact - Users, teams, regions, or workflows likely affected if supplied - Whether the overlap supports consolidation, coexistence, or retirement 5. Total-cost scenarios Compare at least three scenarios where evidence permits: - Retain current portfolio - Consolidate into one or more existing tools - Retire one or more tools after migration or exit For each scenario, include: - Cost components supported by evidence - Cost components that are likely but not quantified - Contract timing and stranded-cost exposure - Migration and change costs - Operational risk cost drivers - Confidence level - Missing financial inputs needed for a firmer estimate 6. Migration and exit constraints Create a table with columns: - Tool or capability affected - Exit or migration constraint - Source of constraint: contract / data / integration / control / process / people / timing / unknown - Severity: high / medium / low - Mitigation option - Owner to verify - Decision impact 7. Control coverage and risk comparison Assess whether consolidation would weaken, maintain, or improve: - Identity and access administration - Role-based access or privilege controls - Audit logging and evidence retention - Security monitoring and incident response support - Privacy, residency, retention, deletion, or export obligations - Business continuity and disaster recovery expectations - Regulatory or contractual control obligations Do not infer control sufficiency from vendor reputation. Tie each point to supplied evidence or mark it as unknown. 8. Retain / consolidate / retire decision record Provide a decision record with: - Recommended decision for each application: retain / consolidate / retire / defer pending evidence - Rationale tied to capability coverage, dependencies, cost, contract terms, controls, and migration risk - Conditions that must be true for the recommendation to remain valid - Required owner verifications before commitment - Risks accepted by the decision - Risks requiring mitigation before execution - Earliest safe decision point and earliest safe execution point if determinable - Reversal difficulty: low / medium / high 9. Portfolio recommendation Give a concise portfolio-level recommendation that states: - Preferred consolidation path - Tools to retain and why - Tools to retire or phase out and why - Tools that should remain temporarily during transition - Sequencing logic - No-regret next steps that do not prematurely commit the organization 10. Completion checks End with a checklist confirming whether the analysis includes: - Capability-to-tool map - Redundancy and dependency analysis - Total-cost scenarios - Migration and exit constraints - Control coverage comparison - Retain / consolidate / retire decision record - Named owner verifications - Explicit missing information - Clear distinction between evidence and inferenceInput for this step
Use the reconciled inventory with capability requirements, integration and data-flow evidence, contracts and exit terms, controls, continuity requirements, costs, migration constraints, and decision horizon.
Carry forward
Carry the capability-to-tool map, true redundancy findings, cost and control scenarios, migration constraints, provisional portfolio recommendation, and evidence gaps into vendor-level action planning.
Review note
The product or portfolio owner, finance owner, security reviewer, data owner, procurement owner, and legal reviewer verify the scenario evidence before commitments.
-
Step 3 Prepare vendor renewal, negotiation, replacement, and exit paths
For each vendor materially affected by the preferred portfolio scenario, define the renewal clock, verified outcomes, total cost, negotiation leverage, resize or extension options, alternatives, transition readiness, and evidence-gated exit conditions.
Prompt: Vendor Renewal Decision PackYou are a senior vendor-management, procurement, commercial-strategy, technology-risk, and transition-planning specialist experienced in: - vendor performance assessment - SaaS and supplier renewals - business-value measurement - licence and entitlement optimization - total-cost analysis - contract negotiation - security and privacy review - operational resilience - vendor concentration and lock-in - alternative evaluation - migration planning - service transition - data extraction and deletion - executive approval packs Help business owners, procurement, finance, IT, security, privacy, legal, operations, and executive approvers decide whether the organization should: - renew - renew with conditions - resize - renegotiate - consolidate - replace - temporarily extend - exit Produce an evidence-based: - renewal clock and decision scope - evidence register - outcome and adoption assessment - total-cost baseline - service and supplier-risk review - dependency and lock-in map - alternative-market assessment - scenario comparison - negotiation position - transition-readiness assessment - approval recommendation - implementation roadmap Do not allow the current contract, previous decision, vendor relationship, sunk cost, internal preference, or approaching deadline to substitute for current evidence. Base every conclusion and recommendation on supplied evidence. Do not claim that a contract, invoice, usage report, service record, security assessment, capability, alternative, migration test, negotiation position, approval, or outcome has been reviewed unless its evidence is available. ## Context to Provide Replace every bracketed placeholder. If a blocking input is missing, ask one consolidated set of questions before making a recommendation. Continue with clearly labelled assumptions only when the missing information is non-blocking. - [Renewal decision, contract deadline, and notice period] - [Vendor, products, services, contract documents, and amendments] - [Legal entities, regions, business units, and users covered] - [Original business case, intended outcomes, and accountable owners] - [Usage, adoption, licence, entitlement, and feature-level evidence] - [Subscription, usage, support, service, tax, and internal cost evidence] - [Service levels, incidents, support cases, and remediation evidence] - [Security, privacy, compliance, accessibility, and resilience assessments] - [Vendor financial health, ownership, subcontractors, and concentration risk] - [Data, integrations, automations, workflows, identity, and operational dependencies] - [Stakeholder feedback, workarounds, training, and support burden] - [Credible alternatives, pricing, capability, and market evidence] - [Migration, coexistence, parallel-run, rollback, and exit evidence] - [Negotiation authority, budget, walk-away limits, and approval constraints] - [Expected future demand and strategic requirements] - [Definition of done] ## Evidence and Working Rules 1. Separate: - confirmed evidence - assumptions - hypotheses - unknowns - risks - recommendations - proposed actions - approved actions - completed actions 2. Build an evidence register before comparing scenarios or recommending a decision. 3. Preserve material conflicts between sources. For every conflict, show: - source - date - scope - reported position - conflicting position - potential decision impact - evidence required to resolve it 4. Prefer direct and current evidence, including: - executed contracts - amendments - invoices - purchase orders - usage reports - entitlement records - service-level reports - incident records - security assessments - privacy assessments - architecture documentation - export tests - migration estimates - current vendor documentation - independently verified alternative evidence 5. Do not invent: - contract clauses - renewal dates - notice periods - usage figures - prices - discounts - service levels - incidents - security findings - alternative capabilities - migration estimates - vendor commitments - negotiation authority - approvals 6. Use `Not provided`, `Not inspected`, `Not tested`, `Unconfirmed`, or `To be agreed` when evidence is unavailable. 7. Redact or restrict: - confidential pricing - negotiation limits - credentials - tokens - personal data - customer records - security vulnerabilities - legal advice - commercially sensitive information not required for the decision 8. Tie every material recommendation to: - supporting finding - affected product or service - affected users or processes - accountable owner - required action - evidence required - acceptance condition - approval requirement - deadline - transition or rollback requirement 9. Distinguish: - contracted entitlement - configured capability - available capability - adopted capability - meaningfully used capability - business outcome - vendor roadmap promise - non-contractual statement - internal assumption 10. Do not treat vendor marketing, demonstrations, roadmap statements, or sales assurances as delivered capability or binding commitment. 11. Distinguish: - sunk cost - committed future cost - avoidable cost - incremental cost - transition cost - termination cost - internal operating cost - risk exposure - potential benefit 12. Evaluate business outcomes, adoption, cost, service, risk, dependency, and switching readiness separately before combining them into a recommendation. 13. Normalize scenario comparisons across the same: - time horizon - currency - tax treatment - inflation assumption - growth assumption - implementation scope - user population - service level - risk boundary 14. Do not net unrelated risks or exceptions merely because their financial values offset. ## Review Scope ### 1. Renewal Clock and Contractual Position Inspect: - contract start date - contract end date - renewal date - notice deadline - notice method - auto-renewal terms - renewal term - minimum commitment - price-increase mechanism - usage true-up - minimum spend - termination rights - termination assistance - convenience termination - cause termination - suspension rights - service-credit provisions - cure periods - amendment hierarchy - order forms - statements of work - product schedules - support schedules - data-processing terms - security schedules - service-level agreements Record: - authoritative contract document - current version - responsible legal entity - products and services covered - geographic scope - user or consumption commitment - decision authority - signature authority - internal approval timetable - required vendor-notification date Identify any contractual ambiguity that could affect: - cancellation - scope reduction - pricing - data access - continuity - migration - deletion - post-termination support Do not rely on calendar reminders or internal summaries when the executed contract is available. ### 2. Original Business Case and Strategic Fit Restate: - problem the vendor was selected to solve - intended business outcomes - expected users - expected capabilities - expected financial benefit - expected operational benefit - expected risk reduction - implementation assumptions - strategic rationale - original decision owner Determine: - which intended outcomes remain relevant - which outcomes were achieved - which outcomes were partially achieved - which outcomes were not achieved - which needs have changed - which capabilities are now unnecessary - which new capabilities are required - whether the vendor remains strategically aligned Separate vendor performance from internal execution failures such as: - poor rollout - inadequate training - missing ownership - incomplete integration - weak process design - insufficient change management - inaccurate original assumptions ### 3. Business Outcomes and Value Realization For each intended outcome, record: - outcome - baseline - target - current result - measurement period - evidence source - vendor contribution - internal contribution - confidence - unresolved gap Assess outcomes such as: - revenue improvement - cost reduction - productivity - cycle-time reduction - error reduction - service improvement - risk reduction - compliance support - customer experience - employee experience - operational resilience - decision quality Where possible, compare current performance with the counterfactual: - without the vendor - with the previous solution - with an internal process - with a credible alternative Do not equate software activity with business value. ### 4. Usage, Adoption, and Entitlement Inspect by product, module, tier, team, region, and user group: - purchased licences - contracted licences - assigned licences - provisioned licences - activated licences - active users - meaningfully active users - peak users - occasional users - inactive users - duplicate users - suspended users - service accounts - unused modules - premium features - API consumption - storage consumption - overages - seasonal use - forecast demand Define what counts as: - assigned - active - meaningfully used - business-critical - replaceable - redundant Identify: - shelfware - duplicate licences - overlapping tools - entitlement leakage - over-provisioning - under-provisioning - unnecessary premium tiers - teams using unsupported alternatives - users retained only because of historical allocation Do not recommend licence reduction without checking: - peak demand - seasonal demand - future projects - contractual minimums - operational resilience - access requirements - deprovisioning consequences ### 5. Total Cost of Ownership Build a normalized total-cost baseline covering: #### Direct Vendor Cost - subscription fees - usage fees - support fees - professional services - implementation fees - training fees - premium features - overages - storage - API charges - maintenance - taxes - currency effects - price uplifts #### Internal Operating Cost - administration - configuration - user support - vendor management - security review - compliance review - integration maintenance - data operations - reporting - reconciliation - training - change management - incident response #### Dependency Cost - middleware - connectors - identity services - storage - data warehouse - monitoring - backup - custom code - specialist staff - external consultants #### Risk and Failure Cost - outages - service degradation - manual workarounds - delayed projects - errors - customer impact - regulatory exposure - security remediation - support escalation #### Exit and Transition Cost - early termination - data extraction - data transformation - migration - coexistence - parallel operation - retraining - process redesign - integration rebuild - testing - communication - decommissioning - archive retention Report: - current annualized cost - proposed renewal cost - expected future cost - avoidable cost - non-avoidable cost - one-time transition cost - recurring replacement cost - cost uncertainty - material assumptions Do not compare headline subscription prices without normalizing scope and total cost. ### 6. Service, Support, and Relationship Performance Review: - contracted service levels - observed availability - material incidents - incident duration - affected users - response times - resolution times - root-cause analyses - recurring failures - support case volume - support quality - escalation effectiveness - maintenance communication - release quality - roadmap delivery - implementation support - account management - executive engagement - commercial responsiveness Distinguish: - contracted obligation - observed delivery - service credit - remediation commitment - non-binding promise - relationship perception Determine whether unresolved service problems are: - isolated - recurring - systemic - product-specific - region-specific - support-tier-specific - caused by internal implementation Do not treat relationship quality as a substitute for service evidence. ### 7. Security, Privacy, Compliance, Accessibility, and Resilience Review current evidence for: - security assessment - penetration-test findings - vulnerability management - incident history - breach-notification obligations - encryption - identity controls - privileged access - audit logging - data segregation - subcontractors - hosting locations - data residency - cross-border transfer - retention - deletion - privacy rights - regulatory obligations - certifications - audit reports - accessibility - business continuity - disaster recovery - recovery objectives - backup - restore testing - financial resilience For each risk domain, record: - finding - evidence - severity - affected scope - compensating control - owner - review date - unresolved action - qualified reviewer Do not treat an expired certification, old assessment, or vendor questionnaire as current assurance. Require qualified review where appropriate from: - security - privacy - legal - compliance - accessibility - finance - operational-resilience owners ### 8. Vendor Viability and Concentration Risk Assess: - financial health - ownership changes - acquisition risk - leadership stability - workforce reductions - product investment - support capacity - market position - customer concentration - supplier concentration - subcontractor dependency - geographic concentration - technology concentration - platform dependency - roadmap stability - product deprecation - end-of-life risk - pricing behaviour Separate: - verified public or contractual evidence - vendor representation - market commentary - internal concern - unsupported speculation Determine whether the organization is excessively dependent on: - one supplier - one product - one integration - one data format - one implementation partner - one internal specialist - one region - one authentication provider ### 9. Data, Integration, Workflow, and Identity Dependencies Map: - data stored - data ownership - data classification - data model - export formats - export frequency - export completeness - retention - deletion - archive requirements - APIs - webhooks - connectors - automations - workflows - customizations - identity federation - single sign-on - provisioning - reporting - downstream systems - upstream systems - operational procedures - customer-facing dependencies For each dependency, record: - owner - criticality - replacement difficulty - documentation status - test status - alternative - failure impact - migration requirement - rollback requirement Identify: - proprietary formats - undocumented integrations - unsupported APIs - rate limits - vendor-controlled encryption keys - unavailable exports - incomplete deletion - manual workarounds - single-person knowledge - hidden workflow dependencies Do not declare exit feasible merely because the vendor provides an export button. ### 10. Stakeholder Experience and Change Capacity Collect or inspect evidence from: - business owners - end users - administrators - support teams - IT - security - finance - legal - operations - data teams - customers where relevant Assess: - satisfaction - user friction - training burden - support burden - workarounds - process fit - missing capabilities - excessive complexity - shadow tools - resistance to change - implementation fatigue - migration capacity - competing priorities Separate: - individual preference - isolated complaint - representative experience - measurable operational burden - business-critical dependency Do not allow user sentiment alone to determine the renewal decision. ### 11. Alternatives and Market Evidence Evaluate credible alternatives, including: - direct competitors - adjacent products - internal build - process redesign - vendor consolidation - partial replacement - coexistence - open-source options - managed services - reduced-scope continuation For each alternative, verify: - current product maturity - required capabilities - missing capabilities - security posture - privacy posture - compliance suitability - accessibility - integration support - data migration support - implementation capacity - pricing basis - contract structure - support model - vendor viability - customer references - deployment timeline - transition risk Distinguish: - verified current capability - demonstration - trial result - proof of concept - roadmap promise - vendor estimate - internal estimate - assumption Do not use an alternative as negotiation leverage unless it is credible, approved, and operationally achievable. ### 12. Switching and Exit Readiness Build a transition inventory covering: - data extraction - export validation - transformation - import - historical records - audit records - attachments - metadata - user accounts - permissions - integrations - automations - reports - templates - workflows - training - support - communications - coexistence - parallel operation - cutover - rollback - decommissioning - retention - deletion verification For each transition activity, record: - owner - effort - dependency - lead time - cost - risk - test requirement - acceptance condition - rollback - customer impact Test or obtain evidence for: - export completeness - export format - data reconciliation - alternative import - identity migration - integration compatibility - performance - user workflow - continuity - deletion confirmation Do not assume contractual exit assistance is operationally sufficient without inspecting its scope and limitations. ### 13. Negotiation Position Define: - negotiation objective - preferred scenario - acceptable scenario - walk-away point - required savings - required scope change - required contract changes - required service improvements - required risk remediation - available alternatives - transition lead time - decision deadline - approval limits - escalation path Potential negotiation elements may include: - price - volume tiers - licence flexibility - product scope - price caps - renewal term - termination rights - service levels - service credits - support level - implementation support - migration assistance - security commitments - privacy terms - accessibility commitments - data export - deletion - audit rights - subcontractor notice - roadmap commitments - benchmarking rights - change-of-control rights Classify each term as: - required - strongly preferred - tradeable - low priority - unacceptable Do not reveal internal negotiation limits outside authorized reviewers. ### 14. Approval and Decision Rights Identify: - business owner - budget owner - procurement owner - finance reviewer - IT owner - security reviewer - privacy reviewer - legal reviewer - compliance reviewer - accessibility reviewer - continuity owner - executive approver - signature authority For every material decision, distinguish: - recommendation - review - approval - risk acceptance - commercial authority - signature authority - implementation authority Do not treat attendance, consultation, or silence as approval. ## Failure Modes to Test Treat every failure mode as a hypothesis until supported by evidence. For each material hypothesis, provide: - predicted signals - observed evidence - contradictory evidence - affected products or users - financial or operational consequence - confidence - cheapest safe test - evidence that would change the assessment Test the following failure modes. ### Late Renewal Mobilization Evidence collection starts after the notice or leverage window has materially narrowed. ### Status-Quo Renewal The organization renews because it renewed previously rather than because current evidence supports renewal. ### Adoption-as-Value Error Licence activity or positive sentiment substitutes for measured business outcomes. ### Utilization-Only Resizing Licence reduction ignores peak demand, future requirements, operational resilience, or contractual minimums. ### Headline-Price Comparison Subscription price is compared without internal operations, integrations, taxes, overages, services, risk, and exit cost. ### Sunk-Cost Bias Past implementation effort is treated as a reason to continue future spending. ### Roadmap Reliance Vendor promises are treated as delivered capability or binding contractual commitment. ### Expired Risk Assurance Security, privacy, compliance, accessibility, resilience, or financial evidence is outdated or incomplete. ### Hidden Dependency Undocumented integrations, data models, workflows, identity services, or internal specialists create unexpected switching risk. ### Alternative Underestimation A cheaper alternative excludes migration, dual-running, retraining, integration, validation, and disruption costs. ### False Negotiation Leverage The organization threatens replacement without a credible alternative, approval, budget, or transition capacity. ### Auto-Renewal Exposure The organization misses notice requirements and loses commercial or strategic options. ### Incomplete Data Exit Data exports omit history, metadata, attachments, audit evidence, permissions, or relationships. ### Unsafe Service Reduction Scope or licence reduction disrupts critical users, processes, controls, or continuity. ### Unverified Deletion The vendor claims deletion, but scope, backups, subprocessors, retention, or confirmation remains unclear. ### Concentration Risk A critical process depends on one vendor, product, region, subcontractor, or internal specialist without an effective alternative. ### Unowned Decision Commercial, risk, security, legal, or transition approval has no clearly authorized owner. ## Workflow ### Step 1: Establish the Renewal Clock Confirm: - contract end - notice deadline - approval lead time - negotiation window - procurement lead time - legal-review time - alternative-evaluation time - transition lead time - internal decision deadline Build a backwards timetable from the contractual notice deadline. Treat an unconfirmed notice deadline as a blocker. ### Step 2: Build the Evidence Register List all supplied: - contracts - amendments - invoices - usage reports - outcome reports - service records - incidents - assessments - architecture documents - integration inventories - alternative evidence - migration evidence - approvals For each artifact, record: - source - owner - date - scope - authority - observation - limitation - confidence - next check ### Step 3: Restate the Business Case Compare: - original problem - intended outcome - current need - measured result - vendor contribution - unresolved gap - future requirement Determine whether the business case remains valid. ### Step 4: Assess Outcomes and Adoption Evaluate outcomes and adoption separately. Identify: - realized value - unrealized value - underused capability - redundant capability - unmet need - ownership gap - training gap - process gap - vendor gap ### Step 5: Normalize Total Cost Calculate comparable total cost for: - current state - proposed renewal - resized renewal - negotiated renewal - alternative vendor - partial replacement - consolidation - temporary extension - full exit Use consistent time horizons and assumptions. ### Step 6: Review Service and Risk Assess: - service delivery - support - incidents - roadmap - security - privacy - compliance - accessibility - resilience - financial health - concentration - subcontractors - unresolved obligations Route specialist findings to qualified reviewers. ### Step 7: Map Dependencies and Exit Constraints Map: - data - integrations - identity - workflows - customizations - reports - users - contracts - knowledge - operations - continuity Identify the minimum evidence required to establish exit feasibility. ### Step 8: Evaluate Credible Alternatives Compare only alternatives with sufficiently verified: - capability - security - integration - pricing - implementation - support - viability - transition evidence Label all unverified assumptions. ### Step 9: Model the Scenarios Evaluate: - renew as proposed - renew with conditions - resize - renegotiate - consolidate - partially replace - fully replace - temporarily extend - exit For every scenario, report: - business value - total cost - service impact - risk - dependency - implementation effort - lead time - reversibility - customer or user impact - uncertainty - approval requirement ### Step 10: Test Sensitivities Test material assumptions such as: - user growth - usage growth - price increase - exchange rates - migration delay - alternative implementation cost - service disruption - internal staffing - dual-running period - contract-overlap period - reduced adoption - vendor roadmap delivery Determine whether the recommendation remains defensible under plausible adverse cases. ### Step 11: Prepare the Negotiation Pack Define: - objectives - supporting evidence - required terms - tradeable terms - approval limits - alternatives - walk-away point - decision timetable - no-agreement plan Do not contact the vendor or communicate a decision without authority. ### Step 12: Assess Transition Readiness For replacement, consolidation, resizing, or exit, define: - transition owner - data plan - integration plan - identity plan - user plan - training plan - support plan - parallel-run plan - cutover - rollback - validation - deletion - decommissioning - communication ### Step 13: Issue the Recommendation Recommend one scenario and state: - decision - rationale - evidence - conditions - dissent - assumptions - risks - required approvals - contractual actions - negotiation actions - transition actions - monitoring - next review date ### Step 14: Define Implementation and Monitoring For the selected scenario, define: - action - owner - deadline - dependency - evidence - approval - acceptance condition - monitoring - escalation - rollback or contingency ## Decision and Safety Controls 1. Do not disclose confidential pricing, negotiation limits, personal data, credentials, security findings, or legal advice beyond authorized reviewers. 2. Do not contact the vendor, accept terms, signal a decision, issue notice, trigger cancellation, or commit funds without appropriate authority. 3. Require qualified review where applicable from: - legal - procurement - finance - security - privacy - compliance - accessibility - operational resilience - data owners 4. Validate alternative capability and migration assumptions before using them as negotiation leverage. 5. Protect: - service continuity - customer commitments - data access - audit records - integrations - identity - user support - regulatory obligations through any change. 6. Keep commercial recommendation, risk acceptance, contract approval, signature, and implementation authority with accountable humans. 7. Do not substitute Claude output for qualified legal, financial, security, privacy, procurement, or executive approval. 8. Prefer: - read-only review - limited proof of concept - export test - migration rehearsal - bounded pilot - parallel run - reversible transition before an irreversible decision. 9. Record every exception with: - reason - affected scope - risk - owner - approver - compensating control - expiry - review date 10. Do not allow a temporary extension or exception to become an undocumented default. 11. Stop and escalate when: - the notice deadline is unclear - the contract is incomplete - signature authority is unknown - material risk evidence is unavailable - data exit is untested - continuity cannot be protected - an alternative is materially unverified - migration capacity is unavailable - customer or regulatory harm could result ## Output Contract Return the result using the following sections. Use concise prose for conclusions. Use tables only where they improve scenario comparison, ownership, cost, risk, evidence, or transition tracking. ### 1. Executive Renewal Recommendation Return: - recommended scenario - confidence - decision deadline - strongest supporting evidence - principal risks - material assumptions - required conditions - accountable approver - next safe action ### 2. Renewal Clock and Scope Show: - contract - products - entities - users - term - notice deadline - auto-renewal status - decision owner - approval milestones - constraints - exclusions ### 3. Evidence Register For each artifact, show: - source - owner - date - scope - observation - authority - limitation - confidence - next check ### 4. Outcome and Adoption Review For each outcome or use case, show: - intended outcome - target - observed result - adoption - vendor contribution - unresolved gap - confidence - owner ### 5. Licence and Entitlement Review Show: - product or tier - contracted quantity - assigned quantity - active quantity - meaningful usage - peak requirement - forecast requirement - unused quantity - recommended scope - risk ### 6. Total-Cost Baseline Show: - cost category - current annual cost - proposed renewal cost - avoidable cost - transition cost - future cost - source - assumption - confidence ### 7. Service and Risk Assessment For each area, show: - domain - evidence - current status - severity - unresolved issue - qualified reviewer - required action - decision impact ### 8. Dependency and Lock-In Map Show: - dependency - owner - criticality - replacement difficulty - available alternative - evidence - migration requirement - rollback requirement - risk ### 9. Alternative Assessment For each alternative, show: - alternative - verified capability - capability gap - implementation maturity - total cost - transition time - risk - evidence quality - status ### 10. Scenario Matrix Compare: - renew - renew with conditions - resize - renegotiate - consolidate - replace - temporary extension - exit Across: - business value - total cost - service - security and compliance - dependency - implementation effort - lead time - reversibility - user impact - uncertainty ### 11. Sensitivity Analysis For each material assumption, show: - assumption - base case - adverse case - scenario impact - decision impact - evidence required ### 12. Negotiation Pack Define: - objective - evidence - required term - preferred term - tradeable term - unacceptable position - walk-away point - approval limit - owner ### 13. Transition Readiness Show: - transition activity - owner - dependency - effort - duration - cost - risk - test - acceptance condition - rollback - status ### 14. Recommendation and Roadmap For each action, show: - priority - action - owner - deadline - dependency - required evidence - approval - acceptance condition - contingency - status ### 15. Decision Record State: - final recommendation - decision owner - approvers - dissent - assumptions - accepted risks - contractual action - implementation action - monitoring - next renewal trigger ## Verification Checklist Before finalizing, confirm that: - notice dates and renewal rights are confirmed from authoritative contract evidence - products, entities, users, regions, and contractual scope are explicit - business outcomes and adoption are assessed separately - adoption is not treated as proof of value - direct cost, internal cost, dependency cost, risk cost, and exit cost are included - scenarios use normalized horizons, currencies, scope, and assumptions - vendor roadmap statements are separated from delivered and contracted capability - service and support performance are supported by current records - security, privacy, compliance, accessibility, resilience, and viability risks have qualified reviewers - data, integrations, identity, workflows, and knowledge dependencies are mapped - alternative capabilities are based on current verified evidence - migration estimates include coexistence, validation, retraining, integration, disruption, and decommissioning - data exit includes export completeness, validation, retention, deletion, and confirmation - negotiation positions have credible alternatives and approved authority - the recommendation remains defensible under documented sensitivity cases - every exception has an owner, approver, compensating control, and expiry - final commercial, contractual, and risk decisions remain with accountable human approvers - every major conclusion is supported by evidence or explicitly labelled as an assumption - no unreviewed source, untested capability, unapproved action, or unresolved conflict is described as complete - the final next action is the smallest safe step that materially reduces renewal uncertainty or commercial risk Begin by checking the supplied context for blocking gaps. If none remain, build the renewal clock and evidence register, complete the review in order, compare all credible scenarios, and issue the recommendation.Input for this step
Provide the preferred and fallback portfolio scenarios, vendor contracts, renewal and notice dates, utilization and outcome evidence, service performance, risk, dependencies, negotiation context, alternatives, and transition constraints.
Carry forward
Carry vendor-specific renew, resize, renegotiate, temporarily extend, replace, or exit recommendations, negotiation gates, transition readiness, deadlines, and unresolved terms into the final brief.
Review note
The commercial owner, finance reviewer, legal reviewer, security reviewer, and operational owner approve vendor-level conditions and contract actions.
-
Step 4 Prepare the accountable portfolio decision brief
Synthesize the inventory, portfolio scenarios, vendor actions, migration constraints, costs, controls, uncertainty, and dissent into comparable options and a decision-ready recommendation.
Prompt: Executive Decision Brief PromptPrepare an executive decision brief for the following decision. Decision inputs - Decision question: [Decision question] - Decision owner and approval authority: [Decision owner and approval authority] - Decision deadline: [Decision deadline] - Business context: [Business context] - Options already under consideration: [Options under consideration] - Evidence pack: [Evidence pack] - Constraints and non-negotiables: [Constraints and non-negotiables] - Decision criteria and priorities: [Decision criteria and priorities] - Affected stakeholders: [Affected stakeholders] - Risk, authority, and escalation limits: [Risk, authority, and escalation limits] - Definition of a decision-ready brief: [Definition of done] Input requirements Treat the decision question, accountable owner, deadline, known constraints, and at least one credible source describing the current situation as minimum inputs. Financial baselines, operating metrics, forecasts, customer evidence, contracts, policies, prior decisions, stakeholder positions, and option estimates are useful supporting inputs. If the decision question, authority, material constraints, or baseline evidence is missing or contradictory, ask only the questions that block responsible comparison or recommendation. If answers are unavailable, continue only where bounded analysis is safe. Preserve each unresolved item as an unknown, conflict, or assumption; do not manufacture figures, stakeholder agreement, approvals, or evidence. Evidence and tool rules 1. Use ChatGPT to organize supplied material, test reasoning, compare options, calculate only from provided figures, and draft the brief. State any calculation method and show enough working for review. 2. Do not imply access to internal systems, live dashboards, private links, meetings, or external sources unless their contents are actually available in the conversation. A URL alone is not evidence if its relevant content cannot be inspected. 3. Classify material claims as one of: supplied fact, direct observation from supplied material, calculation, stakeholder assertion, assumption, hypothesis, forecast, unknown, or conflict. Cite the file, excerpt, table, date, or source label supplied by the user whenever available. 4. Separate historical results from forecasts and correlation from demonstrated causation. Flag stale data, mismatched periods, inconsistent definitions, selection bias, omitted costs, optimistic adoption assumptions, and unsupported precision. 5. Never describe an option as approved, funded, validated, compliant, tested, launched, communicated, or completed unless the supplied evidence proves that state. Keep proposed, pending approval, blocked, unverified, and executed states distinct. Decision analysis workflow 1. Frame the decision: Rewrite the question as a specific choice to be made by the named owner by the deadline. Define what is in scope, what is excluded, why a decision is needed now, and the consequences of delay or no decision. 2. Establish the baseline: Summarize the current operating and financial position using the most decision-relevant metrics. Record metric definitions, periods, sources, and known data-quality limitations. Distinguish verified baseline values from estimates. 3. Confirm decision rights: Identify the recommender, approver, consulted parties, implementers, and parties who must be informed. Flag conflicting mandates or any action exceeding the stated authority limits. 4. Define evaluation criteria: Convert the supplied priorities into clear criteria such as strategic fit, customer impact, expected value, cash requirement, time to value, operational feasibility, reversibility, compliance exposure, security or privacy impact, workforce impact, and execution risk. Assign weights only when supplied or transparently proposed; do not present invented weights as executive preferences. 5. Build a complete option set: Analyze the supplied options and add a status quo, defer, pilot, staged commitment, or reversible alternative when materially relevant. Do not add artificial options merely to create symmetry. Define scope, prerequisites, dependencies, timing, resource demand, and opportunity cost for each credible option. 6. Normalize the comparison: Use consistent time horizons, units, cost boundaries, discounting assumptions, and metric definitions. Reconcile one-time and recurring costs, benefits, downside exposure, implementation capacity, and displaced work. Identify values that cannot be compared reliably. 7. Test economics and outcomes: Where evidence permits, show formulas and inputs for relevant measures such as incremental revenue, avoided cost, total cost of ownership, contribution margin, payback period, break-even point, or expected value. Use ranges or scenarios rather than false precision. Never invent a return estimate when required inputs are absent. 8. Stress-test the options: Evaluate base, upside, and downside cases; key sensitivities; adoption or demand shortfalls; schedule slippage; cost overruns; dependency failure; vendor or concentration risk; regulatory, legal, privacy, security, reputational, and workforce effects where applicable. Identify assumptions capable of reversing the ranking. 9. Account for stakeholder effects: State who benefits, who bears cost or disruption, likely objections, distributional effects, change-management needs, and unresolved dissent. Do not infer stakeholder consent from silence. 10. Form the recommendation: Recommend one option only when the evidence supports a defensible preference. Explain why it wins against the criteria, what trade-offs are accepted, confidence level, and what new evidence would change the recommendation. If evidence is insufficient, issue a conditional recommendation or a clearly bounded no-recommendation finding. 11. Design execution gates: Translate the recommendation into decision gates, accountable owners, dependencies, resources, approval points, leading and lagging indicators, review cadence, stop-loss thresholds, and rollback or exit conditions. Treat all owners and dates not explicitly confirmed as proposed. 12. Verify decision readiness: Reconcile important claims to sources, arithmetic to inputs, option scores to rationale, recommendation to criteria, risks to controls, and implementation gates to named authority. Report every failed or unperformed check rather than claiming verification. Authority and safety boundaries - Produce analysis and a recommendation, not an approval. Do not authorize spending, sign contracts, change policy, contact stakeholders, publish communications, move data, alter systems, or initiate implementation. - Require explicit human authorization for commitments involving funds, personnel, customers, regulated activity, contracts, production operations, security, privacy, legal positions, or external communications. - Minimize exposure of personal, confidential, privileged, security-sensitive, or commercially restricted information. Recommend redaction or aggregation when detailed data is unnecessary. Do not reproduce secrets or credentials. - Flag where qualified finance, legal, compliance, security, privacy, HR, procurement, or operational review is required. Do not represent the brief as a substitute for those approvals. - Stop at analysis and escalate when evidence suggests unlawful conduct, material safety danger, unauthorized access, sanctions exposure, serious privacy or security risk, an unbounded financial commitment, or a decision outside the named owner's authority. - For difficult-to-reverse actions, prefer staged commitment, pilot controls, backups, rollback planning, and explicit kill criteria where practical. Required output A. Decision header - Decision statement - Accountable decision owner and required approvers - Decision deadline and urgency - Scope and exclusions - Current state of the decision: exploratory, under review, recommended, pending approval, or another evidence-supported state B. Executive position - Recommended option or no-recommendation finding - Three to five reasons tied to evidence and criteria - Material trade-offs being accepted - Confidence level with rationale - Immediate decision requested from the owner C. Baseline and decision trigger Provide the relevant operating, customer, market, workforce, and financial baseline; why action is being considered now; cost of delay; and status quo trajectory. Include source, period, metric definition, and limitation for each pivotal baseline claim. D. Evidence ledger Create a table with columns: ID; material claim; classification; source or calculation; source date or period; reliability or limitation; confidence; and implication. Include contradictory evidence rather than silently resolving it. E. Decision criteria Create a table with columns: criterion; definition; weight or priority; measurement method; threshold; source of priority; and uncertainty. Clearly mark proposed weights. F. Options and trade-off matrix Create a table with one row per credible option and columns: option; scope; strategic fit; expected benefits; full costs; time to value; feasibility; key dependencies; reversibility; principal risks; stakeholder effects; evidence gaps; and criterion-based result. Include status quo or defer when materially relevant. Follow the table with concise explanations for any scoring or ranking. G. Economics and scenario analysis Show applicable formulas, inputs, units, time horizon, and results. Compare base, upside, and downside cases. Identify the variables with the greatest effect on the outcome and any break-even threshold. If economics cannot be calculated, list the missing inputs and avoid numeric conclusions. H. Recommendation rationale Explain why the preferred option is superior to each viable alternative, which disadvantages remain, why they are tolerable, what assumptions the recommendation depends on, and the evidence or event that would reverse it. State meaningful dissent or unresolved objections. I. Risk and control register Create a table with columns: risk; cause; affected objective; likelihood; impact; exposure; early warning indicator; preventive control; contingency or recovery action; proposed owner; escalation threshold; and residual risk. Distinguish existing controls from proposed controls. J. Approval-gated implementation outline Create a table with columns: phase or gate; intended outcome; proposed owner; prerequisites; resources; approval required; target timing; acceptance evidence; stop condition; and rollback or exit path. Do not imply that any phase has begun unless execution evidence was supplied. K. Measurement and review plan Define the baseline, target, metric owner, data source, measurement frequency, leading indicators, lagging outcomes, guardrail metrics, review dates, and trigger for continue, adjust, pause, scale, or stop decisions. Note whether each target is supplied or proposed. L. Verification and acceptance record Create a table with columns: check; expected condition; actual observation from supplied material; evidence reference; result as passed, failed, unperformed, or blocked; and required resolution. At minimum check: - the decision owner and approval path are explicit; - options use consistent scope, units, and time horizons; - pivotal claims trace to evidence; - calculations reconcile to source inputs; - assumptions and forecasts are labeled; - status quo and delay consequences were considered; - recommendation follows the stated criteria; - material downside and affected stakeholders are represented; - authority, specialist-review, privacy, and compliance limits are addressed; - implementation gates have acceptance evidence and stop or exit conditions; - no completion or approval claim exceeds available evidence. M. Open issues and handoff List blocking questions, non-blocking unknowns, evidence conflicts, required specialist reviews, decisions reserved for humans, and the smallest safe next action. End with a concise decision-owner checklist separating: decide now, obtain evidence, seek approval, and defer.Input for this step
Supply all prior outputs, the decision question and deadline, non-negotiables, decision criteria, affected stakeholders, authority boundaries, and required implementation or transition evidence.
Carry forward
Produce the final retain, consolidate, retire, or defer decision record with approved conditions, vendor actions, migration sequence, owners, risks, evidence gaps, next actions, and re-review triggers.
Review note
The accountable portfolio or process owner makes the decision; contract, data, security, privacy, migration, and release actions remain with their designated owners.
Completion criteria
The workflow is complete when:
- The inventory distinguishes assigned access, meaningful use, shadow tools, ownership, and evidence gaps.
- True redundancy is assessed against validated capabilities, dependencies, contracts, controls, and migration risk rather than category labels or seats alone.
- Affected vendors have renewal, renegotiation, extension, replacement, or exit actions with timing and evidence gates.
- The decision brief identifies retain, consolidate, retire, or defer outcomes, owners, conditions, migration sequence, and reversal risk.
- No contract action, access removal, migration, data deletion, or communication is represented as authorized or completed without evidence.
Related Workflows
Browse WorkflowsVendor Procurement Due Diligence
Assess vendor claims, evidence quality, security and privacy risk, procurement fit, and decision readiness before approval.
Make an AI Initiative Value and Scale Decision
Reconcile an approved AI value case to realized evidence, diagnose value leakage, calculate accepted-outcome unit economics, and issue a Scale, Hold, Redesign, or Stop decision.
Safe AI Agent Workflow Selection and Deployment Readiness
Move from a broad list of AI opportunities to one prioritized, mapped, governed, and measurable agent workflow that is ready for an informed pilot decision.
Was this useful?