Salesforce Licensing · 2026 Playbook

Salesforce Licence Compliance & Audit Readiness: A CIO's Playbook

Cloud does not mean automatic compliance. This advisory playbook covers Salesforce's licensing model, common compliance pitfalls, True Forward adjustments, enforcement mechanisms, and best practices for CIOs to proactively manage Salesforce usage and avoid audit surprises.

Salesforce LicensingCompliance & Audit ReadinessCIO Advisory
Named UserPer-user subscription model — each individual needs their own licence
True ForwardAutomatic billing adjustments for exceeding contracted quantities
125–150%Typical overage rate if True Forward charges not pre-negotiated
Cloud ≠ SafeAudit risks remain — tied to how you use the service, not just user counts

📋 Table of Contents

1
Licensing

Salesforce's Licensing Model & Cloud Audit Risks

+

User-Based Subscription Model

At its core, Salesforce licensing is primarily user-based — organisations purchase user "seats" (e.g., Sales Cloud or Service Cloud licences) for specific individuals. Each licence type and edition grants a specific set of features and usage entitlements: data storage, API calls, custom objects, and more. Salesforce also offers feature add-ons and usage-based products (Marketing Cloud contacts, Community logins) billed by volume. This mix of per-user licences and usage-based entitlements provides flexibility but also significant complexity.

"No Over-Deployment" vs. Hidden Risks

Unlike on-premises software, you generally cannot exceed the number of user licences purchased — the platform won't allow unlicenced users to log in. This leads many to assume cloud software has no compliance issues. In reality, audit risks still exist in areas beyond simple user counts.

Salesforce's Master Subscription Agreement (MSA) includes strict usage terms — including a clause prohibiting any use that "circumvents a contractual usage limit." In practice, this means even if the system technically allows certain actions, they may violate your contract. Examples include using one account for multiple users, exceeding feature limits, or using Salesforce data in unauthorised ways.

⚠ Key Risk: Vendors like Salesforce have begun auditing SaaS customers to ensure usage aligns with contract terms — not just to count active users. The cloud prevents classic overinstallation, but compliance risks remain — often more subtle, tied to how you use the service rather than the number of users.

Why Audits Happen in a Cloud Service

Salesforce historically hasn't been as audit-heavy as legacy software vendors. Still, it retains contractual audit rights to protect its intellectual property and revenue. Audits or compliance checks may be triggered if Salesforce suspects misuse or simply as part of true-ups during renewals.

True Forward provisions in many enterprise agreements mean that if you exceed contracted quantities (extra users, more contacts, API calls above cap), Salesforce will adjust costs upward at the next billing period. This is less a "gotcha" audit and more an automatic billing adjustment — but it can feel like an audit outcome with significant budget impact.

All usage is tracked on Salesforce's servers. If you quietly added 50 more users than contracted or exceeded a usage cap, Salesforce will eventually find out and bill via True Forward or contract amendment. In some cases, Salesforce may formally invoke audit rights to get detailed compliance data — especially if suspected of violating terms.

💡 Bottom Line: Salesforce's licensing model relies on trust that customers will stick to what they bought. The platform enforces some technical limits, but many entitlements are honour-based. This creates audit risk: if your organisation unknowingly oversteps, you could face compliance issues even without adding unauthorised users. Active licence management and oversight are required. See our Salesforce Licence Optimisation Service for how we help enterprises maintain compliance.
2
Pitfalls

Common Licence Compliance Pitfalls

+

Even well-managed Salesforce orgs can drift into non-compliance due to everyday pressures and mistakes. Below are the most common compliance issues — each with real-world examples:

1. Credential Sharing & Generic Accounts

Sharing login credentials is prohibited by Salesforce's licensing terms, yet it happens frequently. This includes multiple employees using a single "generic" user account (e.g., a shared support login) or hardcoding one user's credentials into team integrations and scripts. Salesforce considers this "indirect access" — even if all individuals have their own licences, using a single account for collective access violates policy.

Example: A customer service department sets up a generic "SupportAgent" Salesforce user for shift workers. Salesforce flags multiple people (different IPs, concurrent sessions) using the same login. The company is required to purchase a separate licence for each user. In another case, a developer hardcoded an executive's Salesforce credentials into a data integration script serving 5–10 internal applications — Salesforce identified the compliance gap and required additional licences plus re-architecture.

Impact: Credential sharing is low-hanging fruit for auditors — easy to detect via abnormal login patterns. If found, Salesforce can require back payment as if each person had their own licence all along.

2. Excessive API Usage & Integration Misuse

Salesforce provides API call allowances with most editions. Integrations that over-utilise the API can run into technical limits and licensing scrutiny. One common scenario: using a single low-level licence or integration user to funnel massive transaction volumes from multiple systems — avoiding paying for higher API capacity or additional full licences.

Example: An IoT company connected device telemetry to Salesforce using one integration account making millions of API calls per day. Salesforce recommended purchasing an "API calls add-on" and noted the integration was effectively allowing thousands of devices to interact with Salesforce data — each distinct source potentially needing proper licensing. In another case, an organisation used multiple accounts in round-robin to bypass per-org API limits — Salesforce explicitly called this out as misuse.

Impact: At minimum, uncontrolled API usage breaks integrations when limits are reached. From compliance view, it can lead to mandated upgrades or add-on purchases. If high API usage is due to indirect access by many users, Salesforce may require you to licence those users or acquire a different product.

3. Exceeding Entitlements or Misusing Feature Access

Every Salesforce licence comes with specific entitlements — limits on custom objects, data storage, platform events, and feature access. For some features, Salesforce trusts you to self-regulate. A key example: Restricted-Use Licences — discounted licences with contractual functionality limits not enforced by software. The system won't stop a user with a "Service Cloud Restricted" licence from editing an Opportunity if permissions are granted — it relies on the customer to honour terms.

Example: A company purchased 100 "Light" (Platform) licences for employees needing only custom app access. An admin later gave those users access to the core Sales app, allowing them to update deals. Salesforce's account team found Platform users editing Opportunity records — the customer was required to upgrade all 100 to full Sales Cloud licences, backdated to when they first used those objects.

Impact: The MSA typically states that if restricted-use licence restrictions are breached, those licences will be automatically upgraded to full licences from the date of first violation. This means costly back-billing for the entire period of misuse.

4. Improper Use of Exported Data & External Access

Using exported Salesforce data outside the platform can present compliance issues if it effectively extends functionality to users or uses not covered by your licence. This is an indirect access scenario: unlicenced individuals benefiting from Salesforce-originated data. Salesforce's terms typically specify the service is for a customer's internal business use only.

Example: A regional bank regularly exported customer data from Salesforce into a home-grown portal used by agents without Salesforce licences. Salesforce questioned how the bank was enabling those agents — ultimately the bank had to purchase Experience Cloud (Community) licences for them so usage fell under a proper licence model.

Impact: Using Salesforce data in unlicenced ways is another form of indirect access risk. If discovered, Salesforce can demand appropriate licences be purchased or the practice cease. The financial impact can be similar to an audit finding — significant unexpected licensing costs.

3
Enforcement

Salesforce's Enforcement Mechanisms

+

Salesforce employs a combination of contractual rights and commercial mechanisms to enforce compliance. CIOs must understand how these work to anticipate and manage enforcement actions.

True Forward Adjustments

True Forward is a provision in larger Salesforce contracts that means if your usage exceeds contracted quantities (user count, storage, API calls), Salesforce will adjust your subscription costs to "true up" with that usage — typically at the next contract period or anniversary. Unlike a one-time penalty, True Forward is a formalised catching-up: you start paying for higher usage in the future (and sometimes for the excess period).

True Forward can also apply to consumption-based products — exceeding Marketing Cloud email or contact counts can automatically trigger higher-tier pricing. True Forward rates for overages are often at list price or with lower discounts — it's not uncommon to see overage rates at 125–150% of normal price if not pre-negotiated. True Forward only moves upward — it generally won't reduce costs if usage drops.

⚠ Budget Risk: If you're nearing a contractual limit, it's significantly better to proactively negotiate an expansion than to face higher True Forward rates. CIOs must keep a close eye on usage trends and engage independent negotiation support to secure better overage terms before they're needed.

Contractual Audit Rights

Salesforce's MSA grants the vendor the right to verify compliance. This can include auditing your usage with notice (e.g., 30 days), typically no more than once per year. In practice, Salesforce hasn't been as aggressive with audits as legacy software vendors — they favour selling more capabilities during renewals and upsells. However, audits do happen, especially in large enterprises or when Salesforce suspects violations.

If non-compliance is found, the typical remedy is purchasing necessary licences to cover usage — effective immediately and sometimes retroactively. The contract may specify any shortfall will be charged at then-current list price, which can be much higher than negotiated rates. In rare cases, Salesforce may consider it a breach of contract; most often they prefer to resolve it commercially.

💡 Key Difference: Audits can happen at any time and look backward at compliance. True Forward is typically a scheduled adjustment looking forward. It's generally better to identify and address compliance issues internally before the vendor audits — that way you can negotiate additional licences on better terms rather than paying list prices under audit pressure.

Other Enforcement Tools

⚙️
System Enforcement of Limits

Salesforce automatically enforces hard limits: storage, API calls per 24 hours, maximum users without additional ordering. Hitting these limits forces the conversation — if you need more, you must buy more.

👤
Sales Team Oversight

Your Salesforce account executive reviews usage and adoption metrics, especially around renewal time. If they see usage not covered by your contract, they'll bring it up as an upsell. Softer than an audit — but the goal (selling more to cover your needs) is the same.

📋
Contractual Clauses

Large deals may include periodic usage reporting requirements, True Forward terms, and audit cost recovery provisions. If an audit finds significant underpayment, you may also have to pay the costs of the audit itself.

💡 Bottom Line: Salesforce enforcement is usually financial and contractual — not technical "kill switches." You won't wake up to find Salesforce turned off. Instead, the risk is a sudden bill or contract addendum that increases costs. CIOs should aim to avoid that by continuously managing compliance. Our Salesforce Licence Optimisation Service includes compliance assessments to identify risks before Salesforce does.

Need help identifying Salesforce compliance gaps before your next renewal or audit?

Salesforce Licence Optimisation →
4
Governance

Best Practices: Policy, Governance & Monitoring

+

Policy & Governance: No Sharing, Clear Rules

🔑
Establish a "Named User Only" Policy

Set an unambiguous internal policy forbidding shared Salesforce accounts or credentials. Every person accessing Salesforce must use their own licenced account. Make this part of your security policy and communicate it to all employees, contractors, and partners. Leverage Salesforce's technical controls — enable two-factor authentication and single sign-on (SSO) to make sharing difficult. Clearly state that violations could lead to disciplinary action.

📋
Document Licence Entitlements & Restrictions

Procurement or vendor management should maintain a summary of what's purchased and key usage restrictions. If you negotiated restricted-use licences or a cap on Marketing Cloud contacts, ensure these details are accessible to your Salesforce admin and development teams. Non-compliance often occurs simply because IT admins were unaware of contractual restrictions. Briefing admins whenever new contracts are signed — translating licence terms into administrative configurations — is essential.

🛡️
Role-Based Access Controls

Use Salesforce's built-in profile and permission-set infrastructure to enforce licensing boundaries. If a group has restricted licences that shouldn't access Object X, create a profile that removes that access. Align profiles with licence types — this follows both compliance and security best practices (principle of least privilege). Conduct periodic access reviews to ensure users have correct profiles for their licence type.

👥
Governance Committee

Form a cross-functional "Salesforce Governance Board" meeting quarterly. Include IT (platform owner), Security/Compliance, Procurement, and business stakeholders. This group reviews licence usage, upcoming needs, and policy violations — elevating compliance from an administrative task to a management issue. They can approve or deny unusual requests (e.g., sharing a login "temporarily" — answer: no).

Monitoring & Licence Management: "Trust But Verify"

📊
Track Usage Metrics Continuously

Use Salesforce admin reports and dashboards to monitor: User Login Activity (identify inactive users for licence recycling; flag unusual patterns like concurrent multi-location logins); API Usage (check via Setup; set alerts at 80% of daily limits); Feature Limits (review data storage, file storage, custom objects via System Overview); Licence Assignments vs. Purchased (proactively manage counts rather than waiting for Salesforce to flag at renewal).

🔍
Internal Audits (Self-Audits)

Conduct internal compliance audits at least annually — preferably semi-annually or quarterly for large orgs. Review all active accounts and licence types, check for generic or suspicious accounts, validate restricted-use licence holders are actually restricted in the system, and ensure no production use of trial features. Document findings and remediate immediately. Self-audits also reveal optimisation opportunities — unused licences that can be reclaimed.

🛠️
Use Licence Management Tools

For large deployments or multiple orgs, consider SAM tools or Salesforce's own License Management App. These automate tracking of usage vs. entitlements, simulate what-if scenarios, and aggregate data across instances. While not strictly necessary, tools ease the monitoring burden and provide alerts and reports for the CIO and stakeholders.

📅
Align with Procurement on Renewals

Before renewal, conduct thorough review of actual usage vs. what you're paying for. Go into negotiations with a clear picture — you can drop unused licences (saving money) or secure proactive discounts on growth. This reduces True Forward surprise and treats renewal as a "licence true-up on your terms" rather than Salesforce dictating it. See our Salesforce Contract Negotiation Service.

5
Integration

Best Practices: Integration, API & Audit Readiness

+

Integration & API Governance

📝
Inventory & Vet All Integrations

Create and maintain an integration register — a list of all systems connecting to Salesforce, what data they exchange, and what accounts they use. Each integration should have a named owner, documented purpose, and appropriate Salesforce user account. Avoid situations where integrations inexplicably use an admin's account or an undocumented generic account.

🔗
Dedicated Integration Users

Use separate "integration user" accounts for major external systems. For example, an ERP sync should use its own API-only licence — not piggyback on a human user's account. This improves security, traceability, and prevents the integration from requiring excessive permissions. Important: these accounts still count as user licences — budget for and purchase them, don't try to "save" by sharing.

🔐
Secure Integrations Properly

Don't hardcode usernames and passwords in integration code. Use OAuth and certificate-based connections. This ensures you can centrally control and revoke access, ties into Salesforce's audit logs, and lets you enforce login IP ranges or login hours for integration users to reduce misuse risk.

📈
Monitor API & Integration Usage

Assign someone to regularly review integration logs. Correlate with Salesforce's API usage stats. If one integration suddenly floods the system or fails and retries (potentially exceeding call limits), intervene quickly. Code reviews for Salesforce integrations should include checks against governor limits and licenced allowances.

🏷️
Naming Conventions & Identity

Clearly distinguish integration accounts by username (e.g., "INTG_EcommerceSite" or "API_DataWarehouse") so they stand out in user lists. Ensure these accounts are not used interactively by people — they should be API-only. If you suspect someone logged into an integration account to use the Salesforce UI, address that immediately.

🌐
Review External User Access

If you use Experience Cloud (Community) or portals, govern those closely. Ensure you're not giving portal access to someone who should be a full internal user, and vice versa. Any person — internal, partner, public — who consumes Salesforce-stored data or functionality should be accounted for in your licensing strategy.

Audit Preparation & Response

⚖️
Know Your Contractual Rights & Obligations

Work with legal counsel to understand the audit clause: notice period, what you must provide, scope limits. Determine who is the primary contact for Salesforce audits (typically procurement or asset management) and ensure IT is in sync.

👥
Assign an Audit Response Team

Like an incident response plan: Salesforce platform owner (IT), legal, procurement/vendor management, and finance. Legal manages communications and NDAs; IT gathers usage data; procurement and finance handle commercial discussions. This team convenes immediately if an audit notice arrives.

🧪
Perform a Mock Audit

Take Salesforce's perspective: produce the reports they'd request (active users and licence types, external system access evidence, usage-based consumption metrics). If anything looks off — e.g., 10 more active users than licences, or 300 partner community users against a 250 contract — fix it before Salesforce asks.

📡
Centralised Communication

All audit communications should be channelled through a single point person (procurement or legal) — not ad-hoc replies from various IT personnel. Have legal review any data before it's sent. Only provide scope of data required by contract — don't volunteer extra information.

🤝
Negotiate & Mitigate Findings

Non-compliance findings aren't the end of the story. Negotiate a fair resolution: instead of paying full list price retroactively, negotiate a new deal at discounted rates. Salesforce often waives strict back-billing as goodwill if you're also renewing other products. Involve independent negotiation experts to strategise this — they know what concessions are achievable.

6
Action Plan

CIO Recommendations Checklist

+

CIOs should take proactive steps to ensure Salesforce compliance and be prepared for any audits or True Forward adjustments. Here is the comprehensive checklist:

✅ 10-Point CIO Compliance Checklist

1
Enforce Named-User Access

Implement a strict policy against shared Salesforce accounts or credentials. Ensure every individual user has their own licence and login. Monitor and prevent any credential sharing.

2
Educate & Document

Keep an updated playbook of Salesforce licence entitlements, limits, and restrictions. Educate admins and users (especially developers integrating systems) on these terms so everyone understands what is and isn't allowed.

3
Regular Internal Compliance Audits

Conduct periodic self-audits of Salesforce usage — review user lists, roles, and feature usage against your contract. Clean up unused accounts and correct incorrect assignments. Catch and fix issues internally before Salesforce notices.

4
Monitor Usage Continuously

Set up dashboards or alerts for key usage metrics: API calls, storage usage, active users vs. purchased. Early detection of unusual usage prevents inadvertent violations and provides time to purchase more capacity if needed.

5
Govern Integrations & APIs

Control how external systems access Salesforce. Use dedicated integration user accounts (licenced appropriately), don't share them, and monitor their activities. Ensure any person or system accessing Salesforce data externally is properly licenced.

6
Optimise Licence Assignments

Match users with the right licence type for their role. Don't give a full Sales Cloud licence to someone who only consumes reports — and don't try to have a service agent operate with a lower licence than they need. Regularly right-size to stay compliant and cost-efficient.

7
Plan for True Forward Scenarios

Anticipate growth and include buffer in your agreement. Negotiate better overage terms (caps or discounts on True Forward charges) during contract negotiations. Budget for potential True Forwards if in a fast-growing environment. Better to slightly over-licence upfront than be caught by surprise at worse prices.

8
Coordinate with Legal & Procurement

Treat licence compliance as a team effort. Involve legal and procurement in establishing policies and responding to vendor inquiries. If an audit notice comes, have a clear internal game plan and unified communication with Salesforce.

9
Maintain Good Vendor Relations

Build a transparent relationship with your Salesforce account manager. Proactively discuss usage and roadmap. If you foresee needing more licences or hitting a limit, work out a plan. Salesforce is less likely to initiate an adversarial audit if you're showing good faith.

10
Leverage Expert Help

For complex Salesforce environments, engage independent software licensing advisors or use specialised tools to maintain compliance. An external perspective identifies obscure issues like indirect access loopholes and advises on remediation before the vendor intervenes.

💡 Core Principle: Integrate Salesforce licence governance into regular IT operations — not as a one-time project but as an ongoing discipline. This protects your IT budget, supports better vendor relationships, and keeps your deployment running smoothly without unwelcome audit surprises. For enterprises navigating complex Salesforce estates, Redress Compliance's Salesforce Advisory Services provide end-to-end support from compliance assessment to negotiation strategy.

Approaching a Salesforce renewal? Get independent benchmark data and negotiation strategy before Salesforce sets the terms.

Salesforce Negotiation Service →

📂 Salesforce & Enterprise Licensing Case Studies

📄 Salesforce Licensing — Related Deep-Dives

Frequently Asked Questions

Can Salesforce actually audit SaaS customers?+
Yes. Salesforce's Master Subscription Agreement (MSA) typically grants them the right to verify compliance with notice (e.g., 30 days), usually no more than once per year. While Salesforce has historically been less audit-aggressive than legacy vendors like Oracle or SAP, they retain and do exercise these rights — especially in large enterprise accounts or where misuse is suspected. Audits may involve requesting system extracts, running usage scripts, or asking for attestation of compliance. If non-compliance is found, the remedy is usually purchasing necessary licences, potentially at then-current list prices.
What is a True Forward, and how does it affect my budget?+
True Forward is a provision in Salesforce enterprise agreements that automatically adjusts your subscription costs if you exceed contracted quantities — whether user counts, storage, API calls, or other metrics. Unlike a one-time penalty, it's a formalised catch-up at the next billing period. The key budget risk: True Forward overage rates are often 125–150% of normal price if not pre-negotiated. True Forward only moves upward — it won't reduce costs if usage drops. CIOs should monitor usage trends closely and proactively negotiate expansion terms before hitting limits. See our Salesforce Contract Negotiation Service.
What are the biggest compliance risks in a cloud-based Salesforce environment?+
The four most common risks are: (1) Credential sharing and generic accounts — multiple people using the same login, which violates named-user licensing terms; (2) Excessive API usage and integration misuse — single integration accounts funnelling massive transactions from multiple systems; (3) Exceeding entitlements or misusing restricted-use licences — using features or objects not covered by your licence type, with potential backdated billing; (4) Improper use of exported data — unlicenced users benefiting from Salesforce data via external systems (indirect access). All four can result in significant unexpected costs if discovered during renewal or audit.
How should we handle restricted-use Salesforce licences?+
Restricted-use licences are discounted licences with contractual functionality limitations not enforced by the software. The system won't stop a user with a restricted licence from accessing objects they shouldn't — it relies on you to honour the terms. If restrictions are breached, the MSA typically states those licences will be automatically upgraded to full licences from the date of first violation, creating costly back-billing. The solution: configure Salesforce profiles and permission sets to actually remove access to restricted features, conduct periodic access reviews, and brief admins whenever new restricted-use terms are signed.
How often should we conduct internal Salesforce compliance audits?+
At minimum annually — but semi-annually or quarterly for large organisations. Internal audits should review: all active user accounts and licence types (verifying each corresponds to a real, authorised individual); generic or suspicious accounts; restricted-use licence holders (validating they're actually restricted in the system); trial features that may have been adopted without proper licensing. Document findings and remediate immediately. Self-audits prevent compliance issues and reveal optimisation opportunities — unused licences that can be reclaimed. Our Salesforce Licence Optimisation Service includes comprehensive compliance assessments.
What should we do if Salesforce initiates an audit?+
Have a pre-defined audit response plan: (1) Channel all communications through a single point person (procurement or legal); (2) Convene your audit response team (IT, legal, procurement, finance); (3) Understand contractual obligations — notice period, scope, what data you must provide; (4) Have legal review any data before sharing — only provide what's contractually required; (5) Don't panic — non-compliance findings are negotiable. Instead of paying full list price retroactively, negotiate a new deal with discounted rates, especially if you're also renewing. Engaging independent negotiation advisors improves outcomes significantly.
How do we prevent API and integration compliance issues?+
Maintain an integration register listing all systems connecting to Salesforce, data exchanged, and accounts used. Use dedicated integration user accounts (API-only licences) for each major system — don't piggyback on human accounts. Use OAuth/certificate-based connections, not hardcoded credentials. Monitor API usage via Setup and set alerts at 80% of daily limits. Clearly name integration accounts (e.g., "INTG_EcommerceSite") so they stand out. Ensure integration accounts aren't used interactively. Code reviews for Salesforce integrations should check against governor limits and licenced allowances.
Is it worth engaging an independent advisor for Salesforce compliance?+
For enterprises with significant Salesforce estates, independent advisors typically deliver ROI many times their fee. They bring current benchmark data from hundreds of Salesforce deals, identify compliance gaps and shelfware that internal teams overlook, and have experience with Salesforce's negotiation tactics — True Forward clauses, restricted-use licence terms, uplift mechanisms, and SELA structures. The key is engaging early (6–12 months before renewal) and ensuring the advisor is vendor-independent. Redress Compliance's Salesforce Advisory Services provide compliance assessment, licence optimisation, and negotiation support across the full Salesforce stack.
📊

Salesforce Licence Optimisation

Learn More →
🤝

Salesforce Contract Negotiation

Learn More →
💼

Salesforce Advisory Services

Learn More →
📋

Microsoft EA Optimisation

Learn More →
🛡️

Oracle Advisory Services

Learn More →

Related Salesforce Licensing Resources

Don't Wait for Salesforce to Find Your Compliance Gaps

Whether you're approaching a renewal, preparing for an audit, or simply want to ensure your Salesforce estate is compliant and optimised, Redress Compliance delivers vendor-independent advisory with a track record of significant savings for Fortune 500 enterprises.

Also managing Oracle, Microsoft, SAP, or IBM contracts? We cover all major vendors.

All Advisory Services →
FF

Fredrik Filipsson

Co-Founder — Redress Compliance

Fredrik Filipsson brings two decades of enterprise software licensing expertise, including hands-on experience at IBM, SAP, and Oracle. As co-founder of Redress Compliance, he advises Fortune 500 enterprises on complex software negotiations across Oracle, Microsoft, SAP, IBM, Salesforce, Broadcom, ServiceNow, and emerging cloud/AI vendors. His team's vendor-independent approach and fixed-fee model ensure procurement leaders receive objective, data-driven guidance to maximise value in every enterprise software engagement.