Two Kinds of SoD Buyer, and Why One of Them Never Answers Your Email Again
2026-08-19

Two kinds of SoD buyer, and why one of them never answers your email again

Article 3 of Field Notes, a series on what we learned selling an offline SAP access-risk tool.


There is a specific silence that follows a good demo. The call went well, the questions were sharp, someone said "this is exactly what we have been looking for", and then nothing. You follow up twice. You get a polite one-liner or you get nothing at all.

It happened to us enough times that I stopped treating it as a sales failure and started treating it as data. The pattern turned out to be readable, and it is readable early. Here is what separates the deals that closed from the ones that evaporated.

The compliance-driven buyer

This buyer has a deadline and an auditor. Usually one of:

  • An external audit finding on segregation of duties that needs a documented response
  • A carve-out, merger, or S/4HANA go-live where someone asked for an SoD report as a gate
  • A first-year SOX or ISAE 3402 scope where the control owner has never produced this evidence before

What they need is a document. A defensible, dated, reasonably rigorous document that says these are the conflicts, here is the analysis, here is what we are doing about it. Once they have it, the need is gone. Not reduced. Gone, until the next audit cycle, and by then the person may have changed roles.

These buyers are wonderful during a trial. They are engaged, they run real data, they ask good questions, and they get value fast, because a tool that produces a clean risk report in an afternoon is exactly what solves their problem. We extended trials for several of them, happily, because the engagement looked like the strongest signal we had.

Then the report was produced, the finding was closed, and the conversation ended. In some cases with a straight answer, which I appreciated. In others with silence.

I want to be fair to these buyers. Nobody misled us. They needed a thing, they used the tool to get the thing, and the tool worked. The mistake was ours: we read intensity of use as intent to buy, and those are different variables.

The efficiency-driven buyer

This buyer already produces SoD reports. That is the point. They produce them repeatedly and it hurts.

Typical shapes:

  • A security team running a role redesign across multiple countries who needs to simulate the impact of a role change before it goes to PFCG
  • A consulting firm doing the same analysis for a different client every month
  • An internal audit function that has to re-run analysis every quarter and reconcile it against last quarter
  • Anyone whose current process involves exporting to Excel and doing lookups by hand

Their problem is not "I need a report". It is "I need this report forty times and each one currently costs me two days". The value is recurring, so the licence is recurring, so the renewal conversation is easy because the pain would come straight back.

Every multi-year relationship we have is with this second type. Without exception.

How to tell them apart in the first call

You can usually diagnose this in fifteen minutes with three questions.

"When did you last run an SoD analysis, and how?" Never, or years ago, or "we have a spreadsheet from the auditors": compliance-driven. Last month, using some combination of tooling and manual work, with an opinion about what was wrong with it: efficiency-driven.

"What happens after you have the report?" "We close the finding" is one answer. "We hand it to the role owners and then argue about it for six weeks" is a completely different answer, and the second one is a buyer whose pain lives in remediation, not detection.

"Who asked for this, and what is their deadline?" A named date tied to an audit milestone is a warning. A named date tied to a project go-live can go either way. No date at all, driven by the team's own frustration, is the best signal in the set.

None of this means you should refuse to work with compliance-driven buyers. It means you should price and resource them differently. A short licence, a fixed-scope engagement, or a one-off assessment fits their actual need much better than a trial that you keep extending in the hope of a renewal that was never going to come.

The thing I got wrong

For about six months I treated trial extension as a relationship-building move. Someone would ask for two more weeks, I would give six, on the reasoning that generosity now buys goodwill later.

It did not. In the compliance-driven cases, extending the trial simply let them finish the project for free, and I had removed my own deadline in the process. In the efficiency-driven cases, the extension was not needed, because those buyers had already decided by week two.

What I do now is ask what the extension is for and what happens at the end of it. If the answer is a specific next step with a specific person, the extension is fine. If the answer is vague, the extension will not change the outcome, and saying so politely tends to produce an honest reply. Several times that honest reply was "we only needed this for the audit", which is a perfectly good answer and one I would rather have in week three than in month four.

For the buyer side

If you recognise yourself as the compliance-driven type, say so. Vendors are not offended by it. You will get a scoped commercial proposal instead of an unwanted courtship, and you will probably get it cheaper, because a defined short engagement is easier to price than an open-ended trial.

The worst outcome for everyone is the one where both sides pretend the evaluation is about a long-term platform decision when it is actually about closing one finding by the end of the quarter.


Next in this series: why organisations that already own SAP GRC Access Control keep evaluating additional tools.

« All posts