Health, Education & Government Higher Education Research & Grants Management

Sponsored Research

Multi-stakeholder institutional decisions where academic mission, student outcomes, and financial sustainability converge.

Example organizations in this space: Battelle RTI International Charles River Associates SAIC

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Pre-Sales

    Qualify and diagnose before investing in a full evaluation cycle.

    1. Fit Validation

      Quick qualification to confirm award type, funding constraints, decision authority, and urgency before investing in full discovery.

      Qualification Questions

      Award & Funding Fit - quick readiness check

      • Which best describes the award that is driving this request? Options: New federal award (grant or contract), Modification to an existing award, Response to an audit finding or compliance requirement, Pilot or cooperative agreement, Other
      • Does the award include explicit research security or NSPM-33 / NIST-related requirements we should plan for? Options: Yes - NSPM-33 / NIST controls explicitly required, Yes - agency-specific security clauses (please describe below), No security-specific clauses, Unsure
      • If known, briefly list award identifiers or the specific security/compliance clauses or notes the seller should be aware of.

      Integration and Access requirements

      • Will the seller need direct access or system integration with your institution's grants, contracts, or research management systems? Options: Yes - system-to-system integration required, Yes - named seller user accounts only, No - work will be via exported reports and emails, Unsure / need to confirm
      • Which categories of data will the project process or store? Select all that apply. Options: Unrestricted research data, Controlled Unclassified Information (CUI), Personally Identifiable Information (PII), Protected Health Information (PHI), Export-controlled data (ITAR/EAR), Other or not sure

      Budget and Decision Authority

      • Is there an allocated budget or funding line for external research management services, and which range best fits? Options: Allocated and approved - under $100k, $100k - $500k, $500k - $1M, Over $1M, No allocated budget yet, Prefer not to say
      • Who will authorize engaging an external research management partner and who else will influence that decision? (roles or brief names)

      Timeline and urgency

      • What is the target date or trigger driving this need (award start date, audit deadline, PI bandwidth), and how flexible is that timing? Options: Specific date or award start within 0-3 months, Within 3-6 months, Within 6-12 months, No firm deadline - exploratory
      • How would you describe the priority for moving to full discovery: critical (must start immediately), important (plan within the quarter), or exploratory? Options: Critical - must start immediately, Important - plan within the quarter, Exploratory - informational only right now
    2. Outcome Discovery

      Map stakeholders, current grants management state, regulatory constraints (NSPM-33 / NIST), and measurable success criteria.

      Discovery Questions

      Quick Tour: Your Current Award and Team

      • Tell me the award type and primary funder for this project, and whether it includes controlled unclassified information under NSPM-33. Options: Federal research grant (R&D), Cooperative agreement, Contracted research, Center or multi-site award, Other
      • Who are the named decision makers and which office signs off on data access and security for this award? Options: PI, Department Chair, VP Research/Research Office, Sponsored Programs/Grants Office, Institutional Security/IT, Other
      • How many active principal investigators and research sites are in scope for this award? Options: 1, 2-5, 6-15, 16-50, More than 50
      • When was the award issued and what is the operational start date the sponsor expects? Options: Already started, Start within 4 weeks, Start within 1-3 months, Start within 3-6 months, Start later than 6 months
      • Describe the current role your central research administration office plays versus departmental staff for daily grants management and security oversight.
      • What single missing approval, resource, or authority would stop you from meeting the award's compliance deadlines?

      Where the Work Actually Happens and Friction Shows Up

      • If your PIs suddenly had half the administrative time they currently spend, which grant-management task would fail first and why? Options: IRB/ethics submissions, Budget reconciliation, Subaward onboarding, Data access provisioning, Technical reporting deadlines, Other
      • On a typical month, how many compliance reports, IRB protocols, or subaward documents does your office process? Options: 0-10, 10-50, 50-200, 200-500, More than 500
      • Which manual handoffs, spreadsheets, or local trackers are relied on today to manage budgets, approvals, or data access? Options: Local spreadsheets, Shared drives, Email approvals, Homegrown database, Commercial grants system, Other
      • How often do late or incorrect approvals delay invoices, subcontract starts, or data sharing in a fiscal quarter? Options: Almost every month, Monthly, Quarterly, Rarely, Never
      • Which single recurring bottleneck, if resolved, would shorten your average award setup time by at least 30%?

      Who's in the Room When Things Go Wrong

      • Who gets notified first when a security control gap is discovered in an active study, and what typically happens next? Options: IT Security, PI/Co-PI, Department Admin, Sponsored Programs, Office of Research Compliance, Other
      • List the stakeholder roles that must approve data access, from institutional officials to PI designees. Options: PI, Co-PI, Department Admin, IT/Security Officer, Sponsored Programs, IRB/Human Subjects Office, Other
      • To what extent are principal investigators enabled to make data-sharing decisions without central office approval? Options: Full authority, Limited authority with notification, Approval required for sensitive data, Central approval always required, Varies by award
      • Estimate the number of named system administrators and security contacts required to grant access and meet NIST 800-171 controls. Options: 0-2, 3-5, 6-10, More than 10
      • What single role vacancy or governance gap would pause onboarding for all new users?

      Security and Compliance That Can't Be Ambiguous

      • Identify the NSPM-33 or NIST 800-171 control area you expect will be the hardest to demonstrate in an audit. Options: Access control, Audit and accountability, Configuration management, Identification and authentication, System integrity, Other
      • Describe any past audit findings, OIG recommendations, or sponsor security comments related to grants data or CUI handling and their current remediation status.
      • Has your institution completed a system security plan or SSP for the environment that will host award data? Options: Yes, current and published, In progress, Planned but not started, No SSP exists
      • List the categories of data in this program that are treated as CUI and who currently labels and enforces that classification. Options: Research data, Personal data, Export-controlled information, Contract deliverables, Other
      • If an external assessor demanded evidence of FISMA-equivalent controls this week, what one deliverable could you not produce within 14 days?

      Alternatives on the Table

      • Name the internal programs or external partners you are actively considering to manage grants security and administration. Options: Continue with incumbent provider, Internal build/IT project, Shared services from system office, New external vendor, Academic consortium solution, Other
      • Tell me which option currently acts as the incumbent for your awards, and why. Options: Internal office, Existing vendor, No incumbent, Other
      • What would need to be true about your current approach for you to keep it rather than switch to an outside partner?
      • Has anyone inside proposed a 'we'll build it ourselves' plan, and if so, which office owns that idea? Options: Yes, central IT, Yes, sponsored programs, Yes, department-led, No internal proposal, Other
      • Under what single condition would you abandon the incumbent or internal build and contract with an outside partner this quarter?

      Data and Integration Reality Check

      • Identify the integrations or APIs that are mission-critical and would break the project if unavailable. Options: Institutional grants system, HR/personnel system, Financial system/ERP, Identity provider/SSO, IRB system, Other
      • Rate the readiness of your primary grants system to export clean award, PI, and budget data for integration, on a 1-5 scale. Options: 1 - Not ready, 2 - Poor, 3 - Fair, 4 - Good, 5 - Ready
      • Name the file formats, API types, or middleware your team uses for secure data transfer. Options: SFTP/secure file, REST API/JSON, SOAP/XML, HL7 or other standard, Custom DB exports, Other
      • Do you have staff or contractors who will own integration testing and accounts provisioning, and how many FTEs are available? Options: No dedicated staff, 1-2 FTEs, 3-5 FTEs, More than 5 FTEs
      • Would a required three-month engineering effort to complete a critical integration be a deal stopper for this program? Options: Yes, would stop the project, No, schedule can absorb it, Maybe, needs leadership signoff

      Timeline and Gating — What Really Stops Launch

      • Pinpoint the single milestone in your internal review or institutional approvals most likely to push go-live past the award deadline. Options: Legal review, IT security approval, Budget signoff, Research compliance/IRB, Executive approval, Other
      • Provide a list of institutional approvals still outstanding and the office responsible for each, for example grants accounting, tech transfer, IRB, or IT security.
      • To what extent can sponsor budget flexibility or rephasing cover delays caused by institutional gating? Options: Fully cover delays, Partially cover, Unlikely to cover, Not applicable
      • When was the last time your institution paused an award launch due to an unresolved compliance item, and what caused the pause?
      • State the one approval or resource that could not be compressed if the sponsor accelerated the start date by 60 days.

      Financial Controls and Subawards — Where Money Meets Rules

      • What recurring subaward or cost-accounting exception do you expect will require the most oversight this award? Options: Indirect cost disputes, Cost share tracking, Foreign subrecipients, High-risk vendors, Effort reporting, Other
      • Tell the office titles responsible for indirect costs, cost share, and subrecipient monitoring for this award.
      • Estimate how often your subaward monitoring activities escalate findings to formal corrective action per year. Options: Never, 1-2 times, 3-5 times, More than 5 times
      • Do you have a standard subaward template that includes security and data handling requirements tied to NSPM-33? Options: Yes, institution-wide template, Yes, department-level template, No template includes security clauses, We are drafting one
      • State the one financial control gap that would prevent the award from passing an institutional financial compliance review.

      Success Criteria and Measurement That Everyone Agrees On

      • Define the measurable outcomes — for PI time saved, award setup time, and audit findings — that would make leadership call this engagement a success.
      • Provide the method you will use to quantify PI time saved — time logs, surveys, or proxy measures — and who approves that metric. Options: Time logs, Surveys of PIs, Proxy (task counts), System activity logs, Other
      • Please list the baseline data sources you already have to measure award setup time and compliance exceptions.
      • Should a pilot show a 30% reduction in PI admin time, what internal approvals would be required to scale across departments? Options: Department signoff, VP Research approval, Central budget allocation, IT security signoff, Other
      • To what degree could politics, budget timing, or competing priorities block immediate SOW execution despite pilot success? Options: Major blocker, Minor blocker, Manageable with leadership, Unlikely to block

      Next Steps, Risks, and Decision Rhythm

      • In practice, which executive can stop a pilot SOW and what is their shortest decision time?
      • Is there a procurement window or fiscal constraint that sets a hard stop for awarding contracts this quarter? Options: Yes, month/end of quarter, Yes, end of fiscal year, No immediate constraint, Unsure
      • Choose the pilot structure you would prefer: focused security controls, end-to-end administration, or hybrid. Options: Focused security controls, End-to-end administration, Hybrid: security + selected admin tasks
      • What red lines or non-negotiables must be captured in a pilot SOW to allow you to proceed?
      • After a successful pilot that meets agreed acceptance criteria, identify the remaining internal step that could still delay contracting beyond 30 days.
  2. Solution Experience

    Walk through how managed research administration and security controls will reduce PI burden and meet agency compliance in realistic scenarios.

    Solution Experience

    • Solution Experience: Research Administration and Security
    • Confirm the current state and its cost
    • You confirm the demonstrated scenario meaningfully reduces PI administrative touchpoints and eliminates the specific rework you described in Discovery.
    • Deliver a tailored control coverage matrix mapping NIST 800-171 and FISMA controls to the buyer's award and proposed operational model.
    • Scenario walkthrough — PI onboarding through secure data capture
    • You confirm the control mapping aligns with the agency acceptance criteria you outlined and identifies residual responsibilities.
    • Prepare a scoped pilot plan that includes success criteria, required integration points, and a timeline for the agreed scenario.
    • Security control mapping in the scenario
    • Provide a sample award statement of work and the list of existing grants, identity, and security tools that must integrate for the pilot.
    • You agree on the exact evidence and success criteria required before a pilot or technical review can proceed.
    • Identify two principal investigators and one research administrator to participate in the pilot scenario and share their availability.
    • Integration and operational proof
    • Validate this maps to your needs
    • Agree next evidence for a decision
    • Solution Experience: Research Administration and Security
    • Solution Experience Deck
    • Solution Brief — Research Administration and Security
    • meeting
    • slides
    • document
  3. Solution Evaluation

    Validate security posture, integration approach, and operational fit against the buyer's acceptance criteria with a scoped pilot or technical review.

    • decision_readiness
    • desired_state
    • current_state
    • success_criteria
    • gaps
    • stakeholders
    • decision_readiness
    • gaps
    • desired_state
    • current_state
    • success_criteria
    • stakeholders
    • success_criteria
    • current_state
    • stakeholders
    • decision_readiness
    • desired_state
    • gaps
    • decision_readiness
    • decision_readiness
    • decision_readiness
    • decision_readiness
  4. Solution Scope

    Define deliverables, responsibilities, NIST 800-171 / FISMA control coverage, integrations, and measurable acceptance criteria.

    Scope Configuration

    • Setup Award in Grants Management System
    • Administer Award Financials and Invoicing
    • Manage Subaward Agreements and Compliance
    • Deploy NIST 800-171 Technical Controls
    • Operate FISMA-Compliant Research IT Environment
    • Provision Authorized User Access and Roles
    • Process Contracting Actions and Modifications
    • Prepare and Submit Technical Reports
    • Maintain Regulatory and Compliance Documentation
    • Execute CUI Handling and Data Loss Prevention
    • Coordinate Export Control and Security Reviews
    • Onboard PI and Research Staff to Compliance Procedures
    • Manage Closeout and Final Deliverables
    • Run Continuous Security Monitoring and Patching

    Scope Questions

    Setup Award in Grants Management System

    • Do you have the award document (award notice or contract) and award number ready for entry into your current grants management system? Options: Yes, No
    • Which award instrument type is this for your award (grant, cooperative agreement, contract, other) and what is the CFDA or contract line item? Options: Grant, Cooperative Agreement, Contract, Other
    • List the budget periods, award start/end dates, and authorized funding amounts per budget period as stated in your award
    • Identify the PI and institutional signing authority with their institutional IDs to be associated with the award record in your grants management system
    • Provide any unique coding required (project code, chartstring, fund/org/PC) for automatic charge routing in your financial system
    • Confirm whether entry into the grants management system includes setup of invoice templates (e.g., SF-425 or agency-specific invoice) and an automated invoicing schedule in your environment Options: Yes, No, Partial - need custom template

    Administer Award Financials and Invoicing

    • Estimate monthly or quarterly invoicing frequency and expected gross invoice amounts per period tied to the budget lines in your award
    • Specify your institution's indirect cost (F&A) rate and whether your award uses a capped rate or a negotiated rate per the award terms
    • Select which financial compliance checks you require on each invoice for your award: allowability, allocability, PI salary cap checks, effort certification Options: Allowability, Allocability, PI salary cap checks, Effort certification
    • Indicate whether salary cap compliance (e.g., NIH salary cap) applies to your award and which budget lines require cap adjustments Options: Yes, No, Not applicable
    • Describe required deliverables or milestones tied to payment schedules in your award (e.g., milestone payments on report acceptance, deliverable IDs)
    • State preferred invoice format and delivery endpoint for your institution (PDF via SFTP, XML to agency portal, direct upload to your grants management system) Options: SFTP, Agency portal upload, Direct GMS entry, Other

    Manage Subaward Agreements and Compliance

    • Name each proposed subawardee and provide their DUNS/UEI and CAGE code for subrecipient checks for your project
    • Assign an owner at your institution for subaward management and indicate their email and department for routing approvals
    • Choose required subrecipient due diligence checks for your subawardees: SAM exclusion, debarment, financial statement review, cybersecurity posture attestation (NIST 800-171) Options: SAM exclusion, Debarment check, Financial statement review, NIST 800-171 attestation
    • Verify whether each subaward in your portfolio will require flow-down of NIST 800-171 controls or specific CUI handling clauses and list the clause references
    • When do you expect to issue subawards relative to the prime award (within 30 days, 60 days, other) and are templates available from your contracts office? Options: Within 30 days, Within 60 days, After 60 days, TBD
    • How many subaward modifications do you anticipate in the first year for your award (budget changes, PI changes, scope changes)? Options: 0-2, 3-5, 6+

    Deploy NIST 800-171 Technical Controls

    • How will you map required NIST SP 800-171 control families (e.g., AC, IA, SC) to your current systems and configurations that host award data?
    • Who is the institutional author of your current System Security Plan (SSP), and does it reference your award's CUI types and locations?
    • Are there existing Plan of Action and Milestones (POA&Ms) for the environment that will host your award CUI, and what is the remaining remediation effort in labor hours?
    • Is there an approved vulnerability scanning cadence and tool in your environment (e.g., Nessus, Qualys) and a report showing percentage of findings closed within 30 days for your systems? Options: Yes, No, Planned
    • Will the deployment require changes to your endpoint hardening baselines or MDM configurations for research staff laptops that will handle CUI? Options: Yes, No, Limited to specific PIs
    • Does an independent assessment or A&A requirement exist for your NIST 800-171 controls, and what evidence will validate successful implementation (updated SSP, independent assessment report, vulnerability scan pass rate <= X)? Options: Updated SSP, Independent assessment report, Vulnerability scan with <=5 critical findings, Other

    Operate FISMA-Compliant Research IT Environment

    • Where will your CUI be stored (cloud tenant, on-prem server, shared drive) and what environment designation (FISMA low/moderate/high) will you apply? Options: Cloud tenant, On-prem, Hybrid
    • Select all monitoring services you require for your environment: continuous monitoring, SIEM alerts, centralized logging retention, incident response runbook Options: Continuous monitoring, SIEM alerts, Centralized logging, Incident response runbook
    • Attach or reference your current Authorization to Operate (ATO) or provide a timeline to obtain one for the environment hosting your award CUI
    • Reference your backup and data retention policy for research data tied to your award and the retention period required per agency terms
    • Include required network segmentation details for your environment: separate VLANs for CUI, research compute, and public access endpoints with baseline firewall rules
    • Detail measurable acceptance criteria for FISMA compliance for your environment (e.g., ATO issued, SSP approved, continuous monitoring pass rate >=95%, monthly vulnerability closure <30 days)

    Provision Authorized User Access and Roles

    • Outline role types you need provisioned for your award (PI, Co-PI, Research Admin, Grants Accountant, Subaward Manager) and the minimum access each role requires in your grants management system and research IT
    • Quantify the number of users per role for your award and the expected provisioning cadence during ramp-up and steady state Options: 1-5, 6-20, 21-100, 100+
    • Measure whether SSO is available via your institutional identity provider (IdP) and which federation protocol your institution uses (SAML2, OIDC) for researcher access to the SaaS tenant Options: SAML2, OIDC, None/Local accounts
    • Prioritize MFA enforcement levels for roles that access your award CUI (required, recommended, exempt) and list any institutional exceptions Options: Required, Recommended, Exempt
    • Rank approval steps required for access in your workflow: PI approval, institutional security approval, training completion, sponsor clearance
    • Clarify the acceptance criterion for access provisioning for your award: how will you verify role mappings are approved and audit logs validate provisioning (signed access matrix, SSO provisioning logs retained for X days)? Options: Signed access matrix, SSO provisioning logs, Access review completed by PI

    Process Contracting Actions and Modifications

    • Note the institutional contracting office contact and typical lead time for executing budget or scope-modifying contract modifications for your awards
    • Confirm whether prior approvals are required from the agency contracting officer for your planned scope items (subawards, foreign collaborations, major equipment purchases) Options: Yes, No, TBD
    • Supply examples of anticipated contract actions for your award (no-cost extension, budget reallocation, PI change) and indicate estimated processing time
    • Enter any cost-share or matching obligations required by your award and whether you will track them in your grants management system
    • Mark any approval thresholds in your institution that require committee review (IRB, export control, biosafety) before contracting actions proceed
    • Declare whether your institution requires an institutional signature for final modifications on your award and provide the authority level needed (Department Chair, Sponsored Programs Director)

    Prepare and Submit Technical Reports

    • Do you have predetermined technical report formats required by the agency for your award (PDRF, SF-428, agency-specific templates) for interim and final reporting? Options: Yes, No, Some templates available
    • Which reporting cadence and milestones are in your award (quarterly progress reports, annual reports, final report) and what are their due dates?
    • List required deliverables attached to your reports: datasets, code repositories, lab notebooks, and whether they contain CUI
    • Identify the PI and point of contact for your report generation and signoff, including ORCID or institutional researcher ID
    • Provide the required submission endpoints for your reports (agency portal, email to program officer, GMS upload) and the authentication method Options: Agency portal, Email to PO, GMS upload, Other
    • Confirm whether your technical reports require review for export control or classification prior to submission and which office handles that review Options: Yes, No

    Maintain Regulatory and Compliance Documentation

    • Estimate the number of compliance documents you must maintain for your award (SSP, POA&M, incident logs, training records) and the update frequency for each
    • Specify who at your institution is responsible for maintaining the System Security Plan and POA&M for systems supporting your award
    • Select required training completion tracking for your personnel on this award (CITI, cybersecurity awareness, CUI handling) and the reporting cadence Options: CITI, Cybersecurity awareness, CUI handling, Other
    • Indicate retention period for your award regulatory records per agency or institutional policy (e.g., 3 years, 7 years, sponsor term) Options: 3 years, 7 years, Sponsor term, Other
    • Describe how you want audit-ready packages compiled for your award in case of agency review or OIG audit (document list, owner, location in GMS or controlled tenant)
    • State whether you require our team to maintain a repository of your award compliance artifacts in your GMS or in a controlled cloud tenant Options: Within your GMS, In controlled cloud tenant, Both, Other

    Execute CUI Handling and Data Loss Prevention

    • Name the CUI categories expected in your award (e.g., Controlled Technical Information, Export Controlled, Personally Identifiable Information) and attach marking guidance
    • Assign responsibility for CUI marking and handling across your research team and indicate the PI's role in enforcement for your award
    • Choose DLP controls required for your award data: endpoint DLP, network DLP, email DLP, encryption at rest and in transit Options: Endpoint DLP, Network DLP, Email DLP, Encryption
    • Verify whether full-disk encryption and host-based agents are permitted on your researcher laptops and list any exceptions for high-performance compute nodes Options: Permitted, Not permitted, Limited exceptions
    • When should secure transfer endpoints be provisioned for your award data ingest (SFTP, secure cloud link) relative to award timelines? Options: Before project start, Within 2 weeks of start, Within 30 days, TBD
    • How many datasets containing CUI will be in scope for your award and what is the typical size and expected update cadence for each dataset?
  5. Mutual Commit

    Finalize SOW, pricing, data-access authorizations, and operational responsibilities required by the award and institutional policies.

    Agreement Modules

    • Master Services Agreement (MSA)
    • Statement of Work (SOW)
    • Subscription Order Form
    • Pricing and Fee Schedule Attachment
    • Data Access and Authorization Agreement
    • Security & Compliance Addendum (NIST 800-171 / FISMA / NSPM-33)
    • Operational Responsibilities & Onboarding Agreement
    • Change Order Agreement
    • Acceptance & Go-Live Criteria
  6. Deployment

    Operationalize rollout with readiness checks, execution, and outcome validation.

    1. Pre-Deployment Readiness

      Confirm concrete readiness facts — access approvals, named owners, environments, and timelines required before execution.

      Pre-Deployment Questions

      Environment and access

      • List the named environments this deployment will touch (production, staging, test) and each environment's primary owner — name the environment in plain language so we can map access requirements.
      • Are access approvals already granted for those environments? (If not, select the current approval state so we can schedule gating tasks.) Options: All approvals in place now, Approvals pending with target approval date, Approvals require external vendor assistance to obtain, Approvals not started

      Data and configuration

      • Will any data migration, bulk import, or configuration bootstrap be required before we begin testing? (This shapes sequencing and storage planning.) Options: No migration or bulk import required, Yes — limited dataset (small scope), Yes — large dataset or multi-phase migration, Yes — phased per site or award
      • Who is the authoritative owner for source data and configuration mappings (name and role)? This person will be the approver for mapping artifacts.

      People and ownership

      • For each deployment workstream below, provide the buyer-side named owner (name and role). Workstreams: environment access, data migration/configuration, security/compliance signoff, PI/research-staff liaison, IT/integration scheduling. (We need one contact per line to assign tasks.)
      • Has the buyer identified an executive sponsor or final signoff authority for deployment milestones? Options: Yes — sponsor identified and contact provided above, Yes — sponsor will be named after this form, No executive sponsor identified yet, Not applicable

      Timing and constraints

      • What is the earliest permissible start date for deployment activities (so we can draft the timeline and resource bookings)?
      • Are there blackout windows, award-imposed dates, or institutional constraints the deployment must avoid or wait for? (Select and briefly describe any windows so we can plan around them.) Options: None known, Scheduled blackout windows — buyer will list dates, Must wait for award effective or funding date, Other constraints — buyer will describe
      • Is a formal compliance gate required before go-live (e.g., ATO, institutional security signoff, 3PAO assessment)? If yes, select the type and identify the gate owner in the DeploymentConfig step. Options: No formal compliance gate required, Yes — ATO/authorization required, Yes — 3PAO or third-party assessment required, Yes — institutional compliance signoff required
      • Do any external integrations require vendor scheduling or cross-party coordination before we can deploy (categories: grants management system, identity provider/SAML, institution data warehouse, other)? If yes, indicate who will coordinate scheduling. Options: No external coordination required, Yes — buyer IT will coordinate scheduling, Yes — requires vendor assistance to coordinate, Multiple integrations; buyer will attach schedule
    2. Configuration Details

      Lock configuration values the deployment team will use — system integrations, access credentials, data flows, and permission mappings.

      Configuration Details

      Environment & Endpoints (Deployment Configuration)

      • Enter the canonical production environment name to use in configuration (Default: prod). Example: prod
      • Enter the production base URL for the buyer's grants-management system integration (format: https://your-grants.example.edu). This exact URL will be placed in the connector settings.
      • Select the hosting region for the seller-hosted instance (Default: US (commercial)). The deployment will target this region. Options: US (commercial), US (GovCloud/FedRAMP), EU, Other
      • Enter the platform role name to map to the buyer's 'Research Admin' role in permission mappings (Default: research_admin). This exact role name will be provisioned/used by the Permissions module.

      Authentication & Identity

      • Select the buyer's identity provider type for SSO (the Authentication module uses this): Options: SAML-based IdP, OIDC-based IdP, No SSO (local accounts)
      • Enter the IdP Entity ID or OIDC Client ID (non-secret identifier). Format examples: urn:example:idp or https://idp.example.edu/client/abcd
      • Select where the SSO secret/credential will be stored/owned (we will not accept secrets in this form; choose the owner/channel for secret exchange): Options: Buyer-owned secrets manager (buyer will provide name at kickoff), Seller-held secure exchange (seller will request via secure channel), To be exchanged at deployment kickoff through a mutually agreed secure channel

      Integrations & Data Flows

      • Select all buyer systems the deployment must integrate with (choose all that apply): Options: Institutional grants management system (e.g., InfoEd, Cayuse, Workday Grants), Institutional identity directory / LDAP / IdP, Institutional HR/payroll system (for effort reporting), Subaward/subrecipient management system, Sponsor CRM or reporting system, No external integrations required at this time
      • For the buyer's grants-management system, select the integration type to configure (Default: REST API if available). If not integrating, choose 'No direct integration'. Options: REST API (recommended), SFTP batch export/import, Database read-only replica, No direct integration
      • Select the source data export format the buyer will provide for batch imports (Default: CSV): Options: CSV (column schema), JSON (structured payload), XML, Other (buyer will provide spec)
      • Will the seller-hosted environment persist Controlled Unclassified Information (CUI) or Personally Identifiable Information (PII) from the buyer's systems? Default: No. Options: Yes, No
    3. Deployment

      Execute the rollout with sequenced tasks, named owners, training for research staff, and validation checkpoints.

    4. Go-Live Approval

      Formal readiness and acceptance checklist confirming access controls, data handling, and compliance gates are satisfied before operational handoff.

      Checklist items

      • Obtain written Authorization to Operate (ATO) or formal AO approval
      • Publish finalized System Security Plan (SSP)
      • Deliver NIST 800-171 / FISMA control traceability matrix and acceptance
      • Resolve or formally accept vulnerability scan and penetration test findings
      • Approve data classification and data flow diagram for covered datasets
      • Provision and verify user accounts and role-based access mappings
      • Validate integration endpoints, API connections, and rollback plan
      • Verify encryption and key management configuration
      • Enable and validate logging, monitoring, and incident response contacts
      • Receive signed data access, data use, and data sharing agreements
      • Complete operational readiness checklist and runbooks
  7. Success

    Review outcomes against success metrics, capture lessons learned, and maintain a shared channel for issues and enhancements.

    Success Reviews

    • Go-Live Health Check (weeks 1-4)
    • First Measurement Review (weeks 4-10)
    • Acceptance Gate Review (around day 90)
    • Quarterly Success Review (ongoing)
    • Annual Outcomes and Lessons Learned Review

    Issues & Enhancements

    • Update the enhancement backlog with priorities and target delivery quarters.
    • Publish the acceptance decision record including the named signatory and the criterion-level outcomes.
    • Publish the remediation register with target dates and acceptance retest windows.
    • Confirm archival or decommissioning evidence for the incumbent system and publish the closure record.
    • Quarterly metric trends and variance analysis
    • Confirm whether the named metrics remain on track toward the Solution Scope targets or require additional remediation.
    • Close at least one long-standing blocker each quarter or record the reason for extended timelines.
    • Agree a prioritized list of operational enhancements with target delivery windows.
    • Re-confirm success criteria and owners
    • Publish a progress update on persistent compliance or integration issues with expected resolution dates.
    • Schedule targeted training or process refresh sessions to address adoption gaps identified by the metrics.
    • Annual outcome presentation vs Solution Scope targets
    • Validate whether annual outcomes meet the targets recorded in Solution Scope and summarize gaps for executive visibility.
    • Document and circulate a lessons-learned report with discrete process improvements and timelines.
    • Establish a standing shared channel and cadence to manage ongoing issues and enhancements for the next year.
    • Publish the annual outcomes summary and lessons-learned report for stakeholder review.
    • Create or confirm the persistent issues and enhancements channel and circulate access and escalation instructions.
    • Schedule the quarterly success review dates for the upcoming year and distribute the calendar.
    • Confirm the deployment is functionally complete and core integrations are operational.
    • Document the top 3 early issues with clear remediation timelines.
    • Establish a short-term stabilization plan to close critical blockers within the first 30 days.
    • Publish a go-live validation report with migration verification details within 2 business days.
    • Provide an updated list of trained users and outstanding training needs.
    • Document and publish remediation steps and target completion dates for critical blockers.
    • Present first-period data vs Solution Scope targets
    • Determine whether the three named metrics are moving toward the Solution Scope targets and document variance magnitudes.
    • Produce a root-cause summary for each out-of-target metric and a prioritized remediation plan.
    • Lock the measurement date and data sources for the acceptance gate review.
    • Publish the first-period metric dashboard with source definitions and sampling windows.
    • Document root-cause analyses for each metric shortfall and circulating the summary for comment.
    • Create the remediation task list with target completion dates aligned to the acceptance gate.
    • Restate acceptance criteria and numeric targets
    • Record a documented pass or fail for each acceptance criterion recorded in Solution Scope.
    • Confirm the incumbent system is either decommissioned or formally retained read-only with migration/archival evidence.
    • Establish a remediation plan with clear resolution timelines for any unmet criteria.
    • Persistent issues and blocker burn-down
    • Captured lessons learned and process improvements
    • Present outcome data against each acceptance criterion
    • Diagnose root causes for any gaps
    • Deployment and data migration validation
    • Enhancement requests and prioritization
    • Document pass/fail decision and record named signatory
    • Long-term compliance and risk posture
    • Agree corrective actions and timelines
    • Early adoption signals and usage patterns
    • Confirm shared channel and cadence for ongoing issues
    • Open issues and blocker triage
    • Confirm readiness timeline to the acceptance gate
    • Confirm next quarter actions and checkpoints
    • Incumbent system decommissioning confirmation
    • Agree immediate remediation actions
    • Agree remediation items and resolution timelines
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.