Sponsored Research
Multi-stakeholder institutional decisions where academic mission, student outcomes, and financial sustainability converge.
This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.
Inside this journey
-
Pre-Sales
Qualify and diagnose before investing in a full evaluation cycle.
-
Fit Validation
Quick qualification to confirm award type, funding constraints, decision authority, and urgency before investing in full discovery.
Qualification Questions
Award & Funding Fit - quick readiness check
- Which best describes the award that is driving this request?
- Does the award include explicit research security or NSPM-33 / NIST-related requirements we should plan for?
- If known, briefly list award identifiers or the specific security/compliance clauses or notes the seller should be aware of.
Integration and Access requirements
- Will the seller need direct access or system integration with your institution's grants, contracts, or research management systems?
- Which categories of data will the project process or store? Select all that apply.
Budget and Decision Authority
- Is there an allocated budget or funding line for external research management services, and which range best fits?
- Who will authorize engaging an external research management partner and who else will influence that decision? (roles or brief names)
Timeline and urgency
- What is the target date or trigger driving this need (award start date, audit deadline, PI bandwidth), and how flexible is that timing?
- How would you describe the priority for moving to full discovery: critical (must start immediately), important (plan within the quarter), or exploratory?
-
Outcome Discovery
Map stakeholders, current grants management state, regulatory constraints (NSPM-33 / NIST), and measurable success criteria.
Discovery Questions
Quick Tour: Your Current Award and Team
- Tell me the award type and primary funder for this project, and whether it includes controlled unclassified information under NSPM-33.
- Who are the named decision makers and which office signs off on data access and security for this award?
- How many active principal investigators and research sites are in scope for this award?
- When was the award issued and what is the operational start date the sponsor expects?
- Describe the current role your central research administration office plays versus departmental staff for daily grants management and security oversight.
- What single missing approval, resource, or authority would stop you from meeting the award's compliance deadlines?
Where the Work Actually Happens and Friction Shows Up
- If your PIs suddenly had half the administrative time they currently spend, which grant-management task would fail first and why?
- On a typical month, how many compliance reports, IRB protocols, or subaward documents does your office process?
- Which manual handoffs, spreadsheets, or local trackers are relied on today to manage budgets, approvals, or data access?
- How often do late or incorrect approvals delay invoices, subcontract starts, or data sharing in a fiscal quarter?
- Which single recurring bottleneck, if resolved, would shorten your average award setup time by at least 30%?
Who's in the Room When Things Go Wrong
- Who gets notified first when a security control gap is discovered in an active study, and what typically happens next?
- List the stakeholder roles that must approve data access, from institutional officials to PI designees.
- To what extent are principal investigators enabled to make data-sharing decisions without central office approval?
- Estimate the number of named system administrators and security contacts required to grant access and meet NIST 800-171 controls.
- What single role vacancy or governance gap would pause onboarding for all new users?
Security and Compliance That Can't Be Ambiguous
- Identify the NSPM-33 or NIST 800-171 control area you expect will be the hardest to demonstrate in an audit.
- Describe any past audit findings, OIG recommendations, or sponsor security comments related to grants data or CUI handling and their current remediation status.
- Has your institution completed a system security plan or SSP for the environment that will host award data?
- List the categories of data in this program that are treated as CUI and who currently labels and enforces that classification.
- If an external assessor demanded evidence of FISMA-equivalent controls this week, what one deliverable could you not produce within 14 days?
Alternatives on the Table
- Name the internal programs or external partners you are actively considering to manage grants security and administration.
- Tell me which option currently acts as the incumbent for your awards, and why.
- What would need to be true about your current approach for you to keep it rather than switch to an outside partner?
- Has anyone inside proposed a 'we'll build it ourselves' plan, and if so, which office owns that idea?
- Under what single condition would you abandon the incumbent or internal build and contract with an outside partner this quarter?
Data and Integration Reality Check
- Identify the integrations or APIs that are mission-critical and would break the project if unavailable.
- Rate the readiness of your primary grants system to export clean award, PI, and budget data for integration, on a 1-5 scale.
- Name the file formats, API types, or middleware your team uses for secure data transfer.
- Do you have staff or contractors who will own integration testing and accounts provisioning, and how many FTEs are available?
- Would a required three-month engineering effort to complete a critical integration be a deal stopper for this program?
Timeline and Gating — What Really Stops Launch
- Pinpoint the single milestone in your internal review or institutional approvals most likely to push go-live past the award deadline.
- Provide a list of institutional approvals still outstanding and the office responsible for each, for example grants accounting, tech transfer, IRB, or IT security.
- To what extent can sponsor budget flexibility or rephasing cover delays caused by institutional gating?
- When was the last time your institution paused an award launch due to an unresolved compliance item, and what caused the pause?
- State the one approval or resource that could not be compressed if the sponsor accelerated the start date by 60 days.
Financial Controls and Subawards — Where Money Meets Rules
- What recurring subaward or cost-accounting exception do you expect will require the most oversight this award?
- Tell the office titles responsible for indirect costs, cost share, and subrecipient monitoring for this award.
- Estimate how often your subaward monitoring activities escalate findings to formal corrective action per year.
- Do you have a standard subaward template that includes security and data handling requirements tied to NSPM-33?
- State the one financial control gap that would prevent the award from passing an institutional financial compliance review.
Success Criteria and Measurement That Everyone Agrees On
- Define the measurable outcomes — for PI time saved, award setup time, and audit findings — that would make leadership call this engagement a success.
- Provide the method you will use to quantify PI time saved — time logs, surveys, or proxy measures — and who approves that metric.
- Please list the baseline data sources you already have to measure award setup time and compliance exceptions.
- Should a pilot show a 30% reduction in PI admin time, what internal approvals would be required to scale across departments?
- To what degree could politics, budget timing, or competing priorities block immediate SOW execution despite pilot success?
Next Steps, Risks, and Decision Rhythm
- In practice, which executive can stop a pilot SOW and what is their shortest decision time?
- Is there a procurement window or fiscal constraint that sets a hard stop for awarding contracts this quarter?
- Choose the pilot structure you would prefer: focused security controls, end-to-end administration, or hybrid.
- What red lines or non-negotiables must be captured in a pilot SOW to allow you to proceed?
- After a successful pilot that meets agreed acceptance criteria, identify the remaining internal step that could still delay contracting beyond 30 days.
-
-
Solution Experience
Walk through how managed research administration and security controls will reduce PI burden and meet agency compliance in realistic scenarios.
Solution Experience
- Solution Experience: Research Administration and Security
- Confirm the current state and its cost
- You confirm the demonstrated scenario meaningfully reduces PI administrative touchpoints and eliminates the specific rework you described in Discovery.
- Deliver a tailored control coverage matrix mapping NIST 800-171 and FISMA controls to the buyer's award and proposed operational model.
- Scenario walkthrough — PI onboarding through secure data capture
- You confirm the control mapping aligns with the agency acceptance criteria you outlined and identifies residual responsibilities.
- Prepare a scoped pilot plan that includes success criteria, required integration points, and a timeline for the agreed scenario.
- Security control mapping in the scenario
- Provide a sample award statement of work and the list of existing grants, identity, and security tools that must integrate for the pilot.
- You agree on the exact evidence and success criteria required before a pilot or technical review can proceed.
- Identify two principal investigators and one research administrator to participate in the pilot scenario and share their availability.
- Integration and operational proof
- Validate this maps to your needs
- Agree next evidence for a decision
- Solution Experience: Research Administration and Security
- Solution Experience Deck
- Solution Brief — Research Administration and Security
- meeting
- slides
- document
-
Solution Evaluation
Validate security posture, integration approach, and operational fit against the buyer's acceptance criteria with a scoped pilot or technical review.
- decision_readiness
- desired_state
- current_state
- success_criteria
- gaps
- stakeholders
- decision_readiness
- gaps
- desired_state
- current_state
- success_criteria
- stakeholders
- success_criteria
- current_state
- stakeholders
- decision_readiness
- desired_state
- gaps
- decision_readiness
- decision_readiness
- decision_readiness
- decision_readiness
-
Solution Scope
Define deliverables, responsibilities, NIST 800-171 / FISMA control coverage, integrations, and measurable acceptance criteria.
Scope Configuration
- Setup Award in Grants Management System
- Administer Award Financials and Invoicing
- Manage Subaward Agreements and Compliance
- Deploy NIST 800-171 Technical Controls
- Operate FISMA-Compliant Research IT Environment
- Provision Authorized User Access and Roles
- Process Contracting Actions and Modifications
- Prepare and Submit Technical Reports
- Maintain Regulatory and Compliance Documentation
- Execute CUI Handling and Data Loss Prevention
- Coordinate Export Control and Security Reviews
- Onboard PI and Research Staff to Compliance Procedures
- Manage Closeout and Final Deliverables
- Run Continuous Security Monitoring and Patching
Scope Questions
Setup Award in Grants Management System
- Do you have the award document (award notice or contract) and award number ready for entry into your current grants management system?
- Which award instrument type is this for your award (grant, cooperative agreement, contract, other) and what is the CFDA or contract line item?
- List the budget periods, award start/end dates, and authorized funding amounts per budget period as stated in your award
- Identify the PI and institutional signing authority with their institutional IDs to be associated with the award record in your grants management system
- Provide any unique coding required (project code, chartstring, fund/org/PC) for automatic charge routing in your financial system
- Confirm whether entry into the grants management system includes setup of invoice templates (e.g., SF-425 or agency-specific invoice) and an automated invoicing schedule in your environment
Administer Award Financials and Invoicing
- Estimate monthly or quarterly invoicing frequency and expected gross invoice amounts per period tied to the budget lines in your award
- Specify your institution's indirect cost (F&A) rate and whether your award uses a capped rate or a negotiated rate per the award terms
- Select which financial compliance checks you require on each invoice for your award: allowability, allocability, PI salary cap checks, effort certification
- Indicate whether salary cap compliance (e.g., NIH salary cap) applies to your award and which budget lines require cap adjustments
- Describe required deliverables or milestones tied to payment schedules in your award (e.g., milestone payments on report acceptance, deliverable IDs)
- State preferred invoice format and delivery endpoint for your institution (PDF via SFTP, XML to agency portal, direct upload to your grants management system)
Manage Subaward Agreements and Compliance
- Name each proposed subawardee and provide their DUNS/UEI and CAGE code for subrecipient checks for your project
- Assign an owner at your institution for subaward management and indicate their email and department for routing approvals
- Choose required subrecipient due diligence checks for your subawardees: SAM exclusion, debarment, financial statement review, cybersecurity posture attestation (NIST 800-171)
- Verify whether each subaward in your portfolio will require flow-down of NIST 800-171 controls or specific CUI handling clauses and list the clause references
- When do you expect to issue subawards relative to the prime award (within 30 days, 60 days, other) and are templates available from your contracts office?
- How many subaward modifications do you anticipate in the first year for your award (budget changes, PI changes, scope changes)?
Deploy NIST 800-171 Technical Controls
- How will you map required NIST SP 800-171 control families (e.g., AC, IA, SC) to your current systems and configurations that host award data?
- Who is the institutional author of your current System Security Plan (SSP), and does it reference your award's CUI types and locations?
- Are there existing Plan of Action and Milestones (POA&Ms) for the environment that will host your award CUI, and what is the remaining remediation effort in labor hours?
- Is there an approved vulnerability scanning cadence and tool in your environment (e.g., Nessus, Qualys) and a report showing percentage of findings closed within 30 days for your systems?
- Will the deployment require changes to your endpoint hardening baselines or MDM configurations for research staff laptops that will handle CUI?
- Does an independent assessment or A&A requirement exist for your NIST 800-171 controls, and what evidence will validate successful implementation (updated SSP, independent assessment report, vulnerability scan pass rate <= X)?
Operate FISMA-Compliant Research IT Environment
- Where will your CUI be stored (cloud tenant, on-prem server, shared drive) and what environment designation (FISMA low/moderate/high) will you apply?
- Select all monitoring services you require for your environment: continuous monitoring, SIEM alerts, centralized logging retention, incident response runbook
- Attach or reference your current Authorization to Operate (ATO) or provide a timeline to obtain one for the environment hosting your award CUI
- Reference your backup and data retention policy for research data tied to your award and the retention period required per agency terms
- Include required network segmentation details for your environment: separate VLANs for CUI, research compute, and public access endpoints with baseline firewall rules
- Detail measurable acceptance criteria for FISMA compliance for your environment (e.g., ATO issued, SSP approved, continuous monitoring pass rate >=95%, monthly vulnerability closure <30 days)
Provision Authorized User Access and Roles
- Outline role types you need provisioned for your award (PI, Co-PI, Research Admin, Grants Accountant, Subaward Manager) and the minimum access each role requires in your grants management system and research IT
- Quantify the number of users per role for your award and the expected provisioning cadence during ramp-up and steady state
- Measure whether SSO is available via your institutional identity provider (IdP) and which federation protocol your institution uses (SAML2, OIDC) for researcher access to the SaaS tenant
- Prioritize MFA enforcement levels for roles that access your award CUI (required, recommended, exempt) and list any institutional exceptions
- Rank approval steps required for access in your workflow: PI approval, institutional security approval, training completion, sponsor clearance
- Clarify the acceptance criterion for access provisioning for your award: how will you verify role mappings are approved and audit logs validate provisioning (signed access matrix, SSO provisioning logs retained for X days)?
Process Contracting Actions and Modifications
- Note the institutional contracting office contact and typical lead time for executing budget or scope-modifying contract modifications for your awards
- Confirm whether prior approvals are required from the agency contracting officer for your planned scope items (subawards, foreign collaborations, major equipment purchases)
- Supply examples of anticipated contract actions for your award (no-cost extension, budget reallocation, PI change) and indicate estimated processing time
- Enter any cost-share or matching obligations required by your award and whether you will track them in your grants management system
- Mark any approval thresholds in your institution that require committee review (IRB, export control, biosafety) before contracting actions proceed
- Declare whether your institution requires an institutional signature for final modifications on your award and provide the authority level needed (Department Chair, Sponsored Programs Director)
Prepare and Submit Technical Reports
- Do you have predetermined technical report formats required by the agency for your award (PDRF, SF-428, agency-specific templates) for interim and final reporting?
- Which reporting cadence and milestones are in your award (quarterly progress reports, annual reports, final report) and what are their due dates?
- List required deliverables attached to your reports: datasets, code repositories, lab notebooks, and whether they contain CUI
- Identify the PI and point of contact for your report generation and signoff, including ORCID or institutional researcher ID
- Provide the required submission endpoints for your reports (agency portal, email to program officer, GMS upload) and the authentication method
- Confirm whether your technical reports require review for export control or classification prior to submission and which office handles that review
Maintain Regulatory and Compliance Documentation
- Estimate the number of compliance documents you must maintain for your award (SSP, POA&M, incident logs, training records) and the update frequency for each
- Specify who at your institution is responsible for maintaining the System Security Plan and POA&M for systems supporting your award
- Select required training completion tracking for your personnel on this award (CITI, cybersecurity awareness, CUI handling) and the reporting cadence
- Indicate retention period for your award regulatory records per agency or institutional policy (e.g., 3 years, 7 years, sponsor term)
- Describe how you want audit-ready packages compiled for your award in case of agency review or OIG audit (document list, owner, location in GMS or controlled tenant)
- State whether you require our team to maintain a repository of your award compliance artifacts in your GMS or in a controlled cloud tenant
Execute CUI Handling and Data Loss Prevention
- Name the CUI categories expected in your award (e.g., Controlled Technical Information, Export Controlled, Personally Identifiable Information) and attach marking guidance
- Assign responsibility for CUI marking and handling across your research team and indicate the PI's role in enforcement for your award
- Choose DLP controls required for your award data: endpoint DLP, network DLP, email DLP, encryption at rest and in transit
- Verify whether full-disk encryption and host-based agents are permitted on your researcher laptops and list any exceptions for high-performance compute nodes
- When should secure transfer endpoints be provisioned for your award data ingest (SFTP, secure cloud link) relative to award timelines?
- How many datasets containing CUI will be in scope for your award and what is the typical size and expected update cadence for each dataset?
-
Mutual Commit
Finalize SOW, pricing, data-access authorizations, and operational responsibilities required by the award and institutional policies.
Agreement Modules
- Master Services Agreement (MSA)
- Statement of Work (SOW)
- Subscription Order Form
- Pricing and Fee Schedule Attachment
- Data Access and Authorization Agreement
- Security & Compliance Addendum (NIST 800-171 / FISMA / NSPM-33)
- Operational Responsibilities & Onboarding Agreement
- Change Order Agreement
- Acceptance & Go-Live Criteria
-
Deployment
Operationalize rollout with readiness checks, execution, and outcome validation.
-
Pre-Deployment Readiness
Confirm concrete readiness facts — access approvals, named owners, environments, and timelines required before execution.
Pre-Deployment Questions
Environment and access
- List the named environments this deployment will touch (production, staging, test) and each environment's primary owner — name the environment in plain language so we can map access requirements.
- Are access approvals already granted for those environments? (If not, select the current approval state so we can schedule gating tasks.)
Data and configuration
- Will any data migration, bulk import, or configuration bootstrap be required before we begin testing? (This shapes sequencing and storage planning.)
- Who is the authoritative owner for source data and configuration mappings (name and role)? This person will be the approver for mapping artifacts.
People and ownership
- For each deployment workstream below, provide the buyer-side named owner (name and role). Workstreams: environment access, data migration/configuration, security/compliance signoff, PI/research-staff liaison, IT/integration scheduling. (We need one contact per line to assign tasks.)
- Has the buyer identified an executive sponsor or final signoff authority for deployment milestones?
Timing and constraints
- What is the earliest permissible start date for deployment activities (so we can draft the timeline and resource bookings)?
- Are there blackout windows, award-imposed dates, or institutional constraints the deployment must avoid or wait for? (Select and briefly describe any windows so we can plan around them.)
- Is a formal compliance gate required before go-live (e.g., ATO, institutional security signoff, 3PAO assessment)? If yes, select the type and identify the gate owner in the DeploymentConfig step.
- Do any external integrations require vendor scheduling or cross-party coordination before we can deploy (categories: grants management system, identity provider/SAML, institution data warehouse, other)? If yes, indicate who will coordinate scheduling.
-
Configuration Details
Lock configuration values the deployment team will use — system integrations, access credentials, data flows, and permission mappings.
Configuration Details
Environment & Endpoints (Deployment Configuration)
- Enter the canonical production environment name to use in configuration (Default: prod). Example: prod
- Enter the production base URL for the buyer's grants-management system integration (format: https://your-grants.example.edu). This exact URL will be placed in the connector settings.
- Select the hosting region for the seller-hosted instance (Default: US (commercial)). The deployment will target this region.
- Enter the platform role name to map to the buyer's 'Research Admin' role in permission mappings (Default: research_admin). This exact role name will be provisioned/used by the Permissions module.
Authentication & Identity
- Select the buyer's identity provider type for SSO (the Authentication module uses this):
- Enter the IdP Entity ID or OIDC Client ID (non-secret identifier). Format examples: urn:example:idp or https://idp.example.edu/client/abcd
- Select where the SSO secret/credential will be stored/owned (we will not accept secrets in this form; choose the owner/channel for secret exchange):
Integrations & Data Flows
- Select all buyer systems the deployment must integrate with (choose all that apply):
- For the buyer's grants-management system, select the integration type to configure (Default: REST API if available). If not integrating, choose 'No direct integration'.
- Select the source data export format the buyer will provide for batch imports (Default: CSV):
- Will the seller-hosted environment persist Controlled Unclassified Information (CUI) or Personally Identifiable Information (PII) from the buyer's systems? Default: No.
-
Deployment
Execute the rollout with sequenced tasks, named owners, training for research staff, and validation checkpoints.
-
Go-Live Approval
Formal readiness and acceptance checklist confirming access controls, data handling, and compliance gates are satisfied before operational handoff.
Checklist items
- Obtain written Authorization to Operate (ATO) or formal AO approval
- Publish finalized System Security Plan (SSP)
- Deliver NIST 800-171 / FISMA control traceability matrix and acceptance
- Resolve or formally accept vulnerability scan and penetration test findings
- Approve data classification and data flow diagram for covered datasets
- Provision and verify user accounts and role-based access mappings
- Validate integration endpoints, API connections, and rollback plan
- Verify encryption and key management configuration
- Enable and validate logging, monitoring, and incident response contacts
- Receive signed data access, data use, and data sharing agreements
- Complete operational readiness checklist and runbooks
-
-
Success
Review outcomes against success metrics, capture lessons learned, and maintain a shared channel for issues and enhancements.
Success Reviews
- Go-Live Health Check (weeks 1-4)
- First Measurement Review (weeks 4-10)
- Acceptance Gate Review (around day 90)
- Quarterly Success Review (ongoing)
- Annual Outcomes and Lessons Learned Review
Issues & Enhancements
- Update the enhancement backlog with priorities and target delivery quarters.
- Publish the acceptance decision record including the named signatory and the criterion-level outcomes.
- Publish the remediation register with target dates and acceptance retest windows.
- Confirm archival or decommissioning evidence for the incumbent system and publish the closure record.
- Quarterly metric trends and variance analysis
- Confirm whether the named metrics remain on track toward the Solution Scope targets or require additional remediation.
- Close at least one long-standing blocker each quarter or record the reason for extended timelines.
- Agree a prioritized list of operational enhancements with target delivery windows.
- Re-confirm success criteria and owners
- Publish a progress update on persistent compliance or integration issues with expected resolution dates.
- Schedule targeted training or process refresh sessions to address adoption gaps identified by the metrics.
- Annual outcome presentation vs Solution Scope targets
- Validate whether annual outcomes meet the targets recorded in Solution Scope and summarize gaps for executive visibility.
- Document and circulate a lessons-learned report with discrete process improvements and timelines.
- Establish a standing shared channel and cadence to manage ongoing issues and enhancements for the next year.
- Publish the annual outcomes summary and lessons-learned report for stakeholder review.
- Create or confirm the persistent issues and enhancements channel and circulate access and escalation instructions.
- Schedule the quarterly success review dates for the upcoming year and distribute the calendar.
- Confirm the deployment is functionally complete and core integrations are operational.
- Document the top 3 early issues with clear remediation timelines.
- Establish a short-term stabilization plan to close critical blockers within the first 30 days.
- Publish a go-live validation report with migration verification details within 2 business days.
- Provide an updated list of trained users and outstanding training needs.
- Document and publish remediation steps and target completion dates for critical blockers.
- Present first-period data vs Solution Scope targets
- Determine whether the three named metrics are moving toward the Solution Scope targets and document variance magnitudes.
- Produce a root-cause summary for each out-of-target metric and a prioritized remediation plan.
- Lock the measurement date and data sources for the acceptance gate review.
- Publish the first-period metric dashboard with source definitions and sampling windows.
- Document root-cause analyses for each metric shortfall and circulating the summary for comment.
- Create the remediation task list with target completion dates aligned to the acceptance gate.
- Restate acceptance criteria and numeric targets
- Record a documented pass or fail for each acceptance criterion recorded in Solution Scope.
- Confirm the incumbent system is either decommissioned or formally retained read-only with migration/archival evidence.
- Establish a remediation plan with clear resolution timelines for any unmet criteria.
- Persistent issues and blocker burn-down
- Captured lessons learned and process improvements
- Present outcome data against each acceptance criterion
- Diagnose root causes for any gaps
- Deployment and data migration validation
- Enhancement requests and prioritization
- Document pass/fail decision and record named signatory
- Long-term compliance and risk posture
- Agree corrective actions and timelines
- Early adoption signals and usage patterns
- Confirm shared channel and cadence for ongoing issues
- Open issues and blocker triage
- Confirm readiness timeline to the acceptance gate
- Confirm next quarter actions and checkpoints
- Incumbent system decommissioning confirmation
- Agree immediate remediation actions
- Agree remediation items and resolution timelines