Scale the function, not the engineer.

There are always more deals than engineers. These are the three assets that decide whether that is a constraint or just a scheduling problem — a model for what an AE runs alone, a way to turn a technical win into a business case without inventing numbers, and reusable response text for the questions that arrive in writing.

01 · AE-to-SE model

What actually needs an engineer

An SE on a qualification call feels helpful and is the fastest route to becoming the bottleneck that caps how many deals a team can run. The model below protects the two stages where an engineer is genuinely irreplaceable — architecture review and proof of concept — and systematises everything before them.

01

Qualification

AE alone

Estate size, platforms in play, incumbent tooling, what triggered the search, and whether there is a compelling event. No engineer required, and pulling one in here burns the scarcest resource on a call that has not earned it.

Pull in an SE when: The prospect names a specific technical blocker — a compliance framework, an integration that must exist, a platform outside the obvious three.

An AE should be able to answer these unaided

  • Which platforms are managed: Windows, macOS, Linux endpoints, plus mobile and agentless network devices.
  • That the agent talks outbound over TCP 443 with no inbound port and no VPN dependency.
  • That patch, backup, remote and endpoint management sit in one console rather than four.
  • Roughly how onboarding works, and that there is no on-premise infrastructure to stand up.
02

Technical discovery

AE with async SE

AE runs the conversation using the discovery library; SE reviews the notes and flags what was missed. A thirty-minute async review protects more deals than a two-hour joint call, because the SE sees ten of these a week and the AE sees one.

Pull in an SE when: Two or more answers land in the 'this is the finding' branch — the managed-versus-exists gap, a person-dependent patch process, or an untested restore.

An AE should be able to answer these unaided

  • The estate-gap question: how many endpoints do you manage, and how many do you think exist?
  • How many agents are on a typical laptop today.
  • When they last performed an actual restore, not a job-status check.
  • Who asks them to prove something — auditors, insurance, a client, the board.
03

Demonstration

SE engaged

Demo only the two or three things the customer described as painful. A feature tour is the failure mode here, and it is what happens when the demo is built before discovery is read.

Pull in an SE when: The customer asks for a environment-specific proof, or a stakeholder appears whose criteria are not yet known.

04

Architecture review

SE-led

Blast radius, delegation model, integration seams, network posture, failure behaviour. This is where the deal is technically won or lost and it cannot be delegated — the questions are adversarial by design and a wrong answer is unrecoverable.

Pull in an SE when: Security or legal raise a requirement with a contractual consequence. Bring the written answer back rather than improvising in the room.

05

Proof of concept

SE-led

Scoped to a written success criterion with a number and a date, agreed before access is granted. Everything else is a free trial with a different name.

Pull in an SE when: Scope expands without something being traded. That is the moment to renegotiate rather than absorb it.

06

Handover

AE with async SE

The POC criterion, the gaps found, the workarounds agreed, and anything promised that has not shipped yet — handed to onboarding in writing. Time-to-value collapses when the implementation team starts from the contract instead of the evaluation.

Pull in an SE when: Onboarding discovers something the POC did not cover. That is an SE feedback loop, not an onboarding failure.

The handoff packet

What goes to onboarding in writing. Time-to-value collapses when the implementation team starts from the contract instead of the evaluation.

The success criterion, verbatim, in the customer's own words
Not your paraphrase. The exact sentence they said, because that is what they will measure against and what they will repeat internally.
The estate numbers as stated, and how confident they were
Managed count, believed-actual count, OS distribution, oldest version in production. 'About 2,000' and '2,047' are different pieces of information and the difference matters at implementation.
Every gap found, including the ones we could not close
A gap disclosed in the evaluation is a known constraint. The same gap discovered in week three of onboarding is a broken promise, even when nobody promised anything.
Who the sceptic was, and what convinced them
There is always one. Onboarding will meet them again, and knowing what moved them the first time saves rediscovering it.
Anything said in a room that is not in the contract
The single most common source of an unhappy first ninety days. Write it down even when — especially when — it was informal.
Network facts already confirmed with their team
Allowlist status, proxy behaviour, whether the backup region was agreed. Re-litigating this with a network team that already signed off is avoidable friction.

Rules for SE time

  • An SE on a qualification call is a scheduling failure, not a service level.It feels helpful and it is the fastest way to become the bottleneck that caps how many deals the team can run.
  • Async review beats a joint call for anything that is not adversarial.Thirty minutes of an SE reading notes covers more deals than two hours of an SE attending one, and the AE keeps ownership of the relationship.
  • If the same question reaches an SE three times, it belongs in the AE answer bank.The third occurrence is the signal. Answering it a fourth time individually is choosing not to scale.
  • Never demo before reading the discovery notes.A demo built without them is a feature tour, and a feature tour is how a technically strong product loses to a worse one that listened.
  • Architecture review and POC are not delegable. Everything before them mostly is.That is the whole model. Protect the two stages where an engineer is genuinely irreplaceable and systematise the rest.

02 · Business value

Every number comes from them

The site is deep for admins and architects and this section exists for the third audience. The discipline is the same as everywhere else: no invented percentages, no modelled breach costs, no claimed insurance savings. Each line below names what you count and where the figure has to come from — which is always the customer, never you.

Tools retired

Count: Annual licence cost of every product this replaces, plus the renewal dates.

Source: Their invoices. Ask for the actual line items rather than a recalled figure.

Careful: Only count what genuinely goes away. A tool that stays for one edge case is not retired, and claiming it is will be corrected in front of the room.

Manual hours removed

Count: Hours per month on reporting, reconciliation, evidence-gathering, and repeated fixes, times a loaded hourly rate.

Source: Their own estimate of who does it and how long it takes. Let them state both numbers.

Careful: Hours saved are rarely headcount saved. Present it as capacity returned, because claiming a person can be removed invites a fight you do not need.

Endpoint agent count

Count: Agents running on a typical machine before and after.

Source: Count them on ten representative endpoints during the POC.

Careful: This is an operational argument, not a financial one. Do not attach a dollar figure to it unless they hand you one.

Time from CVE to remediated

Count: Days between a critical patch being available and it being everywhere, and the percentage that never completes.

Source: Measured in their tenant during the POC. Before that number exists, there is nothing to compare against.

Careful: Their existing compliance percentage almost always excludes devices that stopped reporting. Ask what the denominator is before you accept it.

Time to produce evidence

Count: Elapsed time to answer an auditor, insurer or client asking for proof — encryption state, patch currency, restore capability.

Source: Ask how long the last one took and who did it.

Careful: Frequently the cleanest line in the whole case, because it is a real number they already resent. Do not inflate it.

Cyber insurance posture

Count: Which control questions on their renewal they currently cannot evidence.

Source: Their renewal questionnaire. They have one; ask to see the control section.

Careful: Never claim a premium reduction. You cannot know their underwriting, and an insurer will not confirm it. Frame it as evidence they can produce, not money they will save.

Framing it for an executive

Lead with the risk they already know about

An executive does not need to be taught that unpatched endpoints are dangerous. They need to know how many they have, how long they have been that way, and whether anyone can prove otherwise. Bring their number, not a statistic about the industry.

Convert operations into capacity, not headcount

Hours removed from manual reporting is capacity a stretched team gets back. Framed as headcount reduction it becomes a political problem and the technical champion who helped you becomes the person who armed the argument.

Name the cost of doing nothing without inventing it

The honest version is specific and small: this many hours a month, this many days of exposure, this many controls we cannot currently evidence. That is more persuasive than a modelled breach cost, because a modelled breach cost is instantly recognisable as vendor arithmetic.

Say what you do not know

An executive has been presented to by every vendor in the category. The one who says 'that number would have to come from your renewal questionnaire, not from me' is the one they believe on everything else.

03 · RFP and RFI response bank

14 reusable technical answers

Written generically on purpose. A response bank is only reusable if it carries no client-identifying detail, and that same property is what lets an engineer contribute to one without disclosing anything about a prior engagement.

Each answer is tagged with how far it can be trusted, and several carry a check to perform before submitting. The ones marked unpublished are the most useful in the bank: they are the questions where the correct response is to say what is not documented and offer to measure it, rather than to insert a number that an architect will design against and later discover was invented.

  • Answer the question that was asked, not the one you wish had been asked.Evaluators score against their own matrix. A better answer to a different question scores zero and reads as evasion.
  • A qualified no scores better than an unqualified yes you cannot defend.Most matrices allow a partial. An overstated yes that fails at proof-of-concept costs the whole submission, not one row.
  • Never insert a number to make an answer feel stronger.Rate limits, retention periods and regional detail all get designed against. An invented figure surfaces at implementation with your name on it.
  • Attach documentation for anything with contractual weight.Residency, sub-processors and certifications belong as attachments, not paraphrase. Being approximately right here has legal consequences for the customer.
  • Keep every reusable answer free of client-identifying detail.That is what makes a bank reusable, and it is what lets an engineer contribute one without disclosing anything about a prior engagement.

14 of 14 shown

verifiedDescribe the network requirements for the endpoint agent, including inbound firewall changes.
Response text

The agent communicates outbound over TCP 443 to the cloud control plane. No inbound firewall rule, listening service, or VPN dependency is required on the endpoint, which means remote and roaming devices are managed identically to devices on the corporate network. Port 80 is used only to answer an initial request before redirecting to 443. One disclosure: where a third-party software vendor publishes update payloads only over anonymous FTP or HTTP, the agent may fall back to those protocols after repeated HTTPS attempts fail.

Confirm before you submit this

Confirm the current allowlist for the customer's region, and include the FTP/HTTP fallback disclosure. Omitting it is the kind of thing a proxy log contradicts later.

Not an official source: NinjaOne's canonical allowlist article (ninjarmm.zendesk.com/hc/articles/211406886) requires an authenticated support account and returns HTTP 403 to anonymous requests, so it could not be cited directly. This is a partner's published mirror of that list. Treat the hostnames as a starting point and re-verify inside your own tenant before handing them to a network team.

verifiedWhat on-premise infrastructure must the customer provide and maintain?
Response text

None is required for the management plane. There are no site servers, distribution points, or database instances for the customer to deploy, patch, or capacity-plan. Where agentless network devices are in scope, discovery and polling occur from within the customer network, so a host is required for that role only.

verifiedDescribe the API authorisation model and the privileges each level grants.
Response text

The API uses OAuth 2.0. Three scopes are available. Monitoring grants read-only access to monitoring data and organisation structure. Management permits creation and modification of organisations and devices and permits script execution on endpoints. Control permits remote access. Because Management scope can execute scripts, a credential holding it should be governed as a privileged credential and separated from read-only integrations. Client Credentials is the appropriate grant for server-to-server integrations, and applications should be restricted to it so an interactive flow cannot be used.

Confirm before you submit this

Do not describe Management scope as 'write access'. It is code execution, and a security reviewer who discovers the understatement will re-read every other answer.

verifiedHow does the platform evidence disk encryption state across the estate?
Response text

Encryption state is monitored rather than assumed. BitLocker status is evaluated as a condition covering enabled, disabled, locked and unlocked states, with exclusions available for boot, recovery and removable volumes; FileVault status is evaluated equivalently on macOS with a duration threshold. Because these are conditions rather than a point-in-time report, a device whose protection is disabled after deployment is surfaced as an alertable state rather than discovered at audit.

fieldDoes the solution provide endpoint detection and response (EDR)?
Response text

No. The platform addresses endpoint security posture — whether protection is present, enabled, current, and whether more than one antivirus product is installed and competing — and it performs the remediation and patching that follows a finding. It is not a replacement for a dedicated EDR or EPP product, and it is designed to operate alongside one rather than instead of it.

Confirm before you submit this

Answer this one as a clean no. A hedge here reads as evasion and invites a harder line of questioning on everything adjacent.

unpublishedWhere is customer data stored, and can the customer select a region?
Response text

Data location is determined by the instance the tenant is provisioned into, and backup storage in particular uses region-specific endpoints. Because this carries contractual and regulatory consequence, the current instance and data-handling documentation for the customer's region should be attached to this response rather than paraphrased.

Confirm before you submit this

Do not answer this from memory. Obtain the current regional documentation and attach it. This is the one category where being approximately right has legal consequences for the customer.

Not an official source: NinjaOne's canonical allowlist article (ninjarmm.zendesk.com/hc/articles/211406886) requires an authenticated support account and returns HTTP 403 to anonymous requests, so it could not be cited directly. This is a partner's published mirror of that list. Treat the hostnames as a starting point and re-verify inside your own tenant before handing them to a network team.

unpublishedState the API rate limits and pagination behaviour.
Response text

Per-endpoint rate limits and page-size caps are not published in openly available documentation; the interactive API reference is available to authenticated tenants. Integrators consistently report per-endpoint throttling that requires request batching and caching. We recommend measuring observed throughput within the customer's own tenant during evaluation and designing the integration against that measurement, and we will provide that measurement as part of a proof of concept.

Confirm before you submit this

Never insert a specific number here to make the answer look stronger. An integration architect will design against it and discover it was invented.

verifiedCan customer-specific attributes be stored against a device and used operationally?
Response text

Yes. Typed custom fields can be written from scripts running on the endpoint or through the API, and those fields can then be evaluated as monitoring conditions. This allows a business or compliance attribute to drive alerting directly rather than being maintained separately in a spreadsheet. Field types include checkbox, numeric, decimal, text, date and time, dropdown, multi-select, URL and encrypted text, each with defined format and length constraints.

Confirm before you submit this

If the customer describes a specific attribute, check it against the type constraints before committing. Numeric is a signed 32-bit integer and text is capped at 10,000 characters through the CLI.

verifiedDescribe the administrative delegation model for a multi-region or multi-business-unit estate.
Response text

Scope is expressed through an organisation, location and device hierarchy, and policy assignment resolves from organisation to location to device with the most specific assignment taking effect. A device holds exactly one effective policy at any time; policies are not merged or layered. Variation is authored at design time by deriving a child policy from a parent and changing only what differs. The practical consequence is determinism: the configuration applied to any device is a single object that can be opened and read, rather than a computed result that has to be reasoned about.

verifiedWhich device classes can be brought under management?
Response text

Four policy types cover distinct classes. Agent policies manage Windows, macOS and Linux endpoints. NMS policies manage agentless network infrastructure using SNMP and ICMP. VM policies manage virtualisation hosts and their guests. MDM policies manage Android, iOS and iPadOS without an installed agent. These are separate mechanisms with distinct condition sets rather than a single agent applied to different hardware.

verifiedDescribe the backup and recovery capabilities, including restore granularity.
Response text

Two backup types are available: image backup for full system recovery and file/folder backup for selective protection. Destinations may be cloud, customer network storage, or hybrid. Recovery paths include file-level recovery, image restore, bare metal recovery, and recovery to virtualisation. Backup health is evaluated as monitoring conditions covering job duration and time since last successful job, so backup status is surfaced in the same alerting model as the rest of the estate rather than in a separate console. Device backup and SaaS backup are distinct products protecting distinct workloads.

Confirm before you submit this

Do not state exact retention periods or revision counts. They are not published on the open documentation index and a compliance requirement will be measured against whatever you write.

verifiedDescribe the patch approval and staged deployment controls available.
Response text

Patch approval supports automatic, manual, and reject states, allowing a staged deployment in which early groups are approved manually and observed before later groups deploy on schedule. Patch risk can be evaluated as a monitoring condition on CVSS score combined with the number of days a patch has remained pending, and separately on the age of pending patches per device. The vendor's guidance specifies a minimum interval of one hour between scan and installation; it does not prescribe group sizes or soak durations, which are an operating decision for the customer and which we would design jointly.

Confirm before you submit this

The last sentence matters. Presenting ring sizes as a vendor recommendation is a claim the customer can check and disprove.

verifiedState the minimum supported operating system versions for mobile device management.
Response text

Mobile enrolment supports Apple iOS 10.0 and later, all iPadOS versions, and Android 8.0 (Oreo) and later. Remote access to managed mobile devices requires iOS 16.0 or later and Android 8.0 or later. Declarative Device Management requires iOS or iPadOS 17.0, or macOS 14.0; devices below those versions remain enrolled and managed under standard MDM behaviour. Automated zero-touch enrolment depends on Apple Business Manager, Apple School Manager, or Android Enterprise, which are vendor programmes the customer enrols in independently of the MDM platform.

Confirm before you submit this

Three different floors appear in this answer and they are frequently conflated. Check which one the question is actually asking about before trimming.

verifiedDescribe remote access session types and any functional limitations.
Response text

Interactive sessions provide full desktop control. Background sessions run under the Windows SYSTEM account on a separate minimal desktop, allowing maintenance without interrupting the signed-in user; core administrative tooling including file browser, disk manager, registry editor, event viewer, service manager and command shells operate in this mode, while software that depends on the signed-in user's profile, profile-bound tokens, or interactive graphics may not launch. Agentless ad-hoc access is available for devices that have never been enrolled.

Confirm before you submit this

Keep the background-mode limitation in. An RFP answer that omits it produces a failed acceptance test later, which is worse than a caveat now.