Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
If you think enterprise sales take 3 months, but they actually take 12 months:
→ Revenue projections are off by 9 months
→ Cash flow problems
→ Missed targets
2. Anticipate Requirements
Prepare in Advance:
Before first enterprise customer:
- Get SOC2 certification
- Implement SSO (SAML)
- Prepare standard contracts (MSA, DPA)
- Build security documentation
- Set up support processes
Cost of Not Preparing:
Customer asks: "Do you have SOC2?"
You: "No, but we can get it"
→ 6-12 month delay
→ Customer may choose competitor
3. Prepare Documentation and Support
Required Documentation:
Security questionnaire responses
SOC2 report
Privacy policy
Data Processing Agreement (DPA)
Onboarding guide
Admin training materials
4. Avoid Surprises That Delay Deals
Common Surprises:
Week 10: "We need SOC2" (don't have it, 6 month delay)
Week 15: "We need SCIM" (not implemented, 3 month delay)
Week 20: "We can't accept your liability terms" (contract negotiation, 2 month delay)
Better:
Week 1: Qualify customer (do they need SOC2, SCIM, custom contracts?)
Week 2: Provide SOC2, demonstrate SCIM, share contract template
→ No surprises, faster close
Key Sections:
1. Services (what you provide)
2. Fees (pricing, payment terms)
3. Term and Termination (duration, how to cancel)
4. Warranties (what you guarantee)
5. Liability (caps, limitations)
6. Indemnification (who protects whom)
7. Data Privacy (how you handle data)
8. Security (your security obligations)
9. Confidentiality (NDA)
10. Governing Law (which state/country)
Why Template:
Faster negotiations (start from template, not scratch)
Consistent terms (all customers get similar terms)
Legal review (template pre-approved by your lawyers)
Where to Get:
Hire lawyer to draft ($5k-20k)
Use template from Ironclad, Juro, or similar
Copy from competitor (risky, not recommended)
2. Security Documentation (Trust Center)
Public Trust Center:
URL: https://trust.yourcompany.com
Contents:
- Security overview
- Compliance certifications (SOC2, ISO)
- Privacy policy
- Data Processing Agreement (DPA)
- Subprocessor list
- Security whitepaper
- Contact info (security@yourcompany.com)
Benefits:
Customers can self-serve
Reduces security questions
Builds trust
SEO (ranks for "yourcompany security")
Tools:
SafeBase ($5k-20k/year)
Whistic ($10k-50k/year)
Custom website (free, but manual)
3. Compliance Certifications (SOC2, ISO 27001)
SOC2 Type II:
What: Audit of security controls
Cost: $15k-50k (first year), $10k-30k (renewal)
Timeline: 6-12 months
Frequency: Annual
Required by: Most enterprise customers
ISO 27001:
What: International security standard
Cost: $20k-100k
Timeline: 6-12 months
Frequency: 3-year cert, annual surveillance
Required by: Some enterprise customers (especially international)
When to Get:
SOC2: Before first enterprise customer (or ASAP)
ISO 27001: Optional (nice-to-have)
4. Onboarding Documentation (Step-by-Step Guides)
Admin Guide:
1. Configure SSO
- Step 1: Get IdP metadata
- Step 2: Enter in our app
- Step 3: Test with test user
- Step 4: Enable for all users
2. Set up SCIM
- Step 1: Generate SCIM token
- Step 2: Configure in IdP
- Step 3: Test user provisioning
- Step 4: Enable auto-provisioning
3. Invite users
- Step 1: Upload CSV or use SCIM
- Step 2: Assign roles
- Step 3: Send invitations
4. Configure settings
- Step 1: Set company name
- Step 2: Upload logo
- Step 3: Configure permissions
End User Guide:
1. Log in
- Step 1: Go to yourapp.com
- Step 2: Click "Login with SSO"
- Step 3: Enter company email
- Step 4: Redirected to your IdP
2. Create first project
- Step 1: Click "New Project"
- Step 2: Enter project name
- Step 3: Invite team members
3. Upload data
- Step 1: Click "Upload"
- Step 2: Select file
- Step 3: Map columns
- Step 4: Confirm import
Implementation Engineer: After 5-10 enterprise customers
CSM: After 10-20 enterprise customers
Support Engineer: After 50-100 customers (any size)
Common Blockers
1. Missing SOC2 Report
Problem:
Customer: "Do you have SOC2?"
You: "No"
Customer: "We can't proceed without it"
→ Deal blocked
Solution: Get SOC2 Type II
Timeline: 6-12 months
Cost: $15k-50k
Workaround (if don't have yet):
"We're currently undergoing our SOC2 Type II audit, expected completion in [DATE]. In the meantime, we can provide:
- Our security policies and procedures
- Penetration test results
- Security questionnaire responses
- References from similar customers
Would you like to proceed with these, or wait for SOC2 completion?"
2. No SSO Support
Problem:
Customer: "We require SSO"
You: "We don't support SSO"
Customer: "This is a blocker"
→ Deal dies
Solution: Implement SSO (SAML and OIDC)
Timeline: 2-4 weeks (with library like passport-saml)
Cost: Engineering time
Workaround: None (SSO is must-have for enterprise)
3. Unacceptable Contract Terms
Problem:
Customer: "We need unlimited liability"
You: "Our liability is capped at $10k"
Customer: "Unacceptable"
→ Negotiation stalls
Start Early: Begin preparing for enterprise onboarding before your first enterprise customer. Getting SOC2, ISO 27001, and other certifications takes 6-12 months.
Build Standard Contracts: Create and maintain standard contract templates (MSA, DPA, SLA, BAA). This reduces negotiation time from weeks to days.
Create Trust Center: Build a public trust center with security documentation, compliance certifications, and subprocessor list. This reduces security review time by 50%.
Develop Onboarding Documentation: Create step-by-step guides for SSO, SCIM, and other technical setup. This reduces technical onboarding time.
Hire Customer Success Team: Build a team dedicated to onboarding and customer success. This improves onboarding experience and reduces time to value.
Sales Qualification Best Practices
Qualify Early: Identify customer requirements (SOC2, SSO, custom contracts) early in sales process. This prevents surprises later.
Understand Customer Size: Tailor onboarding approach based on customer size (SMB, mid-market, enterprise).
Know Decision Makers: Identify who makes security, legal, and procurement decisions. This helps navigate the process.
Set Realistic Expectations: Communicate realistic timelines for each stage. Enterprise onboarding takes 3-12 months, not 3-12 weeks.
Document Requirements: Capture all customer requirements early and share with relevant teams.
Security Review Best Practices
Standard Response Library: Maintain comprehensive library of standard responses to common security questions. This reduces completion time from 20-40 hours to 5-10 hours.
Pre-Approved Documentation: Have SOC2 reports, penetration test results, and security policies ready to share under NDA.
Security Team Involvement: Involve security team early in the process. They own security review and should build relationships with customer security teams.
Honesty with Mitigation: Be honest about past incidents but emphasize your response and remediation. Honesty builds trust.
Evidence-Ready Responses: Reference supporting evidence for each claim. For example, "See our SOC2 Type II report for audit findings."
Legal Review Best Practices
Standard Templates: Start with your standard MSA, DPA, and SLA templates. This provides a baseline for negotiation.
Know Your Limits: Identify deal-breakers and non-negotiable terms before starting negotiations.
Liability Caps: Set reasonable liability caps based on contract value (e.g., 1x ACV, $1M, $5M). Never accept unlimited liability.
Quick Turnaround: Respond to legal comments within 48 hours. This keeps momentum and prevents delays.
Legal Team Involvement: Involve legal team early. They should build relationships with customer legal teams.
Procurement Best Practices
Vendor Registration: Complete vendor registration proactively in customer portals when possible.
Required Documents Ready: Have W-9 forms, certificates of insurance, and banking details ready.
Flexible Payment Terms: Offer standard payment terms but be flexible for large enterprises (e.g., Net 30, Net 60).
Invoice Format: Provide invoices in customer's preferred format (PDF, specific fields, purchase order references).
Finance Team Involvement: Involve finance team early. They should build relationships with customer procurement teams.
Technical Onboarding Best Practices
SSO First: Configure SSO before any other technical setup. This is often the first technical requirement.
Test Accounts: Create test accounts in customer's IdP for testing before go-live.
Step-by-Step Guides: Provide detailed, screenshot-based guides for each technical setup step.
Video Walkthroughs: Create video walkthroughs of technical setup processes. This reduces support burden.
Implementation Engineer: Assign a dedicated implementation engineer for enterprise customers. This provides single point of contact.
Training and Rollout Best Practices
Admin Training First: Train customer admins before end users. Admins will train their own teams.
Train-the-Trainer: Create train-the-trainer materials. This scales training for large organizations.
Pilot Rollout: Start with a small pilot group (10-50 users) before full rollout. This identifies issues early.
Quick Wins: Focus on quick wins in initial training. Show users how to complete their first task quickly.
Ongoing Support: Provide ongoing support during rollout period. This ensures smooth adoption.
Communication Best Practices
Single Point of Contact: Designate a single point of contact for the customer. This reduces confusion.
Regular Updates: Provide weekly status updates during onboarding. This keeps customer informed and builds trust.
Clear Milestones: Define clear milestones with dates. Celebrate each milestone completion.
Proactive Communication: Anticipate and address issues before customer raises them. This shows proactive approach.
Stakeholder Updates: Keep all stakeholders (customer and internal) aligned on progress.
Acceleration Best Practices
Self-Service for SMB: Provide self-service onboarding for small customers. This scales infinitely.
Pre-Filled Responses: Share your standard response library with customers. Ask them to copy relevant answers.
Standard Contracts: Use take-it-or-leave-it contracts for SMB and mid-market customers.
Automation Tools: Use tools like DocuSign for contract signing and SafeBase for security documentation.
White-Glove for Enterprise: Provide dedicated CSM for enterprise customers. This improves experience and adoption.
Post-Onboarding Best Practices
Week 1 Check-In: Schedule daily check-ins during first week. This is critical period for adoption.
Time to Value Tracking: Measure and optimize time to value (first meaningful action). Target <30 days.
Adoption Monitoring: Track user adoption metrics (active users, feature usage). Identify and address low adoption.
Quarterly Business Reviews: Schedule QBRs to review progress, gather feedback, and identify expansion opportunities.
Success Metrics: Define and track success metrics (time to value, adoption rate, customer satisfaction, renewal rate).