Vendor management
Skill Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack/plugins/devtools-pack/skills/vendor-management
A curated pack of custom Claude Code skills for developers — installable as a Claude Code plugin marketplace.
npx -y skills add Mattakushi432/Claude-Code-Skills-Custom-DevTools-Pack --skill vendor-managementAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
When to activate: vendor selection, RFP process, contract negotiation, SLA monitoring, vendor risk assessment, supplier relationship management, third-party governance
SKILL.md
7.0 KB, ~1.7k tokens by cl100k_base, as published. Nobody here has run it
Vendor Management
Vendor Selection Process
Phase 1 — Requirements Definition
- Define must-have vs. nice-to-have capabilities
- Set budget range (target + ceiling)
- Identify integration requirements (APIs, SSO, data formats)
- Determine compliance requirements (SOC 2, GDPR, HIPAA, FedRAMP)
- List evaluation stakeholders and final decision maker
- Set evaluation timeline with milestones
Phase 2 — Market Research
- Internal: survey existing vendors for capability expansion
- Analyst reports: Gartner Magic Quadrant, Forrester Wave
- Peer network: references from similar companies
- G2 / Capterra / TrustRadius: user reviews
- LinkedIn: recent funding, headcount trends = vendor stability signal
Phase 3 — RFP Template
RFP: [Solution Category]
Issued by: [Company]
Due date: [YYYY-MM-DD]
Submission format: PDF or Notion doc
Section 1 — Company overview (max 1 page)
- Company history, size, funding stage
- Key customers in our industry vertical
Section 2 — Product/service capabilities
[List your must-have requirements as yes/no questions]
[List nice-to-have as feature questions]
Section 3 — Integration
- API documentation link
- Available connectors / webhooks
- SSO protocols supported (SAML, OIDC)
- Data export formats
Section 4 — Security & compliance
- SOC 2 Type II report (provide or confirm available under NDA)
- Pen test results (date of last test)
- Data residency options
- Sub-processor list
Section 5 — Pricing
- Pricing model (per seat / usage / flat)
- Pricing for our estimated volume
- Multi-year discount options
- Implementation / onboarding fees
Section 6 — Support & SLAs
- Support tiers and channels
- SLAs (uptime, response times)
- Dedicated CSM threshold
Section 7 — References
- 3 customer references in similar industry/size
Vendor Scoring Matrix
Scoring Template (customize weights per procurement)
| Criterion | Weight | Vendor A | Vendor B | Vendor C |
|---|---|---|---|---|
| Functional fit | 30% | /10 | /10 | /10 |
| Security & compliance | 20% | /10 | /10 | /10 |
| Integration ease | 15% | /10 | /10 | /10 |
| Total cost of ownership | 15% | /10 | /10 | /10 |
| Vendor stability | 10% | /10 | /10 | /10 |
| Support quality | 5% | /10 | /10 | /10 |
| Implementation timeline | 5% | /10 | /10 | /10 |
| Weighted total | 100% | — | — | — |
Scoring Rules
- Score 1–10 for each criterion before applying weight
- Score independently per evaluator, then average
- Document rationale for scores ≤ 4 or ≥ 9
- Must-have gaps score 0 regardless of other strengths
Contract Negotiation
Key Contract Clauses to Push On
| Clause | What to seek |
|---|---|
| Price lock | 0–3% annual increase cap for multi-year deals |
| SLA credits | ≥ 10% credit per month for uptime breach |
| Data portability | Right to export all data in standard format within 30 days of termination |
| Termination for convenience | 30–90 day notice without penalty |
| Liability cap | 12 months of fees paid (not uncapped) |
| IP ownership | Customer owns all data and derived outputs |
| Sub-processor notification | 30-day advance notice before adding sub-processors |
| Audit rights | Right to audit or receive third-party audit reports annually |
Negotiation Tactics
- Always negotiate from a written redline — never verbally
- Bundle concessions: "We'll accept X if you accept Y"
- Use competing offer as leverage even if not final choice
- Separate commercial from legal tracks — run in parallel
- Push for mutual NDA before sharing sensitive requirements
- Get implementation scope in the SOW, not MSA — easier to amend
SLA Monitoring
SLA Dashboard Metrics
| Metric | Calculation | Cadence |
|---|---|---|
| Uptime | Available minutes / total minutes × 100 | Monthly |
| MTTR | Sum(resolution times) / # incidents | Monthly |
| First response compliance | # within SLA / total tickets | Weekly |
| CSAT | Average satisfaction score from surveys | Quarterly |
| Renewal health score | Composite of above metrics | Quarterly |
SLA Breach Response
- Log breach immediately in vendor tracker
- Request incident report within 5 business days
- Calculate SLA credit owed per contract terms
- Apply credit to next invoice (track in accounts payable)
- Escalate to vendor exec if 2+ breaches in rolling 90 days
- Trigger contract review if 3+ breaches in rolling 6 months
Vendor Risk Assessment
Risk Tiers
| Tier | Criteria | Review cadence |
|---|---|---|
| Critical | Processes core business / holds PII / revenue-critical | Annual + on incident |
| High | Important ops dependency / limited alternatives | Annual |
| Medium | Significant tool / easy to replace | Bi-annual |
| Low | Commodity tool / minimal data | On renewal |
Risk Assessment Questionnaire
Financial stability
- Audited financials reviewed (or public company check)
- Years in business ≥ 3
- No news of funding issues or layoffs > 20% in last 12 months
Operational resilience
- Business continuity plan reviewed
- Disaster recovery RTO/RPO documented
- Multi-region / multi-AZ availability confirmed
Security posture
- SOC 2 Type II in-scope for relevant services
- Pen test within last 12 months
- CVE response SLA documented
Concentration risk
- What % of our ops does this vendor enable?
- How quickly can we switch if vendor fails?
- Do we have an exit plan documented?
Relationship Management
QBR (Quarterly Business Review) Agenda
1. Prior quarter review (15 min)
- SLA attainment vs. target
- Open tickets / escalations resolved
- Incidents and post-mortem outcomes
2. Product roadmap (15 min)
- Upcoming releases relevant to us
- Feature requests we submitted — status
3. Our roadmap (10 min)
- What we're building that will affect usage
- Volume projections for next quarter
4. Action items (10 min)
- Assign owners and due dates
- Schedule next QBR
Vendor Relationship Health Indicators
- Green: SLA ≥ 98%, CSAT ≥ 4.0, responsive to escalations, roadmap alignment
- Yellow: SLA 95–97%, CSAT 3.5–3.9, delayed responses, minor roadmap gaps
- Red: SLA < 95%, CSAT < 3.5, unresolved escalations, no roadmap transparency
Off-boarding Checklist
- Data export completed and verified
- API keys revoked
- SSO connections removed
- User accounts deprovisioned
- Contract termination notice sent (verify notice period)
- Final invoice reconciled
- Data deletion confirmation received
- Lessons learned documented