Buying HR software

Twelve questions to ask a vendor

Every HR software demo is roughly the same forty minutes. The org chart animates, a leave request is approved in two clicks, a dashboard fills with a fictional company that has never had a messy termination. None of it is dishonest. It is also not where the tool will go wrong.

The questions below are the ones that expose behaviour rather than features. They share a property worth noticing: every one of them has a factual answer that the vendor already knows, because it is a fact about how the system is built rather than an opinion about how good it is. That is what makes them useful. A vendor who cannot answer in a sentence is not being careful. They are telling you the answer is bad.

Questions about leaving

What happens to my data on the day I leave, and in what format? A good answer is concrete and unprompted: one archive, a documented file per entity, the original document files and not merely their metadata, and a manifest listing what is inside so you can check the archive against itself. A bad answer is “we can provide an export on request”, which is a description of a support process, not a format. Follow up with the specific thing people forget: are the documents included, or only rows from tables.

Can I run that export myself, today, without asking you? Good: yes, it sits behind an owner or admin permission on a settings screen. Bad: a ticket, a queue, a stated number of business days, or a fee. This one is worth weighting heavily, and there is a whole argument for starting your shortlist with the export rather than the demo.

Does the export still work if my account is suspended or my invoice is unpaid? Good: yes, explicitly, because export sits outside the billing guard. Bad: any hesitation at all. A vendor who has not thought about this has left the default in place, and the default in most systems is that a suspended account cannot reach its own records.

Questions about the bill

What is the notice period on a price rise, and can it reach me mid-term? Good: a named number of days, plus a statement of what is locked. The stronger version is architectural: prices are versioned rows, a change applies to new terms, and an existing customer keeps the price captured at signup until renewal. Bad: “we would of course let you know.” Goodwill is not a notice period.

Which numbers on this quote are fixed and which float? Ask specifically what happens when you hire eight people in month two. Some vendors bill the growth at renewal, some true it up monthly, and both are defensible. What is not defensible is a vendor who cannot tell you which, because that means the answer will be discovered by you, on an invoice.

Can I buy one module without buying a tier? Good: yes, priced on its own unit; or an honest no with a reason attached. Bad: the feature you asked about turns out to live in a tier alongside twenty things you did not ask about. That pattern has a name and a cost, and it is the subject of how to read an HR pricing page. Prices themselves belong on one page and should be published; ours are on pricing.

What happens on a late invoice? Good: a stated grace period during which nothing changes, a reminder schedule with a final warning before anything is switched off, and a clear statement of what stops and what does not. Bad: “accounts may be suspended”, with no number. Then ask the follow-up that matters more than the grace period: during suspension, can I still export.

Questions about who can see what

Who can see an employee’s pay in the default configuration? Note the last three words. Almost every system can be configured well. Ask what happens if nobody configures anything, because that is the state the system will be in during the month you load the data. A good answer separates two ideas: administering a module is one permission, seeing an amount inside it is another, and the second is off until someone deliberately grants it. A bad answer is “admins see everything, but it is configurable.”

Is there an audit log, can I read it, and can anyone edit it? Three questions in one, deliberately. Many vendors have an audit trail that only their own staff can read, which makes it their compliance artefact, not yours. Good: you read it in the product, filter it, export it, and the tables reject updates and deletes at the database level. Bad: “full audit logging is available”, offered as a tier feature rather than a record you own.

Can your staff see my data, and what do I see when they do? Good: access is requested, scoped, time-boxed, approved by you, and recorded in a log you can read, with a notification you are not allowed to mute. Bad: “only for support purposes.” Everyone reads data only for support purposes. The question is what is recorded and who approved it. If you are working through a formal review, the security questionnaire guide has the longer version of this list.

Questions about after you sign

What is the real implementation timeline, and who does the work? The useful answer names the tasks that are yours rather than theirs: cleaning the employee list, deciding what historical documents come across, rebuilding leave balances, reconciling the people who left last year. Bad: “most customers are live in two weeks”, offered without asking a single question about your data. Two weeks is achievable. It is achievable because you did the work, and the real cost of switching is mostly that work.

Who does support, in which timezone, and what is the escalation path? Good: named hours, a named channel, and honesty about the gap. A small vendor saying “one timezone, twelve hours, and you will often get the person who built it” is a better answer than a large vendor saying “24/7” that resolves to a chatbot until your own morning.

What do you not do? Every vendor with a real product has a list, and the good ones say it early because a bad fit costs them more than it costs you. A vendor who claims no gaps has either not thought about it or is planning to discover the gaps with your money.

The evasion is the finding

None of these twelve questions is a trap. Each has an answer that an honest vendor gives without preparation, because it is already true of the system, written down somewhere internally, and usually enforced by code. That is the point. You are not testing whether the answers are impressive. You are testing whether they exist.

So treat the deflections as data. “That depends on your configuration” to a question about defaults, “we can discuss that in procurement” to a question about export, “nobody has asked that before” to a question about the audit log. In every case the vendor knows and has decided not to say, and what you have learned is that this will be the texture of the relationship after the invoice clears.

Where we stand

We publish our answers rather than waiting for the questionnaire. The export format, the grace period before a late invoice changes anything, what a suspended workspace can still do, and what our own staff can reach and under whose approval are all written out on the security page, with the document behind each control named next to it.

Two of our answers are limits rather than features, and we would rather you heard them here. Single sign-on does not exist yet, so no plan withholds it. And the honest answer to “can I buy one module without buying a tier” is a qualified no: modules are priced individually on their own units rather than bundled into a tier, but enabling any of them requires a paid plan first. That is a real constraint, it is on the pricing page in plain words, and if it disqualifies us for you, we would rather you found out in week one than in month nine.

Common questions

What should I ask an HR software vendor before buying?

Ask about the parts of the system a demo never shows: what the export contains and in what format, whether you can run it yourself, how a price rise reaches you, what happens on a late invoice, who can see pay in the default configuration, whether you can read the audit log, what the implementation actually requires from your team, and who answers support in which timezone. All of these are facts about how the product is built, so any vendor can answer them quickly. The speed of the answer tells you as much as its content.

What does a good answer about data export sound like?

It names a container, a format and a scope without being pushed. Something like: one archive, JSON and CSV per entity, the original document files included rather than only their metadata, a manifest listing each entity and its row count so you can check the archive against itself, run by an admin from a settings screen, and still available while an invoice is unpaid. A vendor who says only that export is supported has told you nothing, because every vendor supports export in some sense, including the ones that mean a partial spreadsheet emailed by a support agent.

Why does the default configuration matter more than what is configurable?

Because the default is what runs. Almost every HR system can be configured so that pay is visible only to the two people who should see it, and almost nobody does that configuration in the first week, when the data is being loaded and the admin permissions are handed out to whoever is helping. Ask what happens if nobody touches the permissions model at all. If the answer is that any admin sees everything, that is your real security posture for the first year, whatever the settings screen permits later.

That was the argument. The free core is where you check it.