Most evaluation processes are organised around the entrance. A demo, a feature matrix, a reference call, a trial where you load ten fake employees and click through the onboarding flow. All of it measures what the tool is like on the best day of the relationship, which is the day before you have committed to anything.
Here is a better first filter, and it takes an afternoon rather than six weeks. Ask each vendor on the list for a complete export, from a real account, and look at what arrives. Judge the exit, not the entrance.
Why the exit is the honest signal
Every feature in an HR system is built because it helps the vendor keep you. Better reporting, deeper workflow, another module. There is exactly one feature that works the other way, and that is the export. A clean, complete, self-serve export makes leaving cheap, and leaving cheaply is the only thing that puts a ceiling on what a vendor can charge you at renewal.
So a vendor who has built a good export has made a commercial decision against their own short term interest. They have accepted that they must win the renewal on the product every year rather than on the difficulty of getting out. That decision is expensive to fake, which is exactly what makes it a signal.
It also correlates with everything else you actually care about. In practice, the companies with a real export tend to be the same ones that publish prices, let you read your own audit log, and answer a security questionnaire without a procurement call. The ones without tend to be the same ones that discover a professional services fee when you ask for your data. You are not really testing the export. You are testing whether the business model requires you to be stuck.
What a good export looks like
Five properties, and they are all checkable rather than promised.
Complete. Every entity, not the directory. People, employment records, the history behind the current values, leave types and balances and the ledger behind them, attendance, generated letters, custom fields and their definitions, and the audit trail. A directory dump is the easiest thing in the world to produce and it is worth the least, because the directory is the part you could rebuild from memory.
Open formats. A documented container that a standard tool opens, with a text based file per entity. JSON as the authoritative record and CSV as the convenience view is a good shape, because the JSON keeps nested structure that a spreadsheet flattens away. A proprietary backup format that only the vendor can restore is not an export, it is a hostage arrangement with extra steps.
Self-serve. An admin clicks it and gets a file. No ticket, no queue, no quote. The gap between “we support export” and “you can run an export” is the gap the entire industry hides in.
Documents, not only rows. This is the property most often missing, and the most expensive when it is. Contracts, signed policies, ID scans, letters. If the archive contains a table of document metadata and a set of links back into the platform you are leaving, you do not have your documents. You have a list of things you used to have.
It works when the relationship is bad. The export must run while an invoice is unpaid and while the account is suspended, because those are precisely the moments you need it. An export that is a function of your subscription status is a lever, and the vendor knows what it is for.
One more property, easy to overlook: a manifest. A file listing each entity and how many rows it contains lets you check the archive against itself rather than trusting it. Without one you cannot tell a complete export from a partial one until the day you need the missing part.
What a bad one looks like
Bad exports fail in recognisable ways, and none of them are presented as refusals.
The support ticket. Export exists, but as a request that a human fulfils, with a stated turnaround that grows when you have given notice.
The partial schema. A CSV of the fields shown on the employee list screen, which is perhaps a third of what the system holds. Everything effective dated is flattened to its current value, so the salary history is gone and the job title is whatever it is today.
The dangling reference. Documents appear as identifiers or as URLs that require a logged in session on the platform you are cancelling.
The fee. Sometimes called data migration assistance. A charge for handing back the records you entered is not a service, and it tells you what the relationship was.
And the quiet one: an export that works while you are paying and stops when you are not. Nobody advertises this. You find out during the week you have the least leverage.
The common thread through the middle of that list is time. An export that hands back only the current state is telling you what the system holds, and a system that cannot say what a record looked like on a date almost certainly never wrote it down. Read the export for history before you read it for anything else, because it is the one property nobody can add afterwards.
How to test it during a trial
Do not ask sales. The sales answer to “can I export my data” is always yes, and it is not dishonest, because somewhere in the product there is a button labelled export. Test the file.
In the first hour of a trial, create data with the right shape rather than the right volume. Three people. One document uploaded against each, ideally a PDF you can recognise. One job title or salary change applied to one of them, so there is a before and an after. One leave request approved and one rejected. A custom field, because custom fields are where partial exports show themselves.
Then, on day three, before you are invested, run the export yourself and open the archive on your own machine. Check five things: the document files are inside the archive and open correctly, the changed field carries its history rather than only its current value, both leave requests are present with their outcomes, the custom field and its definition are both there, and the counts match what you entered.
Ask two questions in writing alongside it. Does this export run while an invoice is unpaid, and does an admin run it without contacting you. Written answers, because these are the two that get renegotiated later.
Anything that fails this test can still be a fine product. It is simply a product you should only buy with your eyes open about what the exit costs, which is the calculation in the real cost of switching HR systems. If you want the wider set of things worth asking while you have a vendor’s attention, they are in twelve questions to ask a vendor, and the mechanics of an actual move are in the switching guide.
Where we stand
We built the export before most of the modules, and the reason was not generosity. It was that we wanted the constraint. A vendor that cannot hold customers by making the exit expensive has to keep earning them, and we would rather be structurally forced into that than trust ourselves to be good about it later.
So: one archive, a documented file per entity with the sensitive values decrypted under your own authority, the original document files included rather than linked, and a manifest listing every entity and its row count, which a round trip test checks the archive against on every build. An owner runs it from a settings screen. It deliberately sits outside the billing guard, so it keeps working while an invoice is unpaid and while a workspace is suspended for non payment. That last point is the one worth reading in full, and the reasoning is on the security page, alongside what happens at each stage of a late invoice.
The limits, honestly. The export is owner only, so an HR admin cannot take it, which is deliberate but will annoy someone. The download link expires, so it is a file you take rather than a permanent URL. And the full archive is a manual act: individual reports can be scheduled and mailed to the owner, but nothing drops the whole archive into your own storage on a timer, which is the version we would want if we were the customer, and it is not built. The manifesto explains why we would rather publish that list than let you find it.