A roadmap is a forward contract with no margin posted — the vendor collects today, and you carry the delivery risk.

Why Roadmap-Ware Matters Now

Every platform vendor in endpoint security has now announced an AI governance module. The pattern is remarkably consistent: announce the module, demo the dashboard, defer the endpoint agent. Ask when enforcement ships and you get soft-quarter language — “next week or two,” “safely in August.” Ask whether the module will block agent actions or just observe them, and you learn that blocking-versus-visibility is “still being decided.”

That last answer should end the meeting. A control whose enforcement posture is undecided is not a control. It is a dashboard with an option attached, and the option is unpriced.

The urgency is not hypothetical. The exposure is already on the books:

Signal Number Source
Enterprises finding unsanctioned agents in their first inventory 88% Ospiri research
Added cost when an incident involves an ungoverned agent +$670K Ospiri research
Window before incumbent bolt-on modules reach maturity 12–18 months Ospiri research
Guardian-agent tools with real-time autonomous enforcement Mostly proof-of-concept today Gartner

Agents are deploying this quarter. A module that enforces “safely in August” leaves you naked for at least one full budget cycle — and August has a habit of becoming November.

Shipped vs. Roadmap-Ware: Reading the Term Sheet

The two products can look identical in a first call. The difference is in what the vendor can prove on demand, in your environment, before the contract is signed.

Dimension Shipped enforcement Roadmap-ware
The demo Live blocking on your own test machine A dashboard over recorded data
Control point Kernel — process, file, and network scopes Browser inspection or cloud-log ingestion
Policy authoring A policy written during the call, enforced immediately A canned detection library, “customization coming”
Evidence Kernel artifacts: process, file, label, action, verdict Screenshots and aggregate charts
SIEM integration Egress you can watch land in your own Splunk “Connector on the roadmap”
Timeline language “Deploy the PoC this week” “Shipping safely in August”

Let’s step back. None of this means the incumbent module will never ship. It means you are being asked to underwrite the vendor’s engineering schedule — and that risk belongs in the price, not in the fine print.

The Anatomy of a Roadmap-Ware Pitch

The tells recur across vendors. From recent diligence calls in the category, the pattern looks like this:

  1. The dashboard leads, the agent trails. The AI module demo is entirely visualization; the endpoint component that would generate the data is “in final validation.”
  2. Enforcement posture is undecided. Whether the product blocks or merely observes is framed as a future product decision — meaning the enforcement architecture doesn’t exist yet.
  3. No live policy authoring. You cannot ask for a policy — “no agent may open files labeled Confidential” — and watch it take effect. You are shown a library of pre-built detections instead.
  4. No kernel evidence. Ask for the artifact trail behind a blocked action and you get an alert record, not proof of what process touched what file with what verdict.
  5. Soft-quarter dates. “Safely August” is not a ship date; it is a probability distribution with a long right tail. Vendors who have shipped quote deployment steps, not seasons.

Any one of these is survivable. Three or more and you are evaluating a prospectus, not a product.

Pricing the Risk Into the Contract

If the platform vendor’s brand still wins the deal — and brand does win deals — then treat the roadmap like any other forward commitment and demand covenants.

Roadmap Risk = (Capability Gap × Contract Duration) + (Deal Weight × Slippage Probability)

Factor What it measures How to estimate it
Capability Gap Distance between demoed and contracted functionality Feature-by-feature diff from the live demo
Contract Duration How long you’re locked in while the gap persists Term length minus PoC period
Deal Weight Share of your agent-governance budget committed Line-item percentage
Slippage Probability Likelihood the ship date moves Vendor’s track record on prior module launches

The hedges are contractual and standard: milestone-gated payments tied to demonstrated enforcement, a PoC gate before the annual commitment activates, and exit clauses if the endpoint agent slips past a named date. A vendor confident in August will sign for September. A vendor who resists the covenant has told you the real date.

What Shipped Actually Looks Like

The burden of proof is cheap to apply because shipped software can carry it in an afternoon. Before any contract, require each of these in your environment — not the vendor’s:

Proof point What you should see
Copy-on-write sandboxing An agent writes to a sensitive path; the write lands in an isolated copy, validated on your test VM
Process and network blocking A policy denies an action mid-execution — block-on-deny where warranted, not an alert afterward
Kernel evidence artifacts Process, file, label, action, verdict — exportable, timestamped, audit-ready
SIEM egress Events arriving in your own Splunk or Datadog during the session
Live policy authoring A rule written in the meeting, enforced before the meeting ends

This is the same bar the agent firewall category exists to meet: enforcement at the kernel, below the prompt layer and below the SaaS APIs, where the agent’s actions actually land. Observability alone — however polished — is monitoring, not governance.

What CISOs Should Do This Quarter

Step Action Output Effort
1 Rerun every shortlisted vendor through the five tells above A shipped vs. roadmap-ware classification 1 week
2 Require the live-proof checklist on a test VM you control Pass/fail evidence per vendor 2 weeks
3 Score each deal with the Roadmap Risk formula A ranked exposure number per contract 2 days
4 Add milestone gates and exit clauses to any roadmap-weighted deal Covenants that convert vendor risk into vendor obligation 1 procurement cycle

Pair the evaluation with your own ground truth: an agent inventory of what is already running on your endpoints makes the “can you see this today?” question concrete rather than rhetorical.

The Bottom Line

In security procurement, a roadmap is not a control — and the difference is measurable at the kernel, on your own test machine, before you sign. Incumbent platforms will keep winning deals on brand while their enforcement layer is still a slide, and the buyers who get hurt are the ones who booked the slide as coverage. The discipline is the same one any trading desk applies to a forward: verify delivery capability, price the slippage, and write the covenants. If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, run a live blocking demo on a test VM you control, and scope a deployment. 90 minutes.