A roadmap is a forward contract with no margin posted — the vendor collects today, and you carry the delivery risk.
Why Roadmap-Ware Matters Now
Every platform vendor in endpoint security has now announced an AI governance module. The pattern is remarkably consistent: announce the module, demo the dashboard, defer the endpoint agent. Ask when enforcement ships and you get soft-quarter language — “next week or two,” “safely in August.” Ask whether the module will block agent actions or just observe them, and you learn that blocking-versus-visibility is “still being decided.”
That last answer should end the meeting. A control whose enforcement posture is undecided is not a control. It is a dashboard with an option attached, and the option is unpriced.
The urgency is not hypothetical. The exposure is already on the books:
| Signal | Number | Source |
|---|---|---|
| Enterprises finding unsanctioned agents in their first inventory | 88% | Ospiri research |
| Added cost when an incident involves an ungoverned agent | +$670K | Ospiri research |
| Window before incumbent bolt-on modules reach maturity | 12–18 months | Ospiri research |
| Guardian-agent tools with real-time autonomous enforcement | Mostly proof-of-concept today | Gartner |
Agents are deploying this quarter. A module that enforces “safely in August” leaves you naked for at least one full budget cycle — and August has a habit of becoming November.
Shipped vs. Roadmap-Ware: Reading the Term Sheet
The two products can look identical in a first call. The difference is in what the vendor can prove on demand, in your environment, before the contract is signed.
| Dimension | Shipped enforcement | Roadmap-ware |
|---|---|---|
| The demo | Live blocking on your own test machine | A dashboard over recorded data |
| Control point | Kernel — process, file, and network scopes | Browser inspection or cloud-log ingestion |
| Policy authoring | A policy written during the call, enforced immediately | A canned detection library, “customization coming” |
| Evidence | Kernel artifacts: process, file, label, action, verdict | Screenshots and aggregate charts |
| SIEM integration | Egress you can watch land in your own Splunk | “Connector on the roadmap” |
| Timeline language | “Deploy the PoC this week” | “Shipping safely in August” |
Let’s step back. None of this means the incumbent module will never ship. It means you are being asked to underwrite the vendor’s engineering schedule — and that risk belongs in the price, not in the fine print.
The Anatomy of a Roadmap-Ware Pitch
The tells recur across vendors. From recent diligence calls in the category, the pattern looks like this:
- The dashboard leads, the agent trails. The AI module demo is entirely visualization; the endpoint component that would generate the data is “in final validation.”
- Enforcement posture is undecided. Whether the product blocks or merely observes is framed as a future product decision — meaning the enforcement architecture doesn’t exist yet.
- No live policy authoring. You cannot ask for a policy — “no agent may open files labeled Confidential” — and watch it take effect. You are shown a library of pre-built detections instead.
- No kernel evidence. Ask for the artifact trail behind a blocked action and you get an alert record, not proof of what process touched what file with what verdict.
- Soft-quarter dates. “Safely August” is not a ship date; it is a probability distribution with a long right tail. Vendors who have shipped quote deployment steps, not seasons.
Any one of these is survivable. Three or more and you are evaluating a prospectus, not a product.
Pricing the Risk Into the Contract
If the platform vendor’s brand still wins the deal — and brand does win deals — then treat the roadmap like any other forward commitment and demand covenants.
Roadmap Risk = (Capability Gap × Contract Duration) + (Deal Weight × Slippage Probability)
| Factor | What it measures | How to estimate it |
|---|---|---|
| Capability Gap | Distance between demoed and contracted functionality | Feature-by-feature diff from the live demo |
| Contract Duration | How long you’re locked in while the gap persists | Term length minus PoC period |
| Deal Weight | Share of your agent-governance budget committed | Line-item percentage |
| Slippage Probability | Likelihood the ship date moves | Vendor’s track record on prior module launches |
The hedges are contractual and standard: milestone-gated payments tied to demonstrated enforcement, a PoC gate before the annual commitment activates, and exit clauses if the endpoint agent slips past a named date. A vendor confident in August will sign for September. A vendor who resists the covenant has told you the real date.
What Shipped Actually Looks Like
The burden of proof is cheap to apply because shipped software can carry it in an afternoon. Before any contract, require each of these in your environment — not the vendor’s:
| Proof point | What you should see |
|---|---|
| Copy-on-write sandboxing | An agent writes to a sensitive path; the write lands in an isolated copy, validated on your test VM |
| Process and network blocking | A policy denies an action mid-execution — block-on-deny where warranted, not an alert afterward |
| Kernel evidence artifacts | Process, file, label, action, verdict — exportable, timestamped, audit-ready |
| SIEM egress | Events arriving in your own Splunk or Datadog during the session |
| Live policy authoring | A rule written in the meeting, enforced before the meeting ends |
This is the same bar the agent firewall category exists to meet: enforcement at the kernel, below the prompt layer and below the SaaS APIs, where the agent’s actions actually land. Observability alone — however polished — is monitoring, not governance.
What CISOs Should Do This Quarter
| Step | Action | Output | Effort |
|---|---|---|---|
| 1 | Rerun every shortlisted vendor through the five tells above | A shipped vs. roadmap-ware classification | 1 week |
| 2 | Require the live-proof checklist on a test VM you control | Pass/fail evidence per vendor | 2 weeks |
| 3 | Score each deal with the Roadmap Risk formula | A ranked exposure number per contract | 2 days |
| 4 | Add milestone gates and exit clauses to any roadmap-weighted deal | Covenants that convert vendor risk into vendor obligation | 1 procurement cycle |
Pair the evaluation with your own ground truth: an agent inventory of what is already running on your endpoints makes the “can you see this today?” question concrete rather than rhetorical.
The Bottom Line
In security procurement, a roadmap is not a control — and the difference is measurable at the kernel, on your own test machine, before you sign. Incumbent platforms will keep winning deals on brand while their enforcement layer is still a slide, and the buyers who get hurt are the ones who booked the slide as coverage. The discipline is the same one any trading desk applies to a forward: verify delivery capability, price the slippage, and write the covenants. If your team is sizing this for the next budget cycle, request a working session. We will walk through your environment, run a live blocking demo on a test VM you control, and scope a deployment. 90 minutes.