Start with the same difficult journey
A fair comparison gives each option the same business task and the same awkward condition. “Customer can view documents” is too broad. Ask a supplier to demonstrate an invited contact working across two companies while a restricted document remains visible to only one account. Include the administrator who grants and removes access. A product demonstration using its default workflow tells you less than a short exercise using your actual relationships, terminology and approval boundaries.
Write the shared brief first
Use the same journeys, source systems and acceptance criteria for a configured product and a custom proposal. This also makes their estimates more comparable.
Explore Write the shared brief firstSeparate a hard requirement from a preference
Mark each requirement as essential, valuable or optional. A hard requirement might be a customer-specific permission rule, a mandatory integration or an export needed to leave the platform. A preference might be the exact position of a navigation item. Do not let many minor conveniences outweigh one failed access requirement. Equally, do not commission a new platform solely to preserve a familiar process that the business is willing to improve.
Use a fit record
For each requirement, record supported directly, supported by configuration, dependent on an extension, custom work required or unsupported. Attach a demonstration or documentation reference rather than a sales assertion.
Test permissions and integrations below the interface
Request evidence for the actions that matter: reading a record, downloading its attachment, changing it and accessing its history. OWASP recommends authorization checks on individual records reached through an API. Hiding a menu item is not that check. For integrations, confirm the exact operation and direction supported. A connector that creates contacts may not update account relationships, carry attachments or reconcile deletions. Also establish what happens when the external service stops responding and who sees the failure.
Worked choice: configure the fit, investigate the gap
Consider a service business that needs secure document exchange, request status and invitations. If a hosted product handles those journeys and exports the required records, configuration may be a sensible first release. Now add a rule that each request needs approval from a changing combination of customer departments before the ERP can act. If the product cannot represent that rule without parallel spreadsheets and manual duplication, investigate a custom workflow or a focused extension. The decision turns on that demonstrated gap, not a general claim that either approach is more professional.
Compare responsibility and the exit route
A hosted product transfers some infrastructure work to its provider, but the business still owns account governance, configuration and data quality. Custom development gives more control over behavior while requiring a clear maintenance and release owner. In both proposals, examine subscription dependencies, support boundaries, export formats and access to technical records. Test an export while evaluating the product: verify attachments, relationships and readable history, not merely a spreadsheet of names.
Keep custom work bounded
When only one journey is unusual, assess whether a focused application can support it without replacing every system. Define its ownership and integration boundary.
Explore Keep custom work boundedInclude ongoing care
Specify who updates dependencies, verifies recovery and responds when a provider changes its interface.
Explore Include ongoing careFinish with a decision record and an exit trigger
Record the chosen approach, evidence from the difficult journey, unresolved risks and reasons the rejected option fits less well. Define the conditions that would prompt reconsideration: a required integration disappearing, an unacceptable export restriction or a workflow becoming central to the business. A small, reversible first release can provide better evidence than a long feature comparison. Before committing, have the people who administer the system perform their tasks; customer-facing polish alone does not demonstrate that the business can operate it.