Checklist for selecting productivity software with workflow, security, and data terms.
Image: Work Stack Lab

Reviews

Part of How to compare eight productivity software tools before reaching a verdict

Selecting productivity software, from workflow fit to export and exit

Use this productivity software selection checklist to test workflow fit, security, data terms, full cost, administration and a credible exit.

Use this business productivity software selection checklist to produce a decision record, not a tick-filled sales form. Assign each line an owner, evidence link, date and status: confirmed, failed, unresolved or not applicable.

The checklist is for organisations in England and was researched on 5 September 2026. It is not legal, privacy, security, financial or procurement advice. The relevant specialists must examine the actual service, configuration, contract and use case.

What to take away

  • A selection checklist should produce a decision record with owners, evidence, dates and status, not a tick-filled sales form.
  • Test every candidate with identical tasks and a neutral workflow that includes incomplete, urgent, blocked and confidential records.
  • Security and privacy duties stay with the customer, so review the chosen edition, tenant settings and contract terms.
  • Do not calculate savings from vendor illustrations; use your own volumes, approved cost method and scenario range.
  • Approval is only sound when an uninvolved reviewer can trace each claimed capability to evidence and reproduce the comparison.

Need and workflow

  • State the operational problem in one sentence without naming a product.
  • Identify submitters, workers, approvers, administrators and external collaborators.
  • Describe normal demand, peaks, deadlines, exceptions and the intended outcome.
  • Mark essential capabilities as gates and keep conveniences as weighted criteria.
  • Record why each candidate entered or left the shortlist.

Create a neutral sample workflow with complete, incomplete, urgent, blocked, reassigned and confidential records. Do not accept a demonstration built only from the provider's ideal example.

Flow from stating the problem to recording shortlist decisions (Selecting productivity software, from workflow fit to export and exit)
Section 0's checklist as a sequence: define the problem and roles before any product enters the shortlist. Image: Work Stack Lab

Trial and evidence

  • Publish reviewer, research date, editions, devices, roles and conflicts.
  • Distinguish provider documentation, observed tests, authoritative guidance and customer claims.
  • Run identical tasks and scoring anchors for every option.
  • Save observations and failures rather than only a final score.
  • Repeat critical tasks after a configuration or product change.

Government Digital Service guidance on testing services regularly is aimed at public services. Its practical value here is the discipline of testing during delivery, involving different roles and covering unusual conditions. It does not certify any commercial product.

Checklist of evidence to publish from a software trial (Selecting productivity software, from workflow fit to export and exit)
Section 1's evidence requirements, so a reader can reproduce the comparison rather than trust a score. Image: Work Stack Lab

Identity, access and resilience

  • Confirm single sign-on and multi-factor authentication requirements.
  • Test ordinary, guest, privileged and emergency access separately.
  • Demonstrate joiner, mover and leaver handling with owned work preserved.
  • Identify audit events, log access, alert routes and retention.
  • Review backups, recovery responsibilities, incident contacts and service dependencies.

The NCSC's SaaS security guidance makes clear that customers retain responsibility for use-specific configuration. Security review should therefore examine the selected edition and tenant settings, not rely on a provider logo or generic certificate.

Access and resilience checks

  • Confirm SSO and MFA requirements
  • Test ordinary, guest, privileged, emergency access
  • Demonstrate joiner, mover, leaver handling
  • Identify audit events, logs, alerts, retention
  • Review backups, recovery, incident contacts

Personal and confidential data

  • Map data categories, people, purposes, locations, transfers and retention.
  • Determine controller, processor and any sub-processor roles.
  • Check supplier access, confidentiality, assistance, audit, return and deletion terms.
  • Minimise test data and avoid live personal information where possible.
  • Complete any required risk assessment before production use.

The ICO lists processing details and minimum provisions for controller-processor arrangements in its contract guidance. The regulator notes that the page is under review after legislative change, so a privacy professional should confirm the current law and the organisation's roles.

Commercial and delivery fit

  • Obtain a dated quotation for the same users, term, currency and tax basis.
  • Separate licences, migration, configuration, integrations, training, support and exit.
  • Check minimum commitments, usage limits, renewals and change mechanisms.
  • Name the supplier entity, implementation party and subcontractors.
  • Agree acceptance criteria, defects, change control, knowledge transfer and ownership of artefacts.

Do not calculate savings from vendor illustrations. Use the organisation's own volumes, approved cost method and scenario range, with finance and commercial review.

Export and exit

  • Define records, attachments, comments, relationships, identities and audit history needed on exit.
  • Export a representative sample and open it independently.
  • Price transformation, migration, overlap, archive and specialist skills.
  • Review termination assistance, deletion evidence and post-contract access.
  • Assign an exit owner and rehearse before dependency becomes critical.

The government's technical lock-in guidance concerns public organisations, but its prompts on open formats, migration cost, proprietary knowledge and planned exit are useful for private due diligence. Keep that scope boundary visible.

Approval

  • List unresolved questions with owner and deadline.
  • Show gate results separately from weighted scores.
  • Record dissent, accepted risks and review sign-offs.
  • Set an expiry date for product, price and contract evidence.
  • Approve a limited pilot before broad rollout where uncertainty remains.

The selection is ready only when an uninvolved reviewer can follow a claimed capability to evidence, reproduce the comparison and see why residual risks were accepted. An attractive total without that trail is not a dependable decision.

Before you act

  • State the operational problem without naming a product.
  • Publish reviewer, research date, editions, devices, roles and conflicts.
  • Test ordinary, guest, privileged and emergency access separately.
  • Minimise test data and avoid live personal information.
  • Export a representative sample and open it independently.
  • List unresolved questions with owner and deadline.

Common questions

What should the checklist produce instead of a completed sales form?

It should produce a decision record. Assign each line an owner, evidence link, date and status, choosing from confirmed, failed, unresolved or not applicable. This keeps the comparison auditable and shows why each candidate entered or left the shortlist.

How should a buyer test a product during a trial?

Run identical tasks and scoring anchors for every option, and save observations and failures rather than only a final score. Create a neutral sample workflow covering complete, incomplete, urgent, blocked, reassigned and confidential records, and repeat critical tasks after any configuration or product change.

What must be checked before approving a purchase?

List unresolved questions with owner and deadline, show gate results separately from weighted scores, and record dissent, accepted risks and sign-offs. Set an expiry date for product, price and contract evidence, and approve a limited pilot before broad rollout where uncertainty remains.

More in Reviews