Skip to main content

Resource library

14 working files behind our guides — scoring sheets, requirement matrices, demo scripts and security-review checklists — plus a 34-term glossary. Everything here is free, ungated, and written to be copied into your own documents.

  • Templates

    Editable scoring sheets, requirement matrices and stakeholder briefs you can drop straight into an evaluation.

    Explore
  • Checklists

    Step-by-step lists for demos, security review, reference calls and contract redlines — so nothing gets skipped under deadline.

    Explore
  • Expert Guides

    What to do in the first 90 days after signing: content migration, library pruning, owner assignment and adoption tracking.

    Explore
  • Whitepapers

    Reference material for security questionnaires, data residency, accessibility and public-sector procurement rules.

    Explore
  • Glossary

    Plain-language definitions for the terms that appear in nearly every RFP software conversation.

    Explore

Templates

Editable scoring sheets, requirement matrices and stakeholder briefs you can drop straight into an evaluation.

  • Spreadsheet2–3 hours

    Requirements Matrix Template

    A two-level requirement structure with priority tiers, weights and a verification-method column — the document you build before contacting any vendor.

    • Six weighted categories that sum to 100, pre-filled with a defensible starting distribution
    • Must-have / should-have / nice-to-have tiers with a hard cap on must-haves
    • A verification-method column so "confirmed" never means "the vendor said so"
    Open the guide
  • Spreadsheet1 hour to set up

    Weighted Evaluation Scorecard

    A 0–4 scorecard with written anchors, per-category subtotals and space for independent scoring by multiple evaluators before reconciliation.

    • Written anchors for every score, so evaluators stop defaulting to the midpoint
    • Category subtotals presented above the total, where the real decision signal lives
    • Separate columns per evaluator plus a reconciliation note field
    Open the guide
  • Document90 minutes

    Vendor Demo Script

    The script you send every vendor in advance — five scripted tasks, two edge cases, and a hard requirement that they use your content instead of their demo dataset.

    • Five live tasks covering import, assignment, drafting, library update and export
    • Two deliberate edge cases: contradictory sources, and a question your library cannot answer
    • A rule that the contributor view is shown from a real second account, not described
    Open the guide
  • Document30 minutes to send

    Vendor Screening Questionnaire

    Ten written questions that filter a long list of eight to fifteen vendors down to three or four finalists — without booking a single discovery call.

    • Ten must-have questions covering seats, governance, security, hosting, AI terms and pricing
    • Answers drop straight into the vendor-response column of your matrix
    • Tests something no demo tests — whether a vendor answers a direct question directly
    Open the guide

Buying Checklists

Step-by-step lists for demos, security review, reference calls and contract redlines — so nothing gets skipped under deadline.

  • ChecklistHalf a day

    Content Library Audit Checklist

    Five measurements that tell you whether you are migrating 400 clean owned answers or 4,000 unattributed fragments — the fact that changes your entire evaluation.

    • Volume, freshness, duplication, ownership and format sprawl, with how to measure each
    • A sampling method that works without a full inventory
    • Guidance on what a bad result should change in your requirement weights
    Open the guide
  • Checklist20 minutes

    Demo Day Checklist

    What to prepare, bring and do on the day — including the five questions to ask in every demo and the ten-minute independent scoring window immediately afterwards.

    • Pre-demo prep: your content sample, five mismatched-vocabulary queries, worst-formatted file
    • Five questions to ask every vendor, including how content gets retired
    • Score independently within ten minutes, before any group discussion
    Open the guide
  • Checklist45 minutes to issue

    Security & Vendor Review Checklist

    Everything to request from finalists on day one of the review — SOC 2 report, DPA, subprocessor list, residency confirmation and the AI-specific terms most checklists still omit.

    • Request the SOC 2 Type II report itself and read the exceptions, not the badge
    • AI-specific terms: model training, opt-out, inference region, prompt retention
    • A live permission test — restricted content must be invisible in search, not merely unopenable
    Open the guide
  • Document30 minutes per call

    Reference Call Script

    Questions that cannot be answered with a testimonial — what implementation actually took, what they still do outside the tool, and what they would negotiate differently.

    • Ask for two references at your size plus one that churned or downgraded
    • The implementation estimate-versus-actual gap is the most honest number available
    • How long until subject-matter experts stopped resisting the tool
    Open the guide

Implementation Guides

What to do in the first 90 days after signing: content migration, library pruning, owner assignment and adoption tracking.

  • PlanOngoing

    First 90 Days Implementation Plan

    A three-phase rollout that starts with a deliberately small, high-quality content subset and ends with the shared drive switched off on purpose.

    • Weeks 1–3: migrate your best 150–300 answers with an owner assigned to each
    • Weeks 4–6: run two real responses end to end and expect to revise your taxonomy
    • Weeks 7–12: onboard contributors, start the first review cycle, retire the shadow drive
    Open the guide
  • Guide2–4 weeks

    Content Migration & Pruning Guide

    How to decide what moves, what gets rewritten and what gets left behind — plus the taxonomy decisions that are expensive to change later.

    • A small trusted library beats a large suspicious one — resist the bulk import
    • Deduplication rules and how to pick a canonical answer among near-identical versions
    • Variant modelling for region and product line, before drift sets in
    Open the guide
  • Policy template3 hours

    Library Governance Operating Model

    Ownership, review cadence and retirement rules written down as a working policy — the practice that determines whether automation helps or amplifies your worst content.

    • Named owners at the item level, with review dates and an overdue report someone actually reads
    • Review cadences that differ by content type instead of one interval for everything
    • A retirement path that removes content from search while preserving what used it
    Open the guide

Compliance Resources

Reference material for security questionnaires, data residency, accessibility and public-sector procurement rules.

  • Reference1 hour

    AI Terms Review Sheet

    The contract and data-handling questions specific to AI features — model training, opt-out rights, inference region, prompt retention and model-change notification.

    • Is customer content used to train models other customers benefit from, and can you opt out
    • Where inference runs, whether prompts and outputs are retained, and for how long
    • Whether you are notified when the underlying model changes, and whether a version can be pinned
    Open the guide
  • Reference1 hour

    Accessibility & Public-Sector Requirements

    What to request when you sell to government or have internal accessibility obligations — conformance reports, their scope, and the export-fidelity requirements buyers impose.

    • Request the accessibility conformance report and check its date and scope, not the claim
    • Mandatory output formats, numbering and forms that your tool must reproduce exactly
    • Records-retention and audit-trail expectations common in public procurement
    Open the guide
  • Reference1 hour

    Data Residency & DPA Requirements

    A structured request covering hosting region, subprocessors, retention, deletion on termination and the export rights you will want if you ever leave.

    • Hosting region and whether it is configurable, confirmed in the agreement rather than on a call
    • Current subprocessor list and notification terms for changes
    • Export rights in a documented machine-readable format, plus post-termination access period
    Open the guide

Glossary

34 terms that come up in nearly every RFP software conversation — defined the way practitioners actually use them, not the way vendor marketing does.

Answer library
The maintained store of reusable answers, narrative sections and boilerplate that a response team draws on. Also called a content library or knowledge library. It is the actual asset in an RFP platform — every other feature operates on it.See also: Content governance, Single source of truth
APMP
The Association of Proposal Management Professionals, the main professional body for bid and proposal practitioners. Its certification levels (Foundation, Practitioner, Professional) are the closest thing the field has to a common credential.
Bid/no-bid decision
The qualification call on whether to respond to an opportunity at all. Widely considered the highest-leverage decision in response work, since a declined bad-fit RFP frees capacity for a winnable one.
Boilerplate
Standard reusable text — company overview, legal language, standard terms — that appears with little variation across responses. Low-risk to automate, but a common source of embarrassment when it goes stale.
Compliance matrix
A table mapping every requirement to the evidence that it is satisfied, with a score and a verification method. Used by responders to prove coverage of a solicitation, and by buyers to make a software selection traceable and auditable.See also: Requirements traceability
Content governance
The practice of keeping a library accurate: named owners per item, review cadences, approval states, deduplication and a retirement path. The constraint on how well any automation performs.
Content variant
An alternative version of an answer for a specific region, product line or buyer segment, ideally linked to a canonical parent so that updating the parent flags the variants for review.
Deal desk
A cross-functional group that reviews non-standard deal terms, pricing and commitments before they are offered. Often a required approver on pricing sections of a response.
DPA
Data Processing Agreement. The contract governing how a vendor processes your data on your behalf, including purposes, subprocessors, security measures and deletion obligations. Required under GDPR and increasingly requested regardless of jurisdiction.
Edit distance
Informally, how much work is needed to turn a generated draft into something submittable. The metric that determines whether AI drafting actually saves time, and the one vendors never report.
Embedding
A numerical representation of text that captures meaning, letting a system find passages that are semantically similar rather than keyword-identical. The mechanism behind semantic search in most current products.See also: Semantic search, RAG
Executive summary
The opening section of a proposal, usually the most-read and most-scrutinised part. Frames the buyer's problem and your differentiated response to it — the part of a response least suited to automation.
Grounding
Constraining generated text to information retrieved from a specific source set, so claims trace back to approved content rather than model priors. The difference between an AI draft you can review in two minutes and one you must verify from scratch.See also: RAG, Hallucination
Hallucination
Fluent, confident output that is not supported by any source. In response work the dangerous case is not obvious nonsense but a plausible invented specific — a certification date, an uptime figure, a version number.
Intake
The process of turning a received RFP document into a structured, assignable question list. High-volume, tedious, and one of the most reliable places automation delivers value.
Knowledge base
A general-purpose store of searchable organisational content. Handles storage and retrieval but lacks the response workflow layer — intake, assignment, deadline tracking, approval routing, buyer-format export.
Oral presentation
A live presentation or defence session where the buyer questions the response team directly. Increasingly weighted more heavily as written responses become cheaper to produce and less discriminating.
Pink team / red team review
Structured review milestones borrowed from formal bid practice. A pink team reviews an early draft for strategy and structure; a red team reviews a near-final draft as the buyer's evaluator would, scoring against the actual criteria.
Portal
The buyer-side system through which a solicitation is issued and responses are submitted, common in public sector and large enterprise procurement. Portals impose their own formats and deadlines, which is why export fidelity matters.
Proposal management software
Software emphasising the creation of designed, persuasive outbound documents — templates, layout, pricing tables, e-signature, engagement tracking. Overlaps with RFP response software but optimises for a different output.
Provenance
The traceable record of where a piece of content came from — which library item, which version, generated or human-written, edited by whom, approved by whom. The foundation of a defensible response process.
RAG
Retrieval-augmented generation. The dominant architecture in AI RFP software: retrieve relevant passages from your library, add them to the prompt, then generate an answer grounded in that material. Output quality depends more on the retrieval step than the model.See also: Grounding, Semantic search
Requirements traceability
The ability to show, for any requirement, what was tested, how, by whom and with what result. The property that separates a compliance matrix from a feature checklist.
RFI
Request for Information. An early-stage, exploratory information request used to map the supplier landscape before a formal solicitation. Usually shorter and less structured than an RFP.
RFP
Request for Proposal. A structured solicitation in which a buyer states requirements and invites suppliers to propose a solution, typically evaluated against published criteria.
RFQ
Request for Quotation. A price-focused solicitation for well-specified goods or services, where the requirement is settled and the competition is largely commercial.
SCIM
System for Cross-domain Identity Management. The standard for automatically provisioning and deprovisioning user accounts from your identity provider. Matters once you pass a few dozen users, and matters for offboarding specifically.
Security questionnaire
A standardised set of security and compliance questions sent by buyers to vendors, often as a large spreadsheet or portal form. High volume, short factual answers, verifiable — the strongest use case for automation in the category.
Semantic search
Search that matches on meaning rather than exact keywords, so a query about "business continuity" can surface content filed under "disaster recovery." Solves vocabulary mismatch, at the cost of a quieter failure mode — plausible but wrong matches presented with equal confidence.
Single source of truth
The principle that one canonical, owned, current version of each answer exists. Widely claimed by vendors and achieved only through governance — near-duplicate detection at creation time is the mechanism that makes it real.
SME
Subject-matter expert. The engineer, security lead or finance manager pulled in to answer specialist questions. Their contribution experience is the strongest predictor of whether an RFP platform is adopted or abandoned.
SOC 2 Type II
An audit report on the design and operating effectiveness of a vendor's controls over a defined period. Request the report itself and read the exceptions — the badge alone tells you an audit happened, not what it found.
Source-to-pay
The broad procurement software category covering sourcing, contracting, purchasing and payment. Procurement-side solicitation tools often live inside these suites, which is why they surface in searches for RFP software.
Win theme
A specific, differentiated argument for why this buyer should choose you, carried consistently through a response. Requires knowledge that is not in your content library, which is why it remains the least automatable part of the work.
Free toolkit

Pair the templates with the guide that explains them

Templates are faster to use when you know what each column is for. Our buying guide walks through the requirement, scoring and compliance work these files are designed to support.