CONTENTFUL · WORKSHOP DAY
Plan.Net / Mindcore · BMW·MINI AEM Replacement · One-day vendor workshop
C

Contentful organization → space → environment (+ environment aliases)

Inheritance-native, compliance-strong.

Contentful is the inheritance-native option: the strongest native field-level localization and fallback machinery of the three, the cleanest compliance sheet (ISO 27001, SOC 2, TISAX), and the vendor our team already runs deepest. It leads the Balanced and Multi-market scoring profiles. The two things that decide the day: whether approval is enforced at the API (not just the UI), and what survives the Salesforce acquisition in writing.

GOING IN Leads Balanced (380/500) and Multi-market (394/500). Front-runner if field-level inheritance is the priority.
Companion to the shared technical dossier · other days: Contentstack pack · Sanity pack
A

The day at a glance

A ~8.5-hour working session, structured around the eight non-negotiable gates. Every critical question is run as “show us”, not “do you support…”. The output of the day is evidence — recordings, logs, API responses — and a completed scorecard, not a feeling.

30m
Context: BMW/MINI + target architecture

Vendor confirms it understands the HQ→market model and the eight gates below.

90m
GATE 1 — Fallback / inheritance

Live demo: partial override + later HQ update. Capture CDA/GROQ payloads before & after.

90m
GATE 2 — Approval workflow

Demo in UI, then attempt publish with a Management-API token. Capture the enforcement response.

60m
GATE 3 — Editor visual preview

Real BMW-like preview: inherited vs overridden fields, market/locale, approval state.

60m
GATE 4 — DAM / AEM Assets

Asset reference, expiry/replacement, usage tracking, pre-publish stale-asset warning.

60m
GATE 5 — Migration / cutover

Environment model, re-runnable import, rate limits, rollback — with real 429/Retry-After logs.

60m
GATE 8 — Compliance / commercial / contract

Answers that go into the contract/RFP, not just the chat: SLA, residency, TISAX/ISO, uplifts.

45m
AI / personalization (Phase-1 scope only)

Only as far as BMW's Phase-1 scope requires — do not let it consume the day.

30m
Recap / open risks

Pass/fail per gate, open-risk owner + follow-up deadline, contractual to-dos.


B

Read-in: where Contentful stands going in

Our position from the documented evidence in the shared dossier (verified against official docs, two passes 2026-07-06/07). The workshop confirms or overturns it — that is the point.

Top strengths

  • Native multi-hop locale fallback chainsde-CH→de-AT→de-DE→en-US, configurable per locale; locale-scoped roles keep market editors in their locale. docs
  • Cleanest compliance sheetISO/IEC 27001:2022, SOC 2 Type 2, and TISAX (TÜV Rheinland / ENX) — the automotive-relevant assessment the others lack. docs
  • Deepest hands-on for usOur repo runs the full Contentful import pipeline, locale-scoped publishing and market tags today — plus BMW already runs 160+ BMW / 147 MINI dealer sites on it. docs

Top risks / where the bodies are buried

  • Workflow API-enforcement is undocumentedThe docs never state whether a Management-API token can publish an entry sitting pre-Approved, and admins bypass steps by default. Governance may be UI-deep only — GATE 2 is where we find out. docs
  • Salesforce acquisition pending closeDefinitive agreement signed 2026-06-01, expected to close ~Aug–Oct 2026. No customer FAQ, pricing or standalone-roadmap commitment published — renewal leverage sits with Salesforce. docs
  • Hard edges at BMW scale50 fields per content type forces model decomposition; a saved empty string silently breaks the fallback chain; the org is pinned to one residency region permanently. docs

C

Live demo scripts — the eight gates

Each gate is a script: setup → show-us steps → expected evidence → pass/fail. Run them in order; GATES 1 and 2 are the ones that decide Contentful. Don't accept a verbal answer where a demo is written.

GATE 1

Field-level HQ inheritance

90 min
Going in: Strong (native) — confirm multi-hop resolution on the CDA and the empty-string trap.
Setup

One space; a field-level-localized car type with a fallback chain de-CH→de-AT→de-DE→en-US. HQ values populated on the default locale.

Show us — live steps
  1. Leave de-DE price and image empty. GET the entry via the CDA in de-DE → expect the fallback-chain values to resolve.
  2. Set de-DE price only. GET again → price is the DE override, image still inherited.
  3. Update the master/default-locale price. GET de-DE → the inherited price reflects the new master value; the DE override is untouched.
  4. Write an empty string "" into de-DE image. GET → show that this blocks the fallback ("what you set is what you get") — the documented trap.
Expected evidence to capture

Four CDA JSON payloads, side by side, showing steps 1–3 resolving correctly and step 4 breaking.

✓ Pass
Steps 1–3 behave as described AND the vendor names a concrete guardrail against empty-string writes from TMS/import.
✗ Fail
Fallback doesn't resolve across a multi-hop chain, OR cross-space references are needed and don't resolve field values at delivery.
Reference: official docs
GATE 2

API-enforced approval

90 min
Going in: Must be proven — docs are silent on API-level enforcement.
Setup

Workflows app: a sequential Draft→Reviewed→Approved→Published workflow; a per-step rule denying publish to the editor role; only a Market-Lead team can move Reviewed→Approved.

Show us — live steps
  1. As an editor in the web app, attempt to publish a Draft entry → expect it blocked.
  2. The decisive step: with a Management-API (CMA) token, POST a publish on that same Draft entry. Capture the HTTP response.
  3. As a space admin, move the entry between steps → note that admins bypass restrictions by default (confirm how the admin role is contained).
  4. Ask: can an integration/automation token be scoped so it, too, respects the workflow gate?
Expected evidence to capture

The raw CMA publish response from step 2 (a 2xx means the gate is UI-only; a 4xx means it is enforced).

✓ Pass
The CMA publish is rejected while the entry is pre-Approved, and admin/token bypass is containable.
✗ Fail
A CMA token publishes a pre-Approved entry regardless — approval is cosmetic at the API.
Reference: official docs
GATE 3

Editor-grade visual preview

60 min
Going in: Native building blocks (Studio / Experiences); BMW-specific preview is configuration + our frontend route.
Setup

Studio / Experiences preview wired to a BMW-like page pulling an HQ master + a DE market variant.

Show us — live steps
  1. Open the page preview; switch market/locale (DE ↔ another market) and desktop ↔ mobile.
  2. Show which fields are inherited-from-HQ vs. locally overridden — visibly, in the editor, not just in the payload.
  3. Show the entry's workflow state and a draft-vs-approved-vs-published comparison in the same flow.
Expected evidence to capture

A screen recording of the full flow, plus the plan gating for Studio (unverified — confirm).

✓ Pass
An editor can see inherited vs overridden fields, market/locale, and approval state in one preview.
✗ Fail
Preview is entry-field editing only, with no page context or inheritance visibility.
Reference: official docs
GATE 4

DAM / AEM Assets coexistence

60 min
Going in: Asset bandwidth is metered; expiry/usage-tracking are App-Framework builds — probe how much is native.
Setup

An entry referencing an external asset (an AEM Assets URL), plus a second stale/expired asset.

Show us — live steps
  1. Reference the external asset and render it through the delivery API + image transforms.
  2. Show expiry / replacement handling and a 'where is this asset used' usage view.
  3. Attempt to publish an entry pointing at the expired asset → expect a warning/block.
Expected evidence to capture

A working external-asset reference and a demonstrated (or clearly-scoped-as-custom) usage/expiry mechanism.

✓ Pass
External DAM references work AND usage/expiry governance exists or is a bounded App-Framework build.
✗ Fail
The only answer is 'move assets into Contentful' — reject the CMS-store-as-DAM answer.
Reference: official docs
GATE 5

Migration & cutover

60 min
Going in: CMA 10 req/s per space; env clone drops workflows; export drops workflows/tasks/scheduled releases/history.
Setup

A source space with content model + entries; a target environment; a scripted import.

Show us — live steps
  1. Run a re-runnable import (idempotent on an external key) twice → show no duplication.
  2. Sustain CMA writes at the 10 req/s/space ceiling for ~10 min → capture the 429 / Retry-After behavior under load.
  3. Clone an environment and swap the master alias → confirm what does NOT copy (workflows) and that versioning/snapshots exist only in the master-alias target.
Expected evidence to capture

Import logs (idempotency), a 429/Retry-After trace, and the alias-swap result.

✓ Pass
Idempotent import, predictable backpressure, and a documented promotion model with the exclusions stated.
✗ Fail
No idempotency story, or the migration window can't be sized because rate behavior is opaque.
Reference: official docs
GATE 6

China / CDN delivery

45 min
Going in: Fastly + CloudFront cache globally; EU residency is storage, not processing; org region-pinned forever.
Setup

A published entry served through the CDN; BMW's own CDN (Akamai) in front for the invalidation test.

Show us — live steps
  1. Publish a change → measure publish-to-edge propagation time.
  2. Ask for the concrete mainland-China delivery story (edge presence / ICP-compliant partner / customer-proxied).
  3. Show the sanctioned cache-invalidation webhook/headers for BMW's Akamai — noting webhooks retry only 3× in ~1 min and never retry timeouts.
Expected evidence to capture

A propagation number and a written China-delivery architecture; the invalidation mechanism.

✓ Pass
A concrete propagation figure + a real China plan + a reconciliation story for missed webhooks.
✗ Fail
China is 'customers handle it themselves' and no propagation guarantee exists.
Reference: official docs
GATE 7

Exit & reversibility

45 min
Going in: Good content export (--download-assets); loses workflows/tasks/scheduled releases, version history, memberships, author history; proprietary rich text.
Setup

The demo space with assets, roles, workflows and some version history.

Show us — live steps
  1. Run space export --download-assets → confirm content model, entries, assets, locales, roles and editor interfaces are all present.
  2. Confirm the exclusions explicitly: workflows, tasks, scheduled releases, version history, space memberships, author history, webhook credentials.
  3. Ask about the migration path for the proprietary rich-text JSON to another platform.
Expected evidence to capture

An export bundle + an explicit written list of what is and isn't included.

✓ Pass
Content + assets export cleanly and the exclusions are acknowledged with a plan for governance/audit continuity.
✗ Fail
Exit is undocumented or assets/history can't be recovered.
Reference: official docs
GATE 8

Contractual signability

60 min
Going in: The most important Contentful gate given the acquisition.
Setup

Commercial / legal stakeholders in the room; RFP language ready.

Show us — live steps
  1. Get, in writing: which roadmap, pricing and renewal terms survive the Salesforce close, and any standalone-availability commitment.
  2. Confirm the SLA ("up to 99.99%") as a contractual number, EU data-residency architecture (storage vs processing), and rate-limit uplifts for migration + steady state.
  3. Confirm the custom-roles tier (Enterprise on today's pricing page) and the AI-Actions / bandwidth metering that apply to BMW's volumes.
Expected evidence to capture

Written answers destined for the contract/RFP — not verbal reassurance.

✓ Pass
Signable terms on roadmap continuity, SLA, residency and uplifts.
✗ Fail
'Nothing changes' with nothing on paper.
Reference: official docs

D

Evidence checklist & contractual follow-ups

Capture during the day

  • Screen recording of every gate demo (GATE 1–4 especially).
  • Raw API responses: the GATE 2 Management-API publish attempt; GATE 5 429 / Retry-After traces.
  • CDA/GROQ payloads for GATE 1 (before and after the HQ update).
  • Written commercial answers for GATE 8 (SLA, residency, TISAX/ISO, uplifts, roadmap).
  • Open-risk register: each failed/partial gate → owner + follow-up deadline.

Contractual / commercial follow-ups (Contentful)

  • Post-Salesforce roadmap, pricing and renewal protections — in writing.
  • API-level workflow-enforcement statement (can a CMA token bypass approval?).
  • Empty-string fallback guardrails for TMS/import round-trips.
  • EU data-residency reference architecture for a German OEM (storage vs processing).
  • SLA 99.99% as a contractual figure + rate-limit uplifts for migration.

E

Post-workshop scorecard

Fill this in before leaving the room, while the demos are fresh. Same template across all three vendors, so the three days are directly comparable. Circle one verdict per gate; a FAIL on GATE 1 or GATE 2 is decisive, not advisory.

GateVerdictEvidence captured (link / file)Owner & follow-up date
GATE 1Field-level HQ inheritance
PASSPARTIALFAIL
   
GATE 2API-enforced approval
PASSPARTIALFAIL
   
GATE 3Editor-grade visual preview
PASSPARTIALFAIL
   
GATE 4DAM / AEM Assets coexistence
PASSPARTIALFAIL
   
GATE 5Migration & cutover
PASSPARTIALFAIL
   
GATE 6China / CDN delivery
PASSPARTIALFAIL
   
GATE 7Exit & reversibility
PASSPARTIALFAIL
   
GATE 8Contractual signability
PASSPARTIALFAIL
   
DECISION RULE

Scores on the dossier are directional; the workshop is where the decision is actually made. GATE 1 (field-level inheritance after partial override) and GATE 2 (API-enforced approval) are pass/fail thresholds — a vendor that fails either is not a Phase-1 platform regardless of its weighted total. GATES 3–8 inform the contract and the build estimate.