The day at a glance
A ~8.5-hour working session, structured around the eight non-negotiable gates. Every critical question is run as “show us”, not “do you support…”. The output of the day is evidence — recordings, logs, API responses — and a completed scorecard, not a feeling.
Vendor confirms it understands the HQ→market model and the eight gates below.
Live demo: partial override + later HQ update. Capture CDA/GROQ payloads before & after.
Demo in UI, then attempt publish with a Management-API token. Capture the enforcement response.
Real BMW-like preview: inherited vs overridden fields, market/locale, approval state.
Asset reference, expiry/replacement, usage tracking, pre-publish stale-asset warning.
Environment model, re-runnable import, rate limits, rollback — with real 429/Retry-After logs.
Answers that go into the contract/RFP, not just the chat: SLA, residency, TISAX/ISO, uplifts.
Only as far as BMW's Phase-1 scope requires — do not let it consume the day.
Pass/fail per gate, open-risk owner + follow-up deadline, contractual to-dos.
Read-in: where Contentstack stands going in
Our position from the documented evidence in the shared dossier (verified against official docs, two passes 2026-07-06/07). The workshop confirms or overturns it — that is the point.
Top strengths
- Fully native enforced approvalPublish rules gate publishing on a named stage; approvers by user or role; four-eyes prevents self-approval; scoped per branch/environment/locale. docs
- Best permission granularityCustom roles scope by content type, specific entries, field, language variant, environment, taxonomy term and asset folder — plus a SCIM API (beta). docs
- Native personalization + CDP + 500-field headroomPersonalize (audiences, variants, A/B, multi-armed bandit) on the Lytics CDP; 500 fields per content type vs Contentful's 50. docs
Top risks / where the bodies are buried
- Localization detaches the entry — permanently“The inheritance of the entry is broken from the fallback language and it, therefore, becomes independent.” The moment a market edits one field, empty fields stop following HQ. This is the field-level requirement failing. docs
- CMA writes are 10 req/s per ORGANIZATIONNot per stack — every stack, integration and import job across BMW + MINI shares one 10 req/s write budget; bulk ops run at 1 req/s. docs
- Compliance + consistency gapsNo TISAX on the trust page; standard SLA is 99.50% (99.95% only on Scale/X5); docs say 3 environments / 2 branches per stack while the legal terms say 5/5; release & webhook fan-out behavior is undocumented. docs
Live demo scripts — the eight gates
Each gate is a script: setup → show-us steps → expected evidence → pass/fail. Run them in order; GATES 1 and 2 are the ones that decide Contentstack. Don't accept a verbal answer where a demo is written.
Field-level HQ inheritance
90 minA stack with a master locale + de-DE; a car entry not yet localized into de-DE.
- GET the de-DE entry with include_fallback=true → it serves master content (inheritance working while unlocalized).
- The decisive step: localize de-DE and change exactly ONE field (price). Save.
- Update the master image. GET de-DE again → show whether the still-empty DE image follows the new master (expected: it does NOT — the entry has detached).
- Ask for the official pattern for 'override one field, keep inheriting the rest' — fragment entries? a delivery-layer merge?
Payloads before/after localization proving detachment, plus the vendor's recommended partial-override pattern.
API-enforced approval
90 minA workflow with a Draft→Reviewed→Approved→Published stage set; a publish rule requiring the Approved stage before publish; four-eyes enabled; only a Market-Lead role can move Reviewed→Approved.
- As an editor in the UI, attempt to publish a Draft entry → expect it blocked by the publish rule.
- With a Management-API token, attempt to publish the pre-Approved entry → capture the response (expected: blocked by the publish rule).
- As the last editor, attempt to approve/publish your own entry → expect four-eyes to block it.
- Confirm the role-gated Reviewed→Approved transition and that Publish Rules are included in BMW's plan tier.
The CMA rejection response + the four-eyes block + confirmation the feature is in-plan.
Editor-grade visual preview
60 minVisual Builder + Live Preview wired to a BMW-like page; Timeline for scheduled releases.
- Open Visual Builder on the page; switch market/locale and device.
- Show inherited-vs-overridden field visibility and the entry's workflow stage.
- Preview a scheduled release via Timeline (draft/approved/published comparison).
A screen recording; confirmation of the Live Preview SDK plan gating.
DAM / AEM Assets coexistence
60 minAn entry referencing an external asset + a stale asset.
- Reference the external asset (or the Interstack asset-sharing pattern) and deliver it.
- Show usage tracking ('where used') and expiry/replacement.
- Attempt to publish with the stale asset → expect a warning.
A working external reference + usage/expiry demonstration or a bounded custom plan.
Migration & cutover
60 minTwo stacks in one organization; a scripted import into each.
- Run a re-runnable import → show idempotency.
- Write to two stacks simultaneously at full tilt → show that they share the org-wide 10 req/s budget (and bulk ops the 1 req/s budget); capture 429s.
- Show the branch model: merge covers content types + global fields only (entries never merge back); confirm 3-vs-5 environments and 2-vs-5 branches against the plan.
429 traces proving the org-wide ceiling; the branch-merge limitation demonstrated.
China / CDN delivery
45 minA published entry through the CDN; BMW's Akamai in front.
- Publish → measure publish-to-edge propagation.
- Ask for the mainland-China delivery story on the multi-cloud (AWS/Azure/GCP) footprint.
- Show cache invalidation for BMW's Akamai and the webhook reliability model.
A propagation number + a written China plan + the invalidation mechanism.
Exit & reversibility
45 minThe demo stack with workflows, roles and personalization config.
- Run cm:stacks:export → confirm content types, entries, assets, global fields, workflows, roles, taxonomy, personalize are present.
- Confirm the exclusions: Users and Releases; note the 100 MB per-item content-length default.
- Ask about converting the proprietary JSON RTE / modular blocks to another platform.
An export tree + explicit exclusions.
Contractual signability
60 minCommercial / legal stakeholders in the room.
- Get the official partial-override-with-continued-inheritance pattern in writing (ties to GATE 1).
- Get contractual rate-limit uplifts (the org-wide 10 req/s), a TISAX plan + date, and resolution of the 3-vs-5 environments / 2-vs-5 branches contradiction.
- Confirm release item caps (500/release, 25/API call) and the release-deploy webhook behavior; confirm Publish Rules and Personalize plan inclusion + Lytics event-based pricing.
Written answers for the contract/RFP.
Evidence checklist & contractual follow-ups
Capture during the day
- Screen recording of every gate demo (GATE 1–4 especially).
- Raw API responses: the GATE 2 Management-API publish attempt; GATE 5 429 / Retry-After traces.
- CDA/GROQ payloads for GATE 1 (before and after the HQ update).
- Written commercial answers for GATE 8 (SLA, residency, TISAX/ISO, uplifts, roadmap).
- Open-risk register: each failed/partial gate → owner + follow-up deadline.
Contractual / commercial follow-ups (Contentstack)
- Official partial-override + continued-inheritance pattern — in writing (GATE 1).
- Contractual rate-limit uplifts above the org-wide 10 req/s write ceiling.
- TISAX assessment plan + date (absent from the trust page today).
- Resolve the docs-vs-legal contradiction: 3 vs 5 environments, 2 vs 5 branches per stack.
- Release item caps + release-deploy webhook behavior; Publish Rules & Personalize plan inclusion.
Post-workshop scorecard
Fill this in before leaving the room, while the demos are fresh. Same template across all three vendors, so the three days are directly comparable. Circle one verdict per gate; a FAIL on GATE 1 or GATE 2 is decisive, not advisory.
| Gate | Verdict | Evidence captured (link / file) | Owner & follow-up date |
|---|---|---|---|
| GATE 1Field-level HQ inheritance | PASSPARTIALFAIL |
||
| GATE 2API-enforced approval | PASSPARTIALFAIL |
||
| GATE 3Editor-grade visual preview | PASSPARTIALFAIL |
||
| GATE 4DAM / AEM Assets coexistence | PASSPARTIALFAIL |
||
| GATE 5Migration & cutover | PASSPARTIALFAIL |
||
| GATE 6China / CDN delivery | PASSPARTIALFAIL |
||
| GATE 7Exit & reversibility | PASSPARTIALFAIL |
||
| GATE 8Contractual signability | PASSPARTIALFAIL |
Scores on the dossier are directional; the workshop is where the decision is actually made. GATE 1 (field-level inheritance after partial override) and GATE 2 (API-enforced approval) are pass/fail thresholds — a vendor that fails either is not a Phase-1 platform regardless of its weighted total. GATES 3–8 inform the contract and the build estimate.