Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should startups use customer discovery to shape…
Identity Beyond IAM

How should startups use customer discovery to shape pricing?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Identity Beyond IAM

Start by asking buyers what outcome they value, what problem they need solved, and what metric would fairly represent that value. Then test whether their answers support a simple pricing model that is easy to explain, forecast, and defend. Discovery should inform packaging, not just product direction, because willingness to pay is a market signal, not a guess.

Why This Matters for Security Teams

customer discovery shapes pricing because it reveals what buyers actually pay for: outcomes, risk reduction, convenience, compliance, or time saved. Startups that skip discovery often price around internal costs or competitor anchors, then learn too late that the market values a different unit of value. NHI Management Group’s Ultimate Guide to NHIs — Key Challenges and Risks shows how hidden identity risk becomes expensive when visibility is weak, and the same pattern applies to pricing: unseen value leads to weak monetisation.

For security and infrastructure products, pricing must be defensible to procurement, simple enough for finance, and aligned with how buyers measure success. That means discovery should test whether the buyer’s language maps to a pricing unit that scales with value instead of friction. The NIST Cybersecurity Framework 2.0 is not a pricing guide, but its emphasis on governance and repeatability mirrors the discipline needed here: define the decision, document the rationale, and make the model explainable.

In practice, many startups discover pricing mistakes only after pilots convert poorly or sales cycles stall, rather than through intentional validation of willingness to pay.

How It Works in Practice

Customer discovery should move beyond feature questions and into value architecture. The goal is to identify the buyer’s job to be done, the metric they already care about, and the purchasing constraint that will shape the deal. For example, a team may say they need “more seats,” but discovery may reveal that the real value is fewer incidents, faster onboarding, or lower audit effort. That distinction determines whether pricing should be per seat, per environment, per workflow, per asset, or per outcome.

Strong discovery typically tests four things:

  • What event triggered the search for a solution.
  • Which metric the buyer already uses to judge success.
  • What budget category the purchase would come from.
  • Which pricing model would feel fair and predictable.

For products tied to identity, access, or security operations, it often helps to compare discovery answers against lifecycle realities. The NHI Lifecycle Management Guide and Top 10 NHI Issues show that operational pain is often concentrated in onboarding, rotation, visibility, and offboarding. If customers consistently describe pain at those points, pricing can be tied to the number of identities, integrations, or protected workloads. That makes the model easier to forecast and easier to justify internally.

Discovery should also surface whether a pricing metric creates perverse incentives. A usage metric that punishes success can slow adoption, while a flat fee can undercharge high-value customers and overcharge low-value ones. The best early-stage approach is usually to prototype two or three pricing models in interviews, then look for the one buyers can repeat back without confusion. These controls tend to break down when the product is sold into enterprises with multiple buying centers because the stated value differs sharply between the technical evaluator, the budget owner, and procurement.

Common Variations and Edge Cases

Tighter pricing alignment often increases the complexity of sales conversations, requiring organisations to balance clarity against nuance. Not every startup should price by usage or outcomes, and current guidance suggests there is no universal standard for this yet. If the product is early, a simple subscription may be better than a sophisticated value metric that customers do not trust or cannot forecast.

Some edge cases deserve special handling. In highly regulated markets, buyers may value auditability more than raw efficiency, so pricing can reflect compliance scope or protected environment count rather than transaction volume. In platform products, discovery may reveal that value is concentrated in a core system of record, but expansion happens through adjacent teams. In those cases, packaging can start narrow and expand by module, rather than forcing a single all-in metric.

One useful test is whether the buyer can explain the price to a colleague in one sentence. If not, the model may be too clever. Another is whether the buyer’s preferred metric can be measured consistently without manual interpretation. If the answer depends on subjective estimates, the model will create friction later in billing and renewals. NHI Management Group’s research on identity lifecycle risk reinforces the broader lesson: weak operational visibility creates weak control, and weak value visibility creates weak pricing discipline.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org