About this template
A starting set of iPaaS requirements for a company choosing an integration platform to connect its applications and data: 42 requirements in 6 sections, from connectors and orchestration to monitoring, governance, scale and security.
It is written for IT, architecture and operations leaders who have to agree on one list before vendor demos shape it. Each section says why it matters; the rows are written to be scored, so every vendor answers the same question.
How to use it
Start with the sections, not the requirements. Decide which sections carry the most weight for your organization, then go through the rows in each one and drop what does not apply. A company with a few high-volume integrations will weigh performance and monitoring heavily; one enabling many teams to build their own integrations will put its weight on governance, lifecycle and security.
Put the same list to every vendor, in the same words, and ask for a score and evidence on each line. A requirement list only compares vendors fairly when every vendor answers the same questions. Olive's Requirements and Scoring and comparison pages show how the list becomes a scored comparison.
Building integrations
These three sections cover what the platform connects to, how integrations are designed and orchestrated, and what happens when they fail. They decide how quickly a new integration ships and how often someone is paged.
Connectors and APIs
7 requirementsA connector catalog is only as good as the maintenance behind it. Depth of each connector, support for your protocols and a clean path for custom endpoints decide how much you build yourself.
- Connector catalogMaintained connectors for the applications and databases in your landscape, with the catalog, versions and support status published.
- Connector depthConnectors expose the full object model and operations of the target application, including custom objects and fields.
- Protocol supportREST, SOAP, GraphQL, file transfer, message queues, databases and event streams supported natively.
- Custom connector developmentA documented kit for building and maintaining connectors to systems without one, reusable across integrations.
- API managementDesign, publish, secure and version your own APIs on the platform, with a developer portal and usage analytics.
- On-premises connectivityA secure agent for systems behind your firewall, without opening inbound ports.
- Schema discovery and mappingAutomatic discovery of source and target schemas with visual mapping, transformations and reusable mapping libraries.
Orchestration and workflow
7 requirementsReal integrations branch, wait, retry and transform. How the platform expresses that logic, and who can build it, decides whether integration is a bottleneck or a shared capability.
- Visual integration designerA low-code designer for flows with branching, loops, parallel steps and error paths, with the generated definition versionable.
- Code where neededScripting or code steps in common languages within a flow, with testing and dependency management.
- Event-driven and scheduled triggersFlows triggered by webhooks, events, queues, file arrival and schedules, with replay of missed events.
- Batch and real-time processingBoth high-volume batch and low-latency real-time patterns on one platform, with bulk APIs used where available.
- Data transformationMapping, enrichment, lookups, aggregation and format conversion with reusable functions and test data.
- Human tasks and approvalsSteps that wait for a person to approve or correct data, with notifications and escalation.
- Reusable componentsShared sub-flows, templates and connections reused across integrations and teams, with version control.
Monitoring and error handling
7 requirementsIntegrations fail quietly and are discovered when a report is wrong. Observability, alerting and a usable path to reprocess failed records are what keep failures small.
- Run history and tracingEvery execution logged with inputs, outputs, duration and step-level detail, searchable by record or correlation id.
- AlertingConfigurable alerts on failures, thresholds and missed schedules to email, chat and incident tools.
- Error handling and retriesRetry policies with backoff, dead-letter handling and compensation steps defined per flow.
- ReprocessingFailed records corrected and replayed from the console without re-running the whole batch.
- Operational dashboardsHealth, throughput, error rates and SLA status across all integrations, by environment.
- Log exportLogs and metrics exported to your observability platform in standard formats.
- Data lineageWhere a record came from and where it went, across flows, for troubleshooting and audit.
Running the platform
These three sections cover how integrations are governed through their lifecycle, how the platform performs as volumes grow, and how data in motion is secured. They are what the architecture team will be judged on in two years.
Governance and lifecycle
7 requirementsWhen many teams build integrations, the platform has to make the right way the easy way. Environments, version control, review and promotion pipelines keep the estate understandable.
- Environments and promotionSeparate development, test and production environments with controlled promotion and environment-specific configuration.
- Version control integrationIntegration definitions stored in your source control, with branching, review and history.
- CI/CD supportAutomated testing and deployment of integrations through pipelines, using documented tooling or APIs.
- Testing frameworkUnit and end-to-end testing of flows with mocked endpoints and test data, runnable in pipelines.
- Reusable connections and secretsConnections and credentials defined once, shared with permission and rotated without editing flows.
- Documentation and catalogAuto-generated documentation and a searchable catalog of integrations, owners and dependencies.
- Change managementApproval and change history for production changes, with rollback to a prior version.
Performance and scale
7 requirementsVolumes grow and peaks arrive on the busiest day of the year. Throughput, latency and the cost model under load are facts to test, not claims to accept.
- Throughput and latencyStated and testable throughput for batch and latency for real-time flows at your expected volumes, with a proof of concept offered.
- Elastic scalingCapacity scales with load automatically, with limits and the pricing impact of scale stated.
- Large payload and file handlingStreaming of large files and payloads without loading them whole into memory.
- Concurrency controlsRate limiting, throttling and ordering controls to respect target system limits and sequence-sensitive data.
- High availabilityRedundant runtime with a published availability commitment and failover that preserves in-flight work.
- Regional deploymentRuntime available in the regions your data must stay in, with routing by region.
- Pricing model clarityPricing by connection, task, volume or user explained, with a five-year projection at your growth.
Security and administration
7 requirementsThe integration platform touches every system's data and holds credentials to all of them. Its security posture is effectively the company's.
- Role-based access controlPermissions by role for designing, deploying, operating and viewing integrations, scoped by project or team.
- Single sign-on and MFASSO through your identity provider and multi-factor authentication enforced for every user.
- Secrets managementCredentials encrypted and stored in the platform's vault or your own, with rotation and no secrets in flow definitions.
- Encryption and data handlingData encrypted in transit and at rest, with options to avoid persisting payloads and to mask sensitive fields in logs.
- Audit trailA complete log of administrative actions, deployments and configuration changes retained for the compliance period.
- Compliance certificationsCurrent third-party certifications and reports shared, and data processing terms that meet your regulatory needs.
- Network securityPrivate connectivity options, IP allow-listing and a documented network model for agents and endpoints.
