Skip to content
SalesforceSkills

RFP Response

Read and respond to RFPs, RFIs, and security questionnaires. AI parses requirements, generates Salesforce-specific responses, flags risk areas, and produces a compliance response matrix.

Skill Details

Install this skill

Versionv1.0.0AuthorJorge ArteagaLicenseMITSections13

Works with

Claude CodeCursorWindsurf

When This Skill Owns the TaskWorkflow

Required Context to Gather FirstWorkflow

Before responding to an RFP, ask for or infer:

1
RFP document or key sections — What are they asking? Share the requirements.
2
Salesforce products in scope — Which clouds are we proposing?
3
Submission deadline — When is this due? Is it realistic to respond well?
4
Bid/no-bid decision — Has someone qualified this as worth pursuing?
5
Known relationships — Do we know anyone at the organization? Is there a preferred vendor?
6
Win themes — What are our 2-3 strategic advantages in this bid?
7
Subject matter experts — What internal resources (product, security, legal) do we need?

WorkflowWorkflow

1
Bid/No-Bid Assessment — Apply the qualifier table before writing a word.
2
Parse the RFP — Categorize requirements into sections (functional, technical, security, commercial).
3
Set the win themes — Identify 2-3 strategic messages that run through every answer.
4
Draft responses — For each requirement, apply the STAR format (Situation, Task, Action, Result).
5
Flag risk items — Mark requirements where Salesforce doesn't fully comply or needs to caveat.
6
Handle "no" gracefully — For gaps, apply the "bridge" strategy rather than a flat no.
7
Build the response matrix — Compile all responses with compliance indicators.
8
Review before submitting — Apply the scoring rubric; fix anything below 80%.

Core Frameworks

Bid/No-Bid Qualifier

Score each criterion 0-2. Total below 8 = consider no-bid.

Total Score:

  • 10-12: Pursue aggressively
  • 6-9: Pursue with resource caps
  • Below 6: No-bid; write a respectful decline

Response Formatting Rules

Every RFP response should follow these rules:

1
Mirror the requirement language — Use the same terminology they used in the requirement.
2
Lead with compliance — Start with "Yes" or "Salesforce fully supports..." before explanation.
3
Prove it, don't just say it — Every capability claim needs evidence (Salesforce documentation URL, customer reference, or named feature).
4
Right-size the response — Match length to question importance. "Do you support SSO?" = 2 sentences. "Describe your data governance approach" = 2 paragraphs.
5
Avoid generic marketing language — "Salesforce is the world's #1 CRM" does not answer the question.

The STAR Response Format

For narrative/functional requirements:

Code
SITUATION: Briefly set the context for Salesforce's capability in this area.
TASK: What specific capability or function addresses this requirement?
ACTION: How does the feature work? (Brief mechanics, not a manual)
RESULT: What outcome can the customer expect? Include a reference if possible.

Handling Gaps: The Bridge Strategy

When Salesforce doesn't fully meet a requirement, never write "No" without a bridge:

Code
Structure:
"While Salesforce [what it does or doesn't do natively], customers achieve
[requirement outcome] by [alternative approach / configuration / partner solution / roadmap].
[Customer reference] is an example of this approach."

Compliance indicator: "Partial" or "Via Partner" rather than "No"

Example:

Requirement: "Does the system support real-time bidirectional sync with SAP S/4HANA?"

>

Response: "While Salesforce does not ship a native SAP S/4HANA connector, real-time bidirectional sync is achieved through Salesforce's MuleSoft integration platform or certified AppExchange ISV connectors, including [MuleSoft Accelerator for SAP / Jitterbit / SnapLogic]. These are production deployments trusted by over [X] Salesforce customers with SAP environments."

Security Questionnaire Quick Reference

Common security questions and Salesforce's standard responses:

Output FormatTemplate

RFP Response Matrix

MARKDOWN
# RFP Response Matrix — [RFP Name]
**Issuer:** [Company] | **Due:** [Date] | **SE:** [Name] | **AE:** [Name]

## Win Themes
1. [Win Theme 1 — the strategic message that runs through all responses]
2. [Win Theme 2]
3. [Win Theme 3]

## Response Summary

| Req # | Requirement Summary | Compliance | Response Status |
|-------|---------------------|------------|----------------|
| [X] | [Brief description] | Full / Partial / No / Via Partner | Draft / Complete / Review |

## Detailed Responses

### Section [X]: [Section Name]

**Requirement [X.1]:** [Full requirement text]
**Compliance:** [Full / Partial / No / Via Partner / On Roadmap]
**Response:**
[STAR-format response]
**References:** [Link, customer name, or doc]

---

## Risk Register

| Req # | Risk Description | Severity | Bridge Strategy |
|-------|-----------------|---------|----------------|
| [X] | [What we can't do or caveating] | H/M/L | [Alternative approach] |

## Recommended Appendices
- [ ] Company overview (1 page)
- [ ] Implementation methodology
- [ ] Customer references (3 minimum; in same industry preferred)
- [ ] Security documentation (SOC 2, ISO certifications)
- [ ] Pricing / commercial proposal

Anti-PatternsReference

Scoring Rubric (100 Points)Reference

Cross-Skill IntegrationReference

TaskThis SkillDefer To
Respond to RFP/RFI requirementsYes
Assess whether to bidYes
Answer security questionnaires (SIG, CAIQ)Yes
Flag risks and "no" strategiesYes
Design the proposed solution architectureNosf-se-whiteboard
Build a proactive business case without an RFPNosf-se-proof-of-value
Write the presentation for the orals/demo phaseNosf-se-presentation
Criterion012
RelationshipNo contacts; cold RFPOne contact, limited accessChampion or exec sponsor inside
Technical FitCore requirements are gapsMostly fits; 2-3 gapsStrong fit; Salesforce is purpose-built for this
Competitive PositionLikely incumbent is not SalesforceLevel playing fieldWe have advantages; they've seen Salesforce
Strategic ValueSmall deal; no logo valueAverage dealMarquee customer; strategic industry
Win ProbabilityBelow 20%20-50%Above 50%
Resources AvailableNo SE/PS capacityStretchedDedicated pursuit team available
Question AreaSalesforce Position
Data residencySalesforce supports data residency in EU, US, APAC, and others via Hyperforce
Encryption at restAES-256 encryption at rest for all data
Encryption in transitTLS 1.2/1.3 for all data in transit
SOC 2 Type IIYes — available at trust.salesforce.com
ISO 27001Yes — Salesforce is ISO 27001 certified
GDPR complianceSalesforce acts as a data processor; DPA available
Penetration testingAnnual third-party pen tests; customer pen testing allowed with permission
Uptime SLA99.9% for production environments
MFA enforcementMandatory MFA available; can be enforced org-wide
Audit logsEvent Monitoring add-on provides full audit trail
Anti-PatternWhy It FailsFix
Responding to every RFP that comes inLow-quality responses consume SE time with little returnAlways do the bid/no-bid assessment first
Writing generic responses that don't address the specific requirementEvaluators notice; scores dropMirror the requirement's exact language; answer what was asked
Saying "No" without a bridgeEliminates Salesforce from consideration for a solvable gapAlways provide an alternative path: partner, configuration, or roadmap
Copying from the last RFP verbatimDates, customer names, and context mismatch; looks carelessReuse structure, not specific answers — always refresh with current evidence
Overpromising on roadmap items"Coming soon" responses create legal and relationship risk if features don't shipOnly reference roadmap items that are publicly announced; caveat clearly
Skipping the win themesResponses are a list of facts with no strategic threadDefine 2-3 win themes before writing anything; thread them through every answer
Long responses to simple binary questionsEvaluators have hundreds of questions to read; oversized answers waste their timeMatch response length to question complexity
CategoryPointsPass Criteria
Compliance Coverage25Every requirement has a compliance indicator and a response
Response Quality25Responses are specific, evidence-backed, and mirror requirement language
Risk Handling20All gaps have a bridge strategy; no flat "No" responses
Win Theme Consistency15Win themes appear throughout the narrative responses
Completeness15All requested appendices (references, security docs) are assembled
SkillWhen to Use It
sf-se-whiteboardDesign the solution architecture that the RFP proposes
sf-se-architecture-reviewUse to develop the technical response section
sf-se-proof-of-valueAdd ROI and business case data to the value proposition section
sf-se-presentationBuild the orals / demo presentation that follows the written RFP
sf-se-competitiveCraft win themes that position Salesforce vs. the likely shortlist

Navigate Proposals & Research