Salesforce DevOps and Automated Testing Tool Solution - UPDATED

Agency: State Government of Tennessee
State: Tennessee
Type of Government: State & Local
NAICS Category:
  • 541511 - Custom Computer Programming Services
  • 541512 - Computer Systems Design Services
  • 541519 - Other Computer Related Services
Posted Date: Apr 20, 2026
Due Date: Apr 23, 2026
Solicitation No: RFI 31701-03828
Original Source: Please Login to View Page
Contact information: Please Login to View Page
Bid Documents: Please Login to View Page
Document ID & Hyperlink: RFI 31701-03828
Amendment 2
Amendment 1
Event Start - Response Due: 03/24/2026

04/23/2026
Event Name: Salesforce DevOps and Automated Testing Tool Solution - UPDATED
Last Updated: 04/20/2026

Attachment Preview

NO. REQUIREMENT TITLE REQUIREMENT DESCRIPTION VENDOR PROPOSED SOLUTION
For each Requirement below, describe
how the proposed solution fully meets
the requirement, is currently in
development, offers alternative

STATE OF TENNESSEE
FINANCE & ADMINISTRATION, STRATEGIC TECHNOLOGY SOLUTIONS
REQUEST FOR INFORMATION
FOR
SALESFORCE DEVOPS AND AUTOMATED TESTING TOOL SOLUTION
RFI # 31701-03828
March 24, 2026
1. STATEMENT OF PURPOSE:
The State of Tennessee, Finance and Administration, Strategic Technology Solutions (STS)
issues this Request for Information ("RFI") for the purpose of identifying a Salesforce DevOps and
automated testing tool solution partner. We appreciate your input and participation in this
process.
1.1. BACKGROUND: Salesforce is currently in use and is being adopted by a growing number
of agencies statewide. To safely and efficiently develop applications that support this
expanding set of use cases, the state requires a dedicated DevOps platform capable of
managing multiple, self-contained sandboxes for Development, QA, System Integration
Testing (SIT), and User Acceptance Testing (UAT) prior to production. To streamline
development cycles, improve deployment efficiency, and ensure consistent quality, the
DevOps platform must integrate directly with Salesforce. Given the complexity of Salesforce
customizations, automated testing is also essential to prevent regression and ensure the
reliability of changes.
2. PROPOSED SOLUTION(S): The State is seeking information on software solutions and
capabilities that currently exist from qualified vendors for a Salesforce DevOps and Automated
Testing Tool Solution. Table 3.1 below represents the State's List of Business Requirements for
which the vendor should provide proposed solutions in their response. In accordance with Section
7. Informational Forms, Technical Information Form Question 4, please demonstrate in your
response how your solution meets our requirements, if there is a feature that doesn't currently
meet the requirements, but is in development, or if your solution provides alternative functionality
that may yield a similar outcome.
Table 3.1: List of Business Requirements
VENDOR PROPOSED SOLUTION
For each Requirement below, describe
how the proposed solution fully meets
the requirement, is currently in
NO. REQUIREMENT TITLE REQUIREMENT DESCRIPTION development, offers alternative
Page | 1
31701-03828

functionality, or does not meet the requirement, and provide a brief description supporting your response.
1.0 FUNCTIONAL REQUIREMENTS
1.a. Continuous Integration Automated builds, code linting, and static
(CI) analysis on every commit.
1.b. Continuous Automated deployment pipelines supporting multi-stage environments (Dev, Test, Prod).
Delivery/Deployment Automated deployment pipelines supporting
(CD) multi-stage environments (Dev, Test, Prod).
1.c. Pipeline Management Ability to define pipelines using for version-
controllable, infrastructure-as-code
configuration.
1.d. Work Item Tracking Tools to manage backlogs, epics, user stories,
and tasks, such as Azure Boards.
1.e. Traceability End-to-end traceability from requirements to
code changes, builds, and releases.
1.f. Reporting Real-time dashboards to track sprint progress
and velocity.
1.g. Scalability Ability to handle large teams and high-
frequency deployment, with options for cloud-
Scalability hosted or self-hosted agents.
1.h. Build and Release Centralized repository to manage packages
1.h. Artifacts (e.g., Maven, npm, NuGet).
2.0 TECHNICAL REQUIREMENTS
2.a. Source Code Integration with Git for distributed version
Management control, branching, and pull request workflows.
2.b. Infrastructure as Code (IaC) Support for tools like Terraform or Ansible to
manage infrastructure through code, ensuring
consistency.
2.c. Containerization Support for container technologies such as
Docker and Kubernetes for orchestration.
2.d. Automated Testing Integration of automated test frameworks
within the CI/CD pipeline.
2.e. Manual Testing Capabilities to manage and execute manual
test cases, such as Azure Test Plans.
2.f. Security Scanning Automated security analysis (DevSecOps)
within the pipeline.
2.g. Observability Integrated monitoring to provide feedback on
application performance in production.
2.h. Telemetry Tools to monitor deployment success rates
2.h. Telemetry and application health.
2.i. Automated testing tool Native automated testing tools.
2.j. Primary and secondary Prefer (Primary) East coast and Secondary Mid-
hosting west (low latency and high accessibility).
3.0 SUPPORT REQUIREMENTS
functionality, or does not meet the
requirement, and provide a brief
description supporting your response.
Infrastructure as Code
(IaC)

functionality, or does not meet the
requirement, and provide a brief
description supporting your response.
1.0 FUNCTIONAL REQUIREMENTS
Continuous Integration Automated builds, code linting, and static
1.a. (CI) analysis on every commit.
Continuous
Delivery/Deployment Automated deployment pipelines supporting
1.b. (CD) multi-stage environments (Dev, Test, Prod).
Ability to define pipelines using for version-
controllable, infrastructure-as-code
1.c. Pipeline Management configuration.
Tools to manage backlogs, epics, user stories,
1.d. Work Item Tracking and tasks, such as Azure Boards.
End-to-end traceability from requirements to
1.e. Traceability code changes, builds, and releases.
Real-time dashboards to track sprint progress
1.f. Reporting and velocity.
Ability to handle large teams and high-
frequency deployment, with options for cloud-
1.g. Scalability hosted or self-hosted agents.
Build and Release Centralized repository to manage packages
1.h. Artifacts (e.g., Maven, npm, NuGet).
2.0 TECHNICAL REQUIREMENTS
Source Code Integration with Git for distributed version
2.a. Management control, branching, and pull request workflows.
Support for tools like Terraform or Ansible to
Infrastructure as Code manage infrastructure through code, ensuring
2.b. (IaC) consistency.
Support for container technologies such as
2.c. Containerization Docker and Kubernetes for orchestration.
Integration of automated test frameworks
2.d. Automated Testing within the CI/CD pipeline.
Capabilities to manage and execute manual
2.e. Manual Testing test cases, such as Azure Test Plans.
Automated security analysis (DevSecOps)
2.f. Security Scanning within the pipeline.
Integrated monitoring to provide feedback on
2.g. Observability application performance in production.
Tools to monitor deployment success rates
2.h. Telemetry and application health.
2.i. Automated testing tool Native automated testing tools.
Primary and secondary Prefer (Primary) East coast and Secondary Mid-
2.j. hosting west (low latency and high accessibility).
3.0 SUPPORT REQUIREMENTS

3.a. Training & Onboarding Availability of user training, documentation,
and onboarding support
3.b. SLA & Availability Clear service uptime commitments, e.g.,
99.9% availability
3.c. Technical Support 24/7 support options, multi-channel (email,
Technical Support phone, chat)
3.d. User Community & Online support portal with FAQs, guides, and
Knowledge Base user forums
3.e. Accessibility Compliance WCAG 2.1 Level AA, ADA, Section 508
compliance
4.0 SECURITY REQUIREMENTS
4.a. Identity and Access Management Role based access controls and integration
Identity and Access with Azure AD in conjunction with State Active
4.a. Management Directory services.
4.b. MFA Integration with State of TN SSO.
4.c. Separation of Prod and Use Test accounts for Non-Prod and Prod
Test Accounts accounts for Production.
4.d. Compliance Audit logs (Admin and tracking) for compliance
4.d. Compliance purposes.
4.e. Encryption Data encrypted in motion and at rest.
4.f. Audit Logs and Capability to log and monitor user activity for
Monitoring compliance and troubleshooting.
4.g. Compliance Support for SOC 2, ISO 27001, HIPAA, NIST
4.g. Certifications 800-53 and FedRAMP certifications
5.0 AI REQUIREMENTS
5.a. General Does this solution contain an AI model?
5.b. Hosting Is application hosted in the US?
5.c. Data What type(s) of data does the AI solution ingest
5.c. Data or create?
5.d. AI Training Does the AI model train from user data?
5.e. Opt Out Option How does the State of TN opt out of training the
AI model?
5.f. Model Training Who develops and trains the AI model: the
enterprise internally or a third-party/vendor?
5.g. Data Sensitivity Does this AI solution leverage a dataset for
training or fine tuning that contains sensitive
information?
5.h. Data Retention Policies Are there different data retention policies for
the user interface versus the API?
5.i. Human in the Loop Does the AI feedback process include human
re-enforcement (RLHF)?
5.j. Third Party Assessment Has a third-party AI assessment been
conducted? If yes, where are the results
available?

Availability of user training, documentation,
3.a. Training & Onboarding and onboarding support
Clear service uptime commitments, e.g.,
3.b. SLA & Availability 99.9% availability
24/7 support options, multi-channel (email,
3.c. Technical Support phone, chat)
User Community & Online support portal with FAQs, guides, and
3.d. Knowledge Base user forums
WCAG 2.1 Level AA, ADA, Section 508
3.e. Accessibility Compliance compliance
4.0 SECURITY REQUIREMENTS
Role based access controls and integration
Identity and Access with Azure AD in conjunction with State Active
4.a. Management Directory services.
4.b. MFA Integration with State of TN SSO.
Separation of Prod and Use Test accounts for Non-Prod and Prod
4.c. Test Accounts accounts for Production.
Audit logs (Admin and tracking) for compliance
4.d. Compliance purposes.
4.e. Encryption Data encrypted in motion and at rest.
Audit Logs and Capability to log and monitor user activity for
4.f. Monitoring compliance and troubleshooting.
Compliance Support for SOC 2, ISO 27001, HIPAA, NIST
4.g. Certifications 800-53 and FedRAMP certifications
5.0 AI REQUIREMENTS
5.a. General Does this solution contain an AI model?
5.b. Hosting Is application hosted in the US?
What type(s) of data does the AI solution ingest
5.c. Data or create?
5.d. AI Training Does the AI model train from user data?
How does the State of TN opt out of training the
5.e. Opt Out Option AI model?
Who develops and trains the AI model: the
5.f. Model Training enterprise internally or a third-party/vendor?
Does this AI solution leverage a dataset for
training or fine tuning that contains sensitive
5.g. Data Sensitivity information?
Are there different data retention policies for
5.h. Data Retention Policies the user interface versus the API?
Does the AI feedback process include human
5.i. Human in the Loop re-enforcement (RLHF)?
Has a third-party AI assessment been
conducted? If yes, where are the results
5.j. Third Party Assessment available?

EVENT DATE (all dates are State business days)
TIME
(Central
Time
Zone)
1. RFI Issued Tuesday, March 24, 2026
2. Written Questions & Comments Deadline 2:00 PM Tuesday, March 31, 2026
3. State Response to Written Questions & Comments Wednesday, April 8, 2026
4. RFI Response Deadline 2:00 PM Thursday, April 16, 2026
EVENT
DATE
(all dates are State business
days)

3. COMMUNICATIONS:
3.1. Please submit your response to this RFI to:
Shannon Keefe, Contract Specialist
Finance and Administration, Strategic Technology Solutions
901 Rep. John Lewis Way North, Nashville, TN 37243
(615) 350-4244
Shannon.Keefe@tn.gov
3.2. Please reference RFI #31701-03828 with all communications to this RFI.
3.3. Please limit all questions to one submission per vendor.
4. RFI SCHEDULE OF EVENTS:
EVENT TIME DATE
(Central (all dates are State business
Time days)
Zone)
1. RFI Issued Tuesday, March 24, 2026
2. Written Questions & Comments Deadline 2:00 PM Tuesday, March 31, 2026
State Response to Written Questions &
3. Wednesday, April 8, 2026
Comments
4. RFI Response Deadline 2:00 PM Thursday, April 16, 2026
5. GENERAL INFORMATION:
5.1. Please note that responding to this RFI is not a prerequisite for responding to any future
solicitations related to this project and a response to this RFI will not create any contract
rights. Responses to this RFI will become property of the State.
5.2. The information gathered during this RFI is part of an ongoing procurement. In order to
prevent an unfair advantage among potential respondents, the RFI responses will not be
available until after the completion of evaluation of any responses, proposals, or bids
resulting from a Request for Qualifications, Request for Proposals, Invitation to Bid or other
procurement methods. In the event that the state chooses not to go further in the
procurement process and responses are never evaluated, the responses to the
procurement, including the responses to the RFI, will be considered confidential by the
State.
5.3. The State will not pay for any costs associated with responding to this RFI.
5.4. Any services or products proposed in this RFI, must be in compliance with the following
security policy: all State data must remain in the United States, regardless of whether the
data is processed, stored, in-transit, or at rest. Access to State data shall be limited to US-

RFI #31701-03828
TECHNICAL INFORMATIONAL FORM
1. RESPONDENT LEGAL ENTITY NAME:
2. RESPONDENT CONTACT PERSON: Name, Title: Address: Phone Number: Email:
3. Provide a brief description of company background and experience providing similar scope of solutions that have been implemented in other states or local governments.
4. For each requirement in Table 3.1: List of Business Requirements, indicate whether your solution Meets, Is In Development, Provides Alternate Functionality, or Does Not Meet the requirement and briefly describe how your solution supports the intended outcome.
5. Describe your solution's security and privacy controls: * Role-based access control (RBAC) * Multi-factor authentication (MFA) * Data encryption in transit and at rest * Data storage and retention policies * Compliance with State privacy and cybersecurity frameworks * Supported industry-standard authentication and authorization protocols (e.g., OAuth 2.0, SAML 2.0, etc.) * FedRAMP compliant * GovCloud complaint Summarize any other adherence to privacy, security, and data governance standards, including strategies and SLAs to mitigate system disruptions during implementation.
6. Provide an overall project timeline to implement a solution that meets the List of Business Requirements in Table 3.1 of this RFI, including phases, milestones, and State resource obligations in each step. Please include knowledge transfer, training and post-implementation technical support into your timeline.
7. Outline your technical roadmap for enterprise-wide adoption of your solution.

based (onshore) resources only. Configuration or development of software and code is
permitted outside of the United States, however, software applications designed,
developed, manufactured, or supplied by persons owned or controlled by, or subject to the
jurisdiction or direction of, a foreign adversary, which the U.S. Secretary of Commerce
acting pursuant to 15 C.F.R. 7 has defined to include the People's Republic of China,
among others are prohibited. Any testing of code outside of the United States must use fake
data. A copy of production data may not be transmitted or used outside the United States.
5.5. The State may request demo presentations from selected RFI respondents.
5.6. Responses should be prepared, with emphasis on completeness and clarity, and should
NOT exceed fifteen (15) pages total in length. Responses, as well as any reference material
presented, must be written in English, and must be written on standard 8 12" x 11" pages
and all text must be at least a 12-point font. All pages must be numbered.
6. INFORMATIONAL FORMS:
The State is requesting the following information from all interested parties. Please fill out the
following forms:
RFI #31701-03828
TECHNICAL INFORMATIONAL FORM
1. RESPONDENT LEGAL ENTITY NAME:
2. RESPONDENT CONTACT PERSON:
Name, Title:
Address:
Phone Number:
Email:
3. Provide a brief description of company background and experience providing similar scope of
solutions that have been implemented in other states or local governments.
4. For each requirement in Table 3.1: List of Business Requirements, indicate whether your
solution Meets, Is In Development, Provides Alternate Functionality, or Does Not Meet the
requirement and briefly describe how your solution supports the intended outcome.
5. Describe your solution's security and privacy controls:
* Role-based access control (RBAC)
* Multi-factor authentication (MFA)
* Data encryption in transit and at rest
* Data storage and retention policies
* Compliance with State privacy and cybersecurity frameworks
* Supported industry-standard authentication and authorization protocols (e.g., OAuth 2.0,
SAML 2.0, etc.)
* FedRAMP compliant
* GovCloud complaint
Summarize any other adherence to privacy, security, and data governance standards,
including strategies and SLAs to mitigate system disruptions during implementation.
6. Provide an overall project timeline to implement a solution that meets the List of Business
Requirements in Table 3.1 of this RFI, including phases, milestones, and State resource
obligations in each step. Please include knowledge transfer, training and post-implementation
technical support into your timeline.
7. Outline your technical roadmap for enterprise-wide adoption of your solution.

8. Describe your solution's training, knowledge transfer and support plan?
9. Describe any risks and/or challenges and potential mitigation strategies that you would advise the State to consider when implementing an enterprise-wide Salesforce DevOps automated testing solution(s).
10. Is your solution available for purchase through public sector cooperative agreements (NASPO, GSA, etc.)?
COST INFORMATIONAL FORM
1. Describe your pricing model (e.g., subscription/license-based, usage-based, per-org/per- environment) and identify any cost differentiations that are role-based.
2. What units of measure drive cost (users, Salesforce orgs, sandboxes, pipelines, code volume, integrations, etc.)?
3. Please provide a typical cost estimate that aligns with proposed project phases for the State to procure all necessary licensing to fully implement an enterprise-wide solution. Identify if pricing is standardized or negotiable for an enterprise, government solution. Provide a breakdown of cost for any additional fees, such as configuration, migration, implementation, onboarding, training, support, maintenance, etc.
4. What insight can you provide into licensing costs and expected increases year-over-year?
ADDITIONAL CONSIDERATIONS
1. Please provide input on alternative approaches or additional things to consider that might benefit the State:

8. Describe your solution's training, knowledge transfer and support plan?
9. Describe any risks and/or challenges and potential mitigation strategies that you would advise
the State to consider when implementing an enterprise-wide Salesforce DevOps automated
testing solution(s).
10. Is your solution available for purchase through public sector cooperative agreements (NASPO,
GSA, etc.)?
COST INFORMATIONAL FORM
1. Describe your pricing model (e.g., subscription/license-based, usage-based, per-org/per-
environment) and identify any cost differentiations that are role-based.
2. What units of measure drive cost (users, Salesforce orgs, sandboxes, pipelines, code volume,
integrations, etc.)?
3. Please provide a typical cost estimate that aligns with proposed project phases for the State to
procure all necessary licensing to fully implement an enterprise-wide solution. Identify if pricing is
standardized or negotiable for an enterprise, government solution. Provide a breakdown of cost for
any additional fees, such as configuration, migration, implementation, onboarding, training,
support, maintenance, etc.
4. What insight can you provide into licensing costs and expected increases year-over-year?
ADDITIONAL CONSIDERATIONS
1. Please provide input on alternative approaches or additional things to consider that might benefit
the State:

This page summarizes the opportunity, including an overview and a preview of the attached documents.
* Disclaimer: This website provides information about bids, requests for proposals (RFPs), or requests for qualifications (RFQs) for convenience only and does not serve as an official public notice. Individuals who wish to respond to or inquire about bids, RFPs, or RFQs should contact the relevant government department directly.

Sign-up for a Free Trial, Government Bid Alerts

With Free Trial, you can:

You will have a full access to bids, website, and receive daily bid report via email and web.

Try One Week FREE Now

See Also

Form Details (Abstract): RFQ 1803575 Status Active Document PDF File Abstract Negotiation Number

Memphis Light

Bid Due: 7/28/2026

Document ID & Hyperlink: RFP 34320-19527 Solicitation Notice Event Start - Response Due:

State Government of Tennessee

Bid Due: 8/14/2026

Document ID & Hyperlink: RFI 33901-21200 Event Start - Response Due: 07/20/2026 08/20/2026

State Government of Tennessee

Bid Due: 8/20/2026

Follow Unify OpenScape Voice Console Active Contract Opportunity Notice ID W50S9926Q1104 Related Notice

DEPT OF DEFENSE

Bid Due: 7/28/2026