- Who is the buyer? Typically they are not same as the user of the product so understand what they look for in similar products.
- SSO, preferably SAML based.
- As for security, take care of OWASP top-10 [1] and you should be covered for app-sec.
- Implement RBAC. Make it easy to add/manage users for an admin-user.
- Setup a demo account in sandbox, fill it with data as close to real world as possible. Makes it super easy during sale pitch. You let your product talk instead of you.
- Consider multi-tenancy from right off the bat. It's hard to add it later.
- Look up your domain specific compliance requirements and build those from ground up. Some such as SOC 2 don't hurt. While at it, get a decent security vendor to pen-test your product, work with them to fix high/medium priority issues and get them to issue certificate. It builds credibility with customers.
- Reports. Typically the admins will require a bunch of reports. It's best to give them a CSV/Excel download and let them slice and dice in their spread sheet software.
- Users will make mistakes so always use soft-delete. You can always do hard-delete after a few months.