Opens in a new tab
News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
3141f607 ddc5 4436 a564 3980de7c9057

Nobody Owns What Your Clients Build
Software that businesses used to buy, they’re starting to build.

Start with McKinsey’s State of AI survey. Nearly a third of respondents, thirty-two percent, say their organization decided against buying at least one software product or feature because it could build the functionality in-house with AI coding agents. Among the companies McKinsey calls AI high performers, it’s nearly half. The survey covered more than seventeen hundred participants, and McKinsey says the shift could be a sign that AI is beginning to reshape how technology budgets get spent.

Those are large organizations. Further down the market, Shree Amujala, who runs a managed service provider in Silicon Valley, writes in CIO that small businesses used to ask him whether they should look at AI. Now they tell him their employees already opened ChatGPT or Claude. He cites Bluevine, a small-business banking platform: seventy-four percent of small business owners are using or testing AI. And among Bluevine’s own customers, Claude users grew seven hundred twenty-nine percent in a year. That measures adoption, not software anyone has finished building. Keep that distinction in mind.

The plumbing for small builders is arriving as a product. GoDaddy launched hosting for web apps that customers built themselves, hired a freelancer for, or made with an AI coding tool. Coding agents can create, deploy and manage those apps entirely through GoDaddy’s API. That’s GoDaddy’s own announcement.

And the builders include MSPs, starting with the system at the center of the business. On this show, Brian J. Weiss, CEO of ITECH Solutions, walked through replacing his own PSA. His eleven-person shop ran a commercial PSA for about eight years. It ended up with six or seven tools bolted on to do what he felt the PSA should have done out of the box. Now it’s building a replacement on Microsoft Dynamics. Techstack supplies the PSA layer, and ITECH owns its own customized layer on top, inside its own tenant. Weiss is customer zero, a design partner and has an interest in Techstack, so weigh his view with that in mind.

It reaches the technicians too. Thread, which sells service management software to MSPs, says that at WheelHouse IT, twenty-five technicians, not engineers, built more than seventy automations in eight weeks. Those cover ninety percent of the shop’s Microsoft 365 workload. Those are Thread’s numbers.

So the buyer is becoming the builder. At the enterprise, at the small business, and inside the service provider.

Which raises the part nobody prices in when they decide to build: what happens after it ships.

Cheap To Build, Costly To Own
Building software was never the expensive part. Keeping it running was.

Brian J. Weiss knows that from his own shop’s history. When ITECH started in 2005, it had its own development team. It built its own ticketing system, its own password manager, its own documentation system. About ten years later, those developers were busy with paying client projects and couldn’t keep the homegrown tools current. So ITECH bought a PSA. The build wasn’t what failed. The upkeep was.

That’s what a software purchase actually buys. The product is the visible part. The patching, the security review, the fixes when something underneath changes: that’s the vendor’s job, and it’s folded into the subscription.

AI changes one side of that and not the other. The Association for Computing Machinery published a brief finding that AI-generated code is arriving faster than open source maintainers can check it, as Channel Dive reports. Agents can change code easily. Keeping up with those changes is the hard part. Co-author Shrinivass A.B. says that as generating software gets easier, the work shifts to verification. It also shifts to the question of “who is accountable for maintaining it.”

You might say that’s a problem for amateurs. Look at how it goes for the best-resourced builders in the world. In the weeks before Meta launched its Muse agent, engineers found several security flaws, 404 Media reports, citing a Meta source and internal documents. At least one could have let an ordinary user break out of Muse’s virtual machine and reach Meta’s sensitive internal databases. It went up to Mark Zuckerberg, and teams worked nights and weekends. The hardening push started eleven days before launch. Meta says it strengthened Muse through red teaming and its bug bounty, and that the work continues.

And OpenAI is still working out what its own agents did. After its test models broke into Hugging Face, OpenAI told a security conference it had spent three million GPU hours investigating, running Codex and other agents across more than seven billion logs. Three infrastructure experts told Fortune that’s somewhere between four and fifteen million dollars in compute. The company that built the agents needed agents to audit them.

In plain terms, AI made writing software nearly free and left the cost of owning it right where it was. When you buy, the vendor carries that cost. When you build, someone else has to. And if nobody is named, it lands wherever the software runs.

For most of your clients, that’s somewhere you’re already responsible for.

The Layer Only You Control
For an MSP, that cost arrives without an invoice attached. A client builds an app. It runs on a laptop you manage, signs in with an account you administer, and reaches data you’re responsible for protecting. There’s no vendor to call. The control that still works sits outside the software: what the device lets it touch, and which identity it runs as. That’s your layer.

Look at what the platform owner did when it decided it couldn’t trust the software running on it. Apple says it will add new controls around macOS Full Disk Access, the setting that lets an app read a user’s files, mail, messages and browsing history. Apple says some developers use it in ways that expose everything on a system without users understanding. It also says that as AI agents become more capable, the risk will grow substantially. Its answer isn’t a fix inside anyone’s agent. It’s a permission at the operating system that will require very explicit user action. TechCrunch notes that’s informed consent, not a new limit. But it shows where the decision lands when the builder can’t be trusted: the layer underneath.

Now look at who’s actually holding that layer. VentureBeat surveyed organizations with a hundred or more employees on how they secure their AI agents. Of the hundred and six that named a primary security layer, ninety-nine percent rely on a model or cloud provider, with OpenAI’s own guardrails alone at forty percent. Specialist security and identity vendors, whose controls sit apart from the platform the agent runs on, came in at about one percent. And among companies with agents in production, sixty-two percent run some or all of them on shared keys or a person’s login. That’s VentureBeat’s own sample of its readers, so it’s small and self-selected. But the shape is clear. The control outside the builder is mostly empty, and identity is where the gap is widest.

So here’s the choice. Treat every tool a client builds, and every one you build, as something you issue an identity to: its own account, scoped permissions, a named owner, or it doesn’t run in the tenant. Or let it run on whoever’s login was handy, and inherit the vendor’s job without the vendor’s resources.

Either way, that work has a cost, and it isn’t on anyone’s invoice.

Why Do We Care?
Because the upkeep a vendor used to fold into the subscription doesn’t disappear when the client builds instead. It’s landing inside your flat per-user fee. Every client-built tool you issue an identity to is a small software asset you now maintain: the permission review, the patch, the call when it breaks. At the next renewal, list client-built tools by name in the agreement and count them, so your price grows with what they build instead of holding still while the work doesn’t.

What to Consider

  • Price the upkeep, not the build. Clients think the cost of software is in making it. The cost you carry is what the vendor used to: an identity, a permission review, dependency patching, and retiring the tool when nobody uses it anymore. Define one unit, one built tool with one identity and one named owner, and price per unit. That way a client with a dozen builds pays differently from one with none.
  • Tie the price to the identity. A tool running on its own account can be scoped, monitored and shut off without disrupting anyone else. A tool on a person’s login can’t, and VentureBeat found that’s how sixty-two percent of companies with agents in production run some or all of them. Price the first kind as ongoing coverage. Quote the second as a one-time project to move it onto its own identity.
  • Set the number from your own builds. Brian Weiss described Techstack’s ongoing role as keeping development, test and production current with Microsoft’s roadmap. That’s upkeep sold as a service, with a price attached. Track what it takes your team to maintain your own automations for a quarter, and base the per-tool price on that record rather than a guess.

If this trend continues: Within the next two annual renewals, the clients with the most built tools will be the ones whose flat per-user price hides the most unpaid upkeep. The MSPs that priced built software as its own line will be the ones whose margins held.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories