Skip to content

Build1 publisher3 min readPublished

When customers build their own features, your permission model becomes the product surface

Vendo's open-source layer lets B2B customers generate features from a vendor's own APIs, acting as the signed-in user. The controls it ships are company-documented, not independently audited.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying When customers build their own features, your permission model becomes the product surface
Photo: ycombinator.com

What happened

  • Nour Zahzah and Yousef Helal released Vendo, an open-source customization layer that lets customers generate features, automations and small applications inside the B2B software they already use, according to Vendo's verified Launch YC announcement.
  • Vendo turns bespoke feature requests into customer-built software, shifting a SaaS vendor's bottleneck from roadmap capacity to permissions, security and governance.
  • Vendo targets requests product managers understand but cannot justify on a shared roadmap: one enterprise customer wants a custom approval flow, another needs a dashboard combining three obscure fields, a third needs an integration that may never matter to anyone else.
  • With Vendo, a customer can describe a dashboard, workflow or integration in plain English and have an embedded agent assemble it from the host product's APIs and interface components.
  • Vendo gives the customer an agent that operates through the vendor's existing API as the signed-in user, and the generated interface appears inside the original product using its theme and components, according to Vendo's documentation.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

Nour Zahzah and Yousef Helal have released Vendo, an open-source customization layer that lets customers generate features, automations and small applications inside the B2B software they already use, according to the company's verified Launch YC announcement [1]. The framing Vendo puts on its own product is the part worth reading twice: it moves a vendor's bottleneck from roadmap capacity to permissions, security and governance [2].

The demand side is not in dispute. Every product team keeps the same drawer of requests: one enterprise customer wants a custom approval flow, another wants a dashboard that combines three obscure fields, a third wants an integration that may never matter to anyone else [3]. Vendo's answer is to let the customer describe the thing in plain English and have an embedded agent assemble it from the host product's APIs and interface components [4], rendered inside the original product using its theme and components [5], in a sandboxed surface that does not modify the host application's source code [6].

The consequential decision is that the agent operates through the vendor's existing API as the signed-in user [5]. Vendo says this keeps the host API and permission model in charge instead of granting the agent a separate path into customer systems [7]. It also means the host's authorization model is now the security boundary for code the vendor did not write and did not review: whatever an endpoint permits that user to do, generated software can do [20]. Any scope that was broader than the screen which used to call it stops being a theoretical gap.

The capability list grows from there. Y Combinator's profile says customers can create automations, connect external tools and let the agent take actions inside the host product, and the repository separately lists schedules, host API actions and connector tools [10]. The source notes the trade directly: each capability adds to the authentication, authorization and review the host vendor must manage [11]. Vendo's repository documents sandboxing, approvals, grants, policy controls, audit records and circuit breakers, and these are company-documented controls rather than an independent security audit [8]. It also describes an iframe environment with network access disabled by default and a sandboxed server for heavier execution [9]. Separately, Vendo can expose host tools to Claude, ChatGPT, Cursor and Claude Code over the Model Context Protocol, which is another route into the same APIs and permissions [12].

Installation is advertised as two commands, npm install @vendoai/vendo and npx vendo init [13], with an initializer that reads the host repository, identifies its theme, components and API surface, and proposes permission-gated changes [14]. Teams can connect an agent they already run or use Vendo's packaged one, which includes chat, actions, generated interfaces and a knowledge base [15]. The two commands are the cheap part. Deciding what your API surface actually permits a customer's agent to do, per tenant, with a retained record, is the part nobody staffed for.

Distribution follows the licence: Apache-2.0 with a free cloud plan, Pro at $49 per month, Teams at $499 per month and custom Enterprise pricing [16]. Teams is roughly ten times Pro [17]. The pitch is also young. The founders previously built Aisle, an in-store AI shopping assistant [18], and Vendo itself began as one-click deploy and customization for open-source software before turning into an embedded agentic layer for commercial SaaS [19].

Watch for an independent review of the documented controls [8], for what the audit records retain and who is expected to read them [8], and for whether tenancy guarantees end up behind the Enterprise tier [16].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories