Leadership1 publisher2 min readPublished
The SaaSpocalypse thesis still has to get past the customer's pen-testers
A widely shared theory says large companies will prompt their way out of paying for CRM and ERP seats. One practitioner's answer is that the buying decision turns on security review and audit trail, and on who signs the liability clause.
The Board Room · Leadership desk

What happened
- An Entrepreneur contributor column takes on the "SaaSpocalypse" theory, which began in a market selloff and now holds that companies will build and self-host the tools they currently license.
- Its central claim is that the approvals enterprise software must pass are beyond what an AI agent can produce or sign.
- Managers pick vendors because a vendor supplies an SLA, support and someone to blame, while a homegrown tool leaves the department dependent on one employee and without cover when it fails.
- The test case the column poses is BP, roughly 95,000 employees, and whether such a company would vibe-code a CRM, a logistics platform or asset tracking for equipment across dozens of countries.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure A manager who adopts a colleague's internal tool takes on a single-person dependency. It reaches into raises and resignations, and into managing that person out.
- decision The choice this quarter is which systems sit inside the audit perimeter, because the case holds where reviewers are involved and is untested on the small-team tools that stay outside review.
- precedent If the liability clause is what the buyer is paying for, an agent product sold into these accounts has to arrive with indemnity and a support contract attached to it.
The approvals cut both ways. The column lists what a system has to survive inside a large enterprise: security review, regulatory sign-off, procurement policy, vendor risk assessment, data-residency requirements and an audit trail that has to hold up years later [7]. Six separate approvals [8], and the incumbent vendor already holds all six for its installed base.
The piece runs as an Entrepreneur contributor opinion [13], and the author writes from the selling side. "I've watched a security questionnaire kill a deal outright, and I've sat through a three-month infosec review that ended with the customer's own pen-testers hammering our product before a single seat was paid for," the author wrote [3]. That "our" places the author on the vendor side of the table. The column also says most of the end-of-SaaS takes on X/Twitter come from people who have never worked inside or sold into a large multinational [15].
The sturdier half of the argument is about incentives. Small founder-led teams buy software to make money or save money; in large organizations, the column says, the operative reasons are "cover my ass" and "make me a hero" [9]. "Nobody gets a bonus for vibe-coding an internal tool," it says [18]. The column carries no seat, renewal or churn figures, so it leaves open how often internal builds displace paid seats [19].
"A vibe-coded tool doesn't just carry technical risk. It carries an employee," the column said [10]. The manager who accepts one is then dependent on a single person. The piece puts that in HR terms: what happens when the employee asks for a raise, quits, or has to be managed out while remaining the only person who understands the system that runs procurement [14]. "You can fire a vendor. You can sue a vendor. You can put a vendor out to bid and get three competitors to undercut it," the author wrote [11].
Every example chosen sits inside the audit perimeter, up to the ERP that runs procurement, finance, staffing and operations at Frankfurt Airport [6]. The argument is strongest there. A nine-person team's project tracker skips infosec entirely, and that tier of spend is where the collapse thesis is easiest to believe.
For a renewal signed this quarter, that leaves the buyer where it was: the approvals exist, and the alternative is unreviewed. An agent that produced a plausible app over a weekend cannot sign a contract with a liability clause. It cannot be sued when something goes wrong, and it cannot stand in front of a regulator, the column said [12].
What to watch
- A large SaaS vendor reporting seat contraction it attributes to customers building tools internally.
- A named enterprise disclosing an internally generated system of record that passed vendor risk review.
- Auditors or regulators issuing guidance on how AI-generated systems are to be evidenced years later.