
It has been just over ten years since Marc Andreesen memorably said software was eating the world. He was correct. Now we have entered a new stage: powerful software is everywhere we turn, and we have been consuming it with little attention to the long-term consequences. So much so that, today, we are left with an ironic question: Did we overeat?
Our plates are definitely full of every imaginable kind of application, and they are all highly tempting. Do you know how many apps you have ever signed up for? Perhaps dozens, or even hundreds? The average number of apps deployed per Okta customer has climbed 22% over the past 4 years. IT leaders I speak with often joke that their companies have more SaaS apps than employees.
This can be a problem and you should care about this. Organizations that allow their appetites to expand without restraint face three major risks:
- Costs: As remote work has become the norm, software has become the second-largest expense category for many companies. Yet as much as 25% of SaaS apps and licenses remain unused. If your company’s top two expenses are people and technology, you are throwing away a lot of money on one of your biggest costs. Compliance risks: To sell cloud-based software or keep customer data in the cloud, you need to become or remain SOC2-, ISO 27001-, or even SOX-compliant. Picture your company and its data as a castle. You must show auditors that it is strongly defended. Now imagine each app as a window, door, bridge, or point of entry into your castle. The more apps you have, the more scrutiny auditors will place on you. Operational efficiency: The gap between a good chef and a world-class chef is entirely about how they manage their team to handle all the ingredients available. Your team is certainly not working together effectively when it uses several versions of the same app, such as Monday, Jira, Asana, or ClickUp. In addition, internal support tickets rise exponentially as the number of apps in use increases.
Still (and to carry the food metaphor a bit further), many of the apps your company uses are in fact the ingredients used to build a great product. After all, creating a technology company is complex. And to do it well you need the right parts and tools. However, the challenge in benefiting from them — in becoming a 3-star Michelin restaurant of software — is to think about how to manage all your software with real mastery.
One way to do this, to unlock your company’s full potential through technology, is to shift the priorities of IT, security, and procurement — the teams that usually care about software operations. Rather than having them solve problems (for example, handling IT tickets), help them build infrastructure that lets employees operate software on their own and become a self-governed workforce.
The appocalypse. Or is it …?
But first: How did we arrive here, at this moment when companies are living on SaaS and living through what I jokingly call the appocalypse? What are the causes of our software addiction?
Better UX of modern software has unbundled traditional enterprise software
Employees rely on more and more specialized apps to succeed at work. We used to use Microsoft products for nearly everything. Now we use Airtable instead of Excel, Notion instead of Word, Pitch instead of PowerPoint. To add some numbers to what many of us observe in daily life: Over 42% of Okta’s Office365 customers now also deploy Zoom instead of simply using Microsoft Teams, and 26% of them also use Box despite having OneDrive.
Individuals are using more apps due to easy and free adoption
Traditionally, enterprise products were sold top-down: The CIO chose to buy Salesforce or Microsoft Office and they became the defaults for the whole company. But startups like Slack and Dropbox made bottom-up growth popular, and, today, 67% of developer companies (for example Datadog or AWS) offer a free plan or trial. We no longer need to schedule a call with salespeople or ask IT for approval — we simply sign up for the free version of the tool.
In short: Apps are here, there, everywhere. But did we go too far? Are we, in fact, using too many apps? I do not think so. Quite the opposite, software can give us superpowers to move the business ahead faster.
Treat technology as a business driver
Think about your car. It takes 30,000 parts to make a single car. But instead of reducing the number of parts, car manufacturers found the best way to assemble the car. The breakthrough came from how they combined different parts. For instance, the Toyota Production System, also known as “lean manufacturing,” became a central competitive advantage for Toyota. One principle was to reduce waste and keep improving operations by surfacing problems quickly. Agile software development and the “lean startup” methodology were influenced by the Toyota system of “build, measure, learn.”
Like Toyota, companies should consider how to revise their operating principles around software and turn them into a competitive differentiator. Traditional ways of managing technology are not enough. Companies often believe centralization is the answer but, in this case, it is not. There are simply too many apps to deal with, along with other factors such as security and compliance.
Centralized software administration is the enemy
In 1944, the Central Intelligence Agency published a guide on how to sabotage your workplace. Point No. 1 was to never take shortcuts and always use a centralized “channel.” Think about the last time you needed access to an app or a permission. You had to go through a channel created by an IT ticket, and ended up waiting. Or think about the last time you needed to buy a new piece of software? It can take 2 to 3 months before you get all the approvals needed to purchase an application.
Here is why centralization does not work, and why efforts to fix it can miss the point.
Centralization creates bottlenecks
More than half of all apps are bought and managed by subject-matter experts in different teams — many of whom simply want to get their tools and begin working. However, departments like IT, security, or procurement need to support most of those requests. From what we are seeing, between 40% and 60% of all IT tickets are tied to software-access issues, which, on average, take about 19 hours to resolve. Employees are left waiting, and admins are being overwhelmed by busywork such as account creation. The management overhead rises with every extra app.
Centralization leads to leaky buckets
Companies also centralize oversight to reduce cost, compliance, or security risks. The reasoning is sound, in that employees should not simply buy duplicate software or be given too much admin access. However, reviewing hundreds of apps and thousands of accounts is not scalable with a centralized approach — it creates leaky buckets, where employees still get and keep unnecessary access to apps without anyone knowing. For example, 25% or more of software goes unused within most companies. Or, Segment’s security team showed last year that 60% of its 669 admin roles were not actively used.
More headcount is not the solution
Commonly, operations teams say they are funded less generously than other departments, so they end up moving more slowly than they would like. So why not simply keep expanding admin headcount in lockstep with the number of apps we use? The problem is right in that question, and in the belief that the answer can only be found by centralizing support and oversight. That kind of fix does not scale.
Centralizing software administration is an odd thing. It is meant to simplify matters, yet as the number of apps grows, it somehow makes things harder for everyone. So how do we rethink the responsibilities of the teams that look after software operations — namely IT, security, and procurement?
Make the compliant path the easy path
Let’s be honest: employees will nearly always choose the path that gives them value with the least effort. If your software management approach stays centralized and full of choke points, people will keep sidestepping your policies by doing things like secretly purchasing software. It becomes a self-reinforcing loop. For many people to behave responsibly — and to reshape the relationship between IT/security/procurement and the rest of the organization — the compliant path has to be the most convenient one.
Self-governance is the new approach to manage software
Solving this complexity is only possible if we return control and accountability to employees and their teams. Rather than simply serving people food, you show them how to cook without hurting themselves. In essence, the aim is to create a setup where incentives line up so that employees who work in the most secure and cost-effective way also resolve their own issues fastest.
We are already used to do-it-yourself behavior when buying food and gas — and even when checking in for a flight — so why not apply it to enterprise software management? Rather than sending requests to IT for help (or moving through “channels,” as the CIA put it in its workplace sabotage guide), IT could let employees help themselves quickly and responsibly. Instead of acting as the central execution unit, security, procurement, and IT need to become the company’s internal platform that equips employees with the right infrastructure.
Automation is useful, but it depends on centralized support and that does not scale across hundreds of apps.
Putting in place a process and structure for self-governance is a critical issue to address because it has a direct effect on the bottom line. Organizations that fail to move from a systemic centralized model to a self-service one risk burning through large sums on unused software, failing the next compliance audit, and leaving the entire organization operating inefficiently. Changing how the organization works is a leadership priority, so it can reach its full potential by using third-party applications strategically instead of being swamped by them.
The question companies should be asking themselves is how to build self-service into as many places as possible. For example:
- Once IT sets up workflows that define who should approve which app, employees can request apps, permissions, internal tools, or even developer resources without needing IT assistance. If procurement creates a system that defines who must approve which kind of software purchase, employees can simply use that self-service system. If security puts in place a way to grant access to sensitive apps or permissions for only a specific time window, they will not need to review access centrally all the time.
Incorporate self-governance into your goals
All of these examples show how the role of software operations teams can shift: instead of handling support tickets or alerts, they could concentrate on designing the system correctly and coaching the organization throughout the process. Beyond that, another way to change technology management through a self-governed workforce is to encourage all team leaders across the organization to include self-service in their OKRs or V2MOM process.
For example, IT often has a goal of cutting the operational headcount needed through automation. Automation is useful, but it depends on centralized support and that does not scale across hundreds of apps. Instead, IT could try to reduce operational headcount requirements through self-service. Or IT may set a goal to shorten the time it takes to respond to tickets. Again, that goal is based on the assumption that support must be centralized. Instead, try adding a goal to lower the share of requests that do not need a first touch from IT.
Up to 25% of SaaS apps and licenses go unused. If your company’s top two expenses are people and technology, you are throwing away a lot of money on one of your biggest expenses.
Self-governance can also begin with a small exercise to cut SaaS spend. Centrally managing hundreds of vendors is impossible, but it may be enough to do something as simple as emailing every Outreach.io or Smartsheet user and telling them you are trying to reduce software spend. Ask for a 👍 if they no longer use the software so you can recover the license.
Or ask all of your app admins to help lower overspending. Make a shared spreadsheet of software apps and annual costs, then ask them to cut as much cost as possible by removing licenses or canceling apps entirely. To turn this into a team challenge and line up incentives, give a prize for every unused or redundant app they delete, and a cash reward to the top three admins who reduce SaaS spend the most. This method gives you an early look at what it means to have a self-governed workforce.
Are we full yet?
Building a technology company is difficult — especially now. Instead of lamenting all the tools we use, a better use of energy might be to create an efficient way to manage both your tools and the processes behind them. Giving your teams and employees power through self-governance can become a competitive advantage. Not only will employees feel like a core part of the process and therefore have a stake in its success, but the people in IT, security, and procurement will become real enablers rather than ticket or alert handlers.
So yes, we may have an all-you-can-eat SaaS buffet in front of us, but we have the tools and the knowledge to satisfy our appetite and make all of those choices work for us. It only takes the determination to change how we relate to software.