There is a person in your building who already builds software. They do not call it that, and nobody else does either. They are the one who maintains the commission sheet your sales team is paid from, or the pricing calculator your estimators quote from, or the capacity tracker operations refuses to run without, or the rep who prices deals their own way. Lately they are also the one with a desktop AI tool open at lunch, asking it to write the formula, fix the macro, or stand up the screen that shows the whole schedule at once.
Decide this about them now, because how you treat them decides the next five years: that person is not your risk. They are your first internal builder, doing free R&D on your payroll. The actual risk is that you do not know they exist. You cannot fund, protect, or govern a software estate you have never mapped.
The person, and what they actually build
They are in operations more often than not. Sometimes finance, sometimes the plant. Their title says coordinator, analyst, or supervisor, and their real job is making the work come out right when the off-the-shelf tool stops one step short of reality. So they build the missing step. A form that feeds the report. A list that reconciles two systems. A tracker that turns three spreadsheets into one number the whole company trusts.
That is software. It has logic, inputs, outputs, and rules. It decides who gets paid and how much, what a job costs, and whether there is capacity to take the next order. Nobody calls it software, because it was never sold to you, and that has been its quiet advantage: it exists precisely because buying a product to do that specific job was never worth it.
The spreadsheet is the proof and the precedent. Everyone has been able to build software since 1985. It is called Excel, and your company runs on it. The spreadsheet is arguably the most successful end-user programming environment in history, and it exists because the last mile of every business is too specific to buy off a shelf. Your commission sheet is more accurate to your business than any vendor's commission module, because the person who wrote it had to live with your actual rules.
AI is the second act of that story, with a larger blast radius. The same person who built the sheet can now ask a desktop tool to build the whole screen, the approval flow, and the summary report in an afternoon. Same democratization, same upside, same failure mode, now pointed at things that touch customers and money directly.
If the builder in your building sits on the sales floor, the ground-floor version of this pattern has its own essay: the rep who outgrew the CRM.
Why they never asked permission
Because nobody was ever going to say yes. The request would have gone to IT, whose job is to keep the estate stable and secure, not to staff a one-off tool for one team. Or it would have gone to a vendor, whose answer is a product with the feature you need buried two tiers up the pricing page. So the person built it quietly, it worked, and the company kept running.
Most of the building in the economy is happening this way. A Retool survey covered by VentureBeat in April found 78% of teams planning to build custom tools by the end of 2026. Klarna, the payments company, ditched Salesforce's flagship CRM product in late 2024 for a homegrown AI system. And the market has been repricing software companies ever since: roughly $300 billion in software market value evaporated in a single session in early February, nearly a trillion dollars was erased from software and services stocks within weeks, and forward earnings multiples fell from about 39 times to about 21. One Zoho CEO called AI "the pin that is popping this inflated balloon."
The SaaSpocalypse, as a Jefferies analyst named it, is not a story about IT budgets. It is a story about people building things without asking. Read the survey number again: 78%. Not 78% of startups. 78% of teams across the middle market planning custom builds, and most of those builds will never cross your IT department or your procurement desk. They will come from the person at the desk who got tired of waiting.
What you actually have: free R&D
Sit with this sentence. Your company's real rules, the edge cases and exceptions no vendor ever learned, are already encoded in working tools that someone built on your payroll, for free. If you hired a contractor to reproduce what that person knows, it would cost six figures and take a year, and it would still be wrong, because the knowledge lives in the person, not in any spec you could write today.
So do not punish the builder. Tell them to stop, and you get the worst of both worlds: the building continues anyway, because the business still needs the tool, and it goes underground where you cannot see it. Punishing the one person who surfaced is how you teach everyone else to hide.
What the builder actually needs is small. Permission, stated out loud, to keep going. Data access that does not require a ticket and a prayer. A reviewer who understands the business rule well enough to check the work. Twenty minutes of your time once a quarter. That is the entire budget of the cheapest R&D your company will ever run.
The other half of the truth: an unmapped estate is still a risk
None of the above is permission to ignore what they build. The quiet history of end-user software is littered with failures, and the famous public ones, a trading desk, a published macroeconomics paper, were not caused by stupid people. They were caused by software that nobody treated as software: unversioned, unreviewed, dependent on one person. If the person who built your commission sheet left, it would take a month to reconstruct, and nobody would know where to start.
AI makes the blast radius larger. The same ease that lets one person build a good tool lets ten people build ten bad ones, and the bad ones touch customers and money directly. When Retool shipped an enterprise-governance product in June, its hook was blunt: AI-assisted "vibe coding" by non-developers now tops the C-suite list of concerns. The C-suite is worried for a reason. You cannot secure what you don't know exists.
Hold both halves at once. The builder is an asset. The unmapped estate is a risk. The fix for the risk is not to stop the building, because you cannot, and the building is the point. The fix is to map it.
What to do this quarter
- Ask the department heads, not IT: what runs your team day to day, and who built it? You will have your list by Friday.
- Walk the floor for tools nobody has heard of. The schedule screen in the plant. The pricing sheet in estimating. The reconciliation helper in finance. Name each one on a single page: what it does, what data it touches, who maintains it, who reviews it.
- Say the sentence to the person who built them: keep building, and tell us what you are building. We will get you the data access and a reviewer.
- Set the two rules before anything else ships: where the data lives, and who reviews the output. Do it on day one, or you will do it after an incident.
- Give the builder a visible name. Call it internal tools, or the automation group, or just fund the time. The title matters less than the signal that building is legitimate work.
The person who built the commission sheet is not a problem to be solved. They are an answer to a question you have not asked yet. Ask it this week, then build the map and the rules around what they make. That is the whole job, and it is smaller than you think.
If you found your builder, or you are the builder, [email protected] is the fastest conversation worth having.
