The hidden costs of tool sprawl in mid-size companies
The 15th SaaS login is rarely the fee. It is questionnaires, champions who leave, and no shared context. How 10–200 person companies should gate the next AI SKU.
- tool-sprawl
- saas
- procurement
- operations
A typical 10–200 person company already runs on the order of a dozen SaaS subscriptions before anyone adds "AI." Each one looked cheap at the moment of purchase. Each added a login, an invoice, a security questionnaire, an admin, and a champion. The champion will leave. The questionnaire will be asked again by the next enterprise customer. The invoice will auto-renew.
Tool sprawl is the real competitor to the next AI product, not Copilot. The 15th tool has to be dramatically better than the 14th to clear procurement fatigue. Most AI point products are marginally better at exactly one thing, and still leave you mapping the last stretch into QuickBooks by hand.
This is not an argument against software. It is an argument against surface area that does not retire work.
The costs that never appear on the vendor's ROI slide
The fee is the visible line. Monthly or annual, sometimes a one-time license plus usage. Controllers can add. That is the easy part.
The questionnaire is a tax on every new logo in the stack. Your largest customer's MSA, your insurer, and your own finance team will each ask who subprocesses the data. Fourteen tools is fourteen answers, fourteen DPA chains, fourteen "wait, do they train on our data" threads. The 15th AI SKU that cannot reuse an existing review is not a $290 line item. It is another cycle of the person who already owns AP and close.
The champion is a single point of failure. Sprawl accumulates tribal knowledge: which zap is allowed to touch the mailbox, which GPT is "the good one," which dashboard is stale. When that person resigns, the tool does not become ownerless in the org chart. It becomes a zombie: billed, unused, still connected.
Context does not travel. A vertical point solution can be excellent at one job. Ten problems is then ten contracts, ten reviews, ten invoices, and no shared memory between "the thing that coded the bill" and "the thing that drafted the reminder." Below a certain deal size, procurement costs more than the product is worth. That sentence is about your time, not the vendor's ARR.
Integration remainder. Generic AI gets a long way on a demo PDF. The last stretch into the system of record is the job. If each point tool stops at a CSV, you have purchased a new pile, not a process. The planning range for custom remainder work sits in the $20k–$60k band, or months of internal thrash. Sprawl multiplies remainders.
Identity and access debris. OAuth grants, shared passwords from 2022, contractors who still have seats, a Slack app nobody can name. Unlimited seats (we charge for work, not watchers) is a pricing shape, not permission to skip offboarding. Sprawl makes offboarding a scavenger hunt.
Cognitive load on the operator. At this size, operations leads have usually already abandoned a product that required a data warehouse they do not have. That is not hostility to software. The next login that requires a warehouse, a customer data platform, or an ML owner will fail the same way. Fatigue is rational.
Why AI products make sprawl worse, faster
They are sold as seats, canvases, or single-purpose add-ons. Seats duplicate: ChatGPT Team plus Copilot plus a specialist writer tool plus a meeting note tool, each making individuals somewhat faster at work they already did, none of them running at 2am. Canvases duplicate: a Zapier zap, an n8n flow, an agent-builder prototype, three ways to miss the same exception. Point solutions duplicate: one vendor per pain, each with a thin AI feature that does not share a vendor relationship with the others.
Directories make this worse by dumping evaluation on the buyer. A list of things that might work is not curation. Abandoned listings stay installed in the same way zombie SaaS stays billed.
A gate for the 15th tool
Before you add it, write answers. If you cannot, you are not buying. You are collecting.
- What two tools does this retire? If the honest answer is "none, it is extra," the bar is very high. Extra is how you get to 20.
- What system of record does it write to? Named objects. Draft vs posted. Revocable OAuth.
- Who is the owner in month six, by role, not by first name? If the owner is "whoever set it up," you are funding a zombie.
- Does the security review reuse a vendor we already cleared? One DPA chain is the point of a pack or a single catalog. Ten chains is the point of sprawl.
- Hours at our volume, with the formula on the page. No round "save a day a week."
- Named refusal. If it will not pay the bill, say so. If it needs a warehouse, say so before the trial.
- Off switch. Pause, revoke, export. Cancellation must not unwind work already in the books.
- Champion leave test. If that person is hit by a bus, does the SOP still name the queue?
What "one vendor for eight jobs" is, and is not
The competitive line, without punch-up: buy the specialized product where it matters. For the other eight jobs: one vendor, one bill, one security review.
That is not a claim that one catalog item is the deepest possible AP product on earth. Vertical specialists earn their keep on the jobs that are actually distinctive. It is a claim about procurement and context at 10–200 people, where the operator's week is the scarce resource.
A pack is the catalog shape for that claim: a curated bundle around one job-to-be-done, so close prep is not three vendors. A tool, agent, or workflow should still earn its login by replacing named minutes, not by adding a dashboard.
We will not imply a crowd of third-party sellers. Launch supply is first-party: we build it, integrate it, pick up the phone. "Marketplace" is how you buy — browse, compare, deploy — not a bazaar of unverified listings. One bad listing damages the promise more than fifty good ones reinforce it. That is why curation is the product.
What to do with the 14 you already have
You do not need a transformation program. You need a list.
- Inventory: name, owner, annual spend, last login, OAuth still live, data it holds.
- Kill zombies. If nobody can name the job, revoke the grant, then cancel.
- Keep the seats that make people faster. Do not expect them to run processes.
- Keep the pipes (Zapier, Make, n8n) that are actually in the SOP, with an owner and a diagram in a folder finance can find. Do not add an LLM step without an eval.
- Put new AI spend through the 15th-tool gate. Prefer work that lands in systems you already open, so adoption is not another login.
nox.markets is for the remainder: jobs that should not be a 15th silo, and should not be a four-month project. If week one misses the hours at your volume, cancel it. That sentence is the sprawl control. Use it.
More from the blog
Data protection questions a buyer should ask any AI product vendor
A usable questionnaire on subprocessors, training, retention, human access, approval, and exit for operators and controllers at 10-200 person firms.
When the model provider retires the model: dependency risk you can actually plan for
Model deprecation is scheduled maintenance. What breaks, who pays to retest, and which contract terms a buyer should require in writing before you buy.
How to measure automation honestly when time-saved numbers are usually invented
Why vendor hour-savings fail a controller rebuild test, and how volume times minutes times loaded rate stays honest without fake case studies.
