Writing / 2026

The Software You Didn't Buy Still Needs an Owner

Orgs are skipping software purchases and building with agents. Each build is rational; the fleet is the risk. Agents compress maintenance work but can't inherit maintenance duty.

A new line item is showing up in build-vs-buy decisions, and McKinsey’s August survey put a number near it: 32% of organizations decided against buying at least one software product or feature because they could build it in-house with agentic coding tools, with the share higher in tech and healthcare. Behind that statistic, picture the concrete version: a renewal that used to end with “we don’t have the engineers” now ends with an agent-assisted build and a cancelled contract.

I’ve argued the calculus genuinely shifted , so this is not the TCO lecture, and it’s not a warning against building. The problem worth a post is one level up from any single decision: each skipped purchase can be individually rational and the sum still be unmanageable, because what accumulates isn’t code, it’s a fleet. Build-vs-buy is decided one tool at a time, by different teams, each seeing only its own tidy win. Nobody is deciding the portfolio, and the portfolio is where this bites.

First, the strongest case for building, granted in full: agents don’t just write version one. They patch dependencies, migrate APIs, write the tests, and they’re improving at all of it, so the maintenance hours per tool really are falling. But walk through what a maintenance obligation is, and notice how much of it was never hours of labor. Someone must notice that a CVE dropped in a dependency at all. Someone must decide the fix ships this week and not this quarter. Someone must answer when the tool breaks at 2 a.m., and someone must be the person a security review or a data-protection auditor asks about access, retention, and configuration. Agents can compress maintenance work. They cannot inherit maintenance duty, because duty attaches to someone accountable, and that remains the one thing you cannot delegate to the machine . A vendor contract never transferred your accountability either, but it did sell you a counterparty: shared maintenance capacity, a security team on someone else’s payroll, an SLA to point at. Cancel the subscription and the counterparty’s duties don’t vanish. They re-home, silently, to whoever prompted the tool into existence.

Predict the failure mode from those two facts, cheap creation and sticky duty, and you get orphan accumulation: not one big unowned system, which someone would notice, but a dozen small ones. The contract tracker, the vendor-portal replacement, the reporting glue: each written mostly by an agent, each shipped by whoever needed it, each orphaned the day its author changes teams. Make “orphan” a measurable category, because that’s what turns this from metaphor into management. An orphan is software with production traffic or production data and no accountable team, no catalog entry, or no review date. Count yours. The count is the instrument this essay is for, and if your org moved early on agent-built tools and the count isn’t zero, you already knew that before counting.

Getting the count down doesn’t require bureaucracy sized to kill the win; it requires proportion. The bar for taking production traffic or data is four fields in the service catalog. An accountable team, not the enthusiast. A tier, from a written taxonomy that keys on data sensitivity, blast radius, and recoverability. The security checks that tier demands, which for the lowest tier can be an automated scan and for the highest is a human review. And a retirement trigger: the date or condition on which someone re-decides existence, because a decision made in an afternoon deserves revisiting annually. Price ownership at the portfolio level, a maintenance allocation across the fleet rather than a person per tool, and let the tiers concentrate it where the blast radius is. Tools that can’t clear four fields stay personal, off production data, which is where a week of agent output belongs by default.

Then make the original decision legible at the moment it’s made. The memo that says “agent builds it: $0 versus $40K a year” is comparing a purchase price to nothing. The real comparison is counterparty versus duty: what the vendor’s operational capacity was worth, against a permanent seat in your fleet with your name on it. Sometimes the build still wins; often it does. But the interesting number at year’s end is no longer what you saved on subscriptions. It’s the orphan count, and whether anyone can produce the list.