Agentic AI software market — research memo
Date: 18 September 2026
Scope: SaaS pivot research for a 1-VPS indie product. Not a generic “AI platform.” No quantum. No social network.
Method: Primary sources opened and cited below. Numbers that appear only in secondary recaps are not used. Market-size estimates disagree by definition; that disagreement is the finding.
1. Market size and growth (dated)
Two different “agentic AI” markets
Analysts are not measuring the same thing. Treat every TAM as a definition, not a census.
| Source (opened) | What it counts | 2026 figure | Trajectory |
|---|---|---|---|
| Bain & Company, 7 May 2026 (PR Newswire) | US SaaS TAM created by automating cross-system human coordination, not replacing systems of record | $100B US TAM; vendors capturing $4–6B (~90%+ uncaptured) | Canada + Europe + Australia + New Zealand could double to ~$200B |
| MarketsandMarkets, 20 Aug 2026 (PR Newswire UK) | Global “Agentic AI” software/services (platforms, orchestration, prebuilt agents) | $19.33B in 2026 (from $11.56B in 2025) | $205.88B by 2033, 40.2% CAGR |
| MarketsandMarkets, 4 May 2026 | Agentic AI security only | $1.65B in 2026 | $13.52B by 2032, 42.0% CAGR |
| Menlo Ventures, 16 Sep 2026 (GlobeNewswire) | Consumer AI spend (assistants + agents), not enterprise SaaS | $40B global consumer AI spend in 2026 (from $12B a year earlier) | Spend tripled while the user base barely grew |
How to use these numbers for a 1-VPS SaaS: Bain is the labor-replacement opportunity incumbents and well-funded natives (Glean, Sierra) are chasing. MarketsandMarkets $19.33B is a vendor-revenue forecast that already includes Microsoft, AWS, Google, Salesforce, ServiceNow, IBM. The addressable slice for an indie is not a percentage of $100B. It is the self-serve remainder: teams who already pay $20–200/mo for coding agents and LLM keys and need a permit / budget / receipt layer those vendors do not sell on a credit card.
Bain, 7 May 2026 — the $100B “glue work” TAM
Bain’s second report in a five-part software-in-the-age-of-AI series (released 7 May 2026, Boston) argues agentic AI does not kill SaaS. It monetizes the human glue between SaaS systems: pull from ERP, reconcile a spreadsheet, interpret a vendor email, decide whether to escalate.
- US TAM: ~$100B. Captured today: $4–6B. Untapped: >90%.
- Plus Canada/Europe/AU/NZ: similar-sized increment → ~$200B combined.
- Highest-value work sits where no single system of record owns the outcome (ERP + CRM + billing + support).
- Automation potential by function:
- Customer support and R&D/engineering: 40–60% of workflow tasks
- Finance and HR: 35–45% (AP/payroll high; FP&A and employee relations low)
- Sales and IT: 30–40%
- Legal: 20–30% (repeatable contract review, severe error cost)
- Named early movers: Glean ~$200M ARR (cross-function search, not a single knowledge base); Sierra >$150M (resolve issues across systems, not inside one ticket tool).
- David Crawford (Bain TMT chair): the moat moves from “system of record” to “cross-workflow decision context.” Time horizon: quarters, not years.
Bain is an opportunity-sizing exercise, not 2026 booked revenue. Do not treat $100B as this year’s invoice.
MarketsandMarkets, 20 August 2026 — $19.33B → $205.88B
Opened PR (Delray Beach, 20 Aug 2026):
- 2025: $11.56B. 2026: $19.33B. 2033: $205.88B. CAGR 2026–2033: 40.2%.
- Software: 71.9% of 2026 spend (development, orchestration/runtime, memory, connectivity, governance/observability, process automation, prebuilt apps).
- Architecture: single-agent systems dominate 2026 because they are easier to deploy, test, and govern. Multi-agent waits on orchestration, identity, shared context, runtime governance.
- Application: customer service & support 23.1% of 2026.
- Fastest end-user: IT & ITeS (coding, incident management, DevOps, service desk).
- Region: North America largest in 2026; Asia Pacific fastest (42.9% CAGR).
- Concentration: top 5 players 30.12%; top 10 47.16% (Microsoft, AWS, Google, Salesforce, ServiceNow, IBM, Palantir, OpenAI, Oracle, Accenture). More than half of revenue is still outside the top 10 — room for specialists, but also for incumbent M&A.
- 2026 funding/M&A named in the same release: Sierra $950M (May 2026), Decagon $250M (January), Harvey $200M (March); Salesforce proposed $3.6B for Fin; ServiceNow completed $2.85B Moveworks (Dec 2025); Cognition acquired Windsurf (July 2025).
Caveat: MarketsandMarkets published a different “Agentic AI Market” note on 17 Aug 2026 ($7.06B in 2025 → $93.20B by 2032, 44.6% CAGR). Same firm, different report IDs and definitions. Use the 20 Aug 2026 $19.33B / 40.2% figure when citing “the” MnM agentic TAM, and flag the collision.
Agentic AI security is a separate, smaller, faster wedge
MarketsandMarkets, 4 May 2026:
- $1.65B (2026) → $13.52B (2032), 42.0% CAGR.
- Solutions 71.32% of 2026. Threat detection & response 23.10%.
- Semi-autonomous / human-in-the-loop: 74.40% of 2026 — the market is not buying fully autonomous agents as the default.
- North America 41.92% in 2026. SMEs are the fastest-growing org-size segment because they skip to AI-native apps and lack in-house security staff.
- Named vendors include Microsoft, Palo Alto, CrowdStrike, Okta, Cloudflare, plus a long tail of agent-security startups (Zenity, Astrix, Aembit, Promptfoo, etc.).
This $1.65B is the governance/security envelope a permit-gateway product lives in. It is not the $19B “all agentic software” envelope.
Menlo, 16 September 2026 — consumer spend, not enterprise TAM
Menlo Ventures 2026 State of Consumer AI (nationally representative survey of 5,067 US adults, July 2026; GlobeNewswire 16 Sep 2026):
- Global consumer AI spend $40B in 2026, from $12B in 2025. User base 1.8B → 2.0B (+11%). US adult usage 61% → 64%.
- 55% of US AI users now pay for at least one AI product. 46% of payers spend more than last year.
- 14% of payers spend $100+/month and account for ~60% of US consumer AI spending.
- Daily use: 19% → 25% of US adults.
- Agents: 41% of US AI users have tried an AI agent; 24% use one regularly; 32% have let AI take an action at least once without final approval. Regular agent users: 92% pay for AI vs 55% of AI users overall.
- Trust now outranks convenience: accuracy 45%, trustworthiness 40%, security/privacy 36%, ease of use 32%.
- Holdouts hardened: 70% of non-users distrust AI-generated information (from 58%).
Implication for $19–99/mo SaaS: the buyer already has a card on file at OpenAI/Anthropic/Cursor. They will add a guardrail or receipt product if it is cheaper than one runaway agent loop and faster than a sales call. They will not add a fourth observability dashboard.
LangChain State of Agent Engineering, 12 June 2026
Opened: langchain.com/state-of-agent-engineering. Public survey 18 Nov–2 Dec 2025, 1,340 responses. Tech-heavy (63% technology; 49% of orgs <100 people). Treat as a builder census, not a Fortune 500 census.
| Finding | Number |
|---|---|
| Agents in production | 57.3% (up from 51% prior year); another 30.4% actively developing with a deploy plan |
| Large enterprises (10k+) in production | 67% |
| Small orgs (<100) in production | 50% |
| Top barrier | Quality 32% (accuracy, consistency, tone, policy) |
| Second barrier | Latency 20%. Cost dropped vs prior year |
| At 2k+ employee orgs | Quality still #1; security #2 at 24.9%, ahead of latency |
| Observability | 89% some form; 62% step/tool tracing. In production: 94% / 71.5% |
| Offline evals | 52.4% |
| Online evals | 37.3% (44.8% among production teams) |
| Not evaluating | 29.5% overall, 22.8% in production |
| Multi-model | >75% use multiple models |
| Fine-tuning | 57% do not fine-tune |
| Daily agents (write-in) | Coding agents dominate (Claude Code, Cursor, GitHub Copilot, Amazon Q, Windsurf, Antigravity). Then research/deep-research. Then custom LangChain/LangGraph agents |
| Primary use case (forced single pick) | Customer service 26.5%, research/data 24.4%, internal workflow automation 18%. At 10k+: internal productivity first (26.8%) |
Read-through: production is real, quality is the killer, observability is table stakes (do not clone Langfuse), evals are the gap, coding agents are the daily habit, and cost is no longer the #1 story for production teams — but spend caps still matter for individuals and small teams whose personal API bills explode (see Menlo $100+/mo cohort).
NIST (voluntary US baseline, not a market-size source)
Opened: NIST AI homepage and NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023 (doi:10.6028/NIST.AI.100-1).
- Voluntary, living document. Core functions: Govern, Map, Measure, Manage. Trustworthiness characteristics: valid/reliable, safe, secure/resilient, accountable/transparent, explainable/interpretable, privacy-enhanced, fair (harmful bias managed).
- NIST states it is building an AI testing/evaluation ecosystem and characterizing language-model and agentic-AI performance. A formal community review of the RMF is expected no later than 2028.
- This is the US language buyers use in RFPs (“map to NIST AI RMF”). It is not a license to sell “we make you NIST-compliant.” A 1-VPS product can emit evidence (who called which tool, under which rule, with whose key) that a customer later maps to Govern/Map/Measure/Manage. That is software, not an audit.
2. Where demand is hottest right now (Sep 2026)
Heat is not evenly distributed. Ranked by what shipped in the last 90 days + what builders already do every day.
2.1 Agent identity, SSO, and “who is this agent?” — boiling
This is the enterprise governance rush the brief flagged. It is real and crowded at the top.
- Okta Agent SSO GA 24 August 2026. Bundled at no extra cost into core Okta SSO (~20,000 customers). Cross App Access (XAA) agents register in Universal Directory; short-lived identity-governed tokens replace static API keys. Okta for AI Agents (GA since May 2026) adds shadow-agent discovery, A2A connections, certifications, kill switch. Named XAA integrations: Anthropic/Claude, Asana, Atlassian, Canva, Datadog, Figma, Glean, Granola, Linear, MintMCP, Notion, Slack, Supabase.
- Okta AI Agents at Work 2026 (Apprize360 survey fielded March 2026; article 27 May 2026; n = 292 executives + 492 knowledge workers, 7 countries):
- Only 34% of orgs apply the same security controls to agents as to humans.
- 58% of executives report an AI-related security incident or close call in the last 12 months.
- 52% of employees use AI tools without approval; US 67%.
- 90% of executives are confident they have visibility; 95% think employees use AI responsibly.
- Of unapproved-tool users: 54% share internal messages/email, 45% HR data, 39% confidential docs; >20% share login credentials.
- 92% of executives say autonomous agents are in widespread or moderate use.
- Convenience drives shadow AI: 80% “easier to use my own account,” 78% “my team already uses it.”
- Microsoft Agent 365 GA 1 May 2026 (Microsoft Learn, updated 19 Aug 2026): control plane to observe, govern, secure agents. Copilot Studio agents can be Entra identities with Conditional Access, RBAC/ABAC. Bundled with Purview audit, Defender, data policies, Copilot-credit caps. Licensed per user; works best with E5. Not a $29 self-serve SKU.
- Broadcom AgentMinder unveiled 31 August 2026 at VMware Explore: identity + declared intent + runtime gateway on every tool invocation + OpenTelemetry audit. Packaged with vDefend (shadow MCP/LLM discovery on the packet path) and Avi (tool-misuse prevention, exfil blocking). This is VMware Private AI Cloud infrastructure, not a credit-card SaaS.
- IBM watsonx Orchestrate, 3 September 2026: AI Gateway discovers/imports Amazon Bedrock agents (Azure Foundry and Vertex “end of September”); Trace Inspector GA 17 Aug; Custom LLM-as-a-Judge GA 31 Aug; AgentOps Agent GA 31 August 2026 (natural-language eval → GEPA/ACE instruction optimization). Contact-sales pricing.
- Dataiku Agent Management, announced 9 March 2026 as a standalone product (does not require the Dataiku platform). Cross-platform inventory + business KPI measurement, not just uptime. Early access as of that date; Yahoo recaps in mid-September still describe October GA. Enterprise data-science buyer.
Heat: high. Indie room: low inside Okta/Entra/VMware/IBM. The gap is everyone not on those control planes — developers, agencies, 10-person startups, people pasting API keys into Claude Code.
2.2 MCP as the lingua franca — boiling, shifting from “connect” to “govern and cheapen”
Opened Anthropic, 28 July 2026 (Bringing MCP 2026-07-28 to Claude):
- MCP >400 million monthly SDK downloads, 4× this year. “Industry standard for connecting AI agents to applications.”
- Spec 2026-07-28: stateless core (request/response, serverless/edge-friendly), official extensions (MCP Apps, Tasks), auth aligned to production OAuth 2.0 / OIDC so servers talk to Entra or Okta without workarounds.
- Claude directory: 950+ MCP servers, “millions of people every day.”
- Enterprise-managed auth: admin authorizes a connector once; users inherit via IdP groups.
- MCP tunnels (research preview): outbound-only path to private MCP servers — no inbound firewall holes.
Opened Cloudflare, 14 April 2026 (Scaling MCP adoption):
- Local MCP servers treated as a security liability (supply chain, tool injection, no admin control).
- Pattern: remote MCP + Access SSO + MCP server portals (central discovery, DLP, tool allowlists per group) + AI Gateway cost/fallback + Gateway “shadow MCP” detection (JSON-RPC method fingerprints:
tools/call,initialize, etc.). - Code Mode: collapse dozens of tool schemas into
search+execute. Cloudflare’s example: 52 tools / ~9,400 tokens → 2 tools / ~600 tokens (94% reduction); previously claimed 99.9% on the public Cloudflare API MCP. - Public MCP servers sit behind WAF AI Security for Apps (prompt injection, leakage, topic classification).
Heat: the protocol war is over; MCP won. Demand has moved to portals, allowlists, spend, and shadow-MCP detection. Cloudflare/Okta/Anthropic own the enterprise version. Nobody owns a 60-second, English-rule, BYO-key MCP permit for a Cursor/Claude Code user.
2.3 Coding agents — the daily habit, already paid
LangChain write-ins (June 2026 report): Claude Code, Cursor, GitHub Copilot, Amazon Q, Windsurf, Antigravity are the daily agents. Research agents are second; custom LangGraph agents third.
This is the only agent category that already has consumer-grade willingness to pay (Menlo: coding is a default task; 55% of AI users pay; regular agent users 92% pay). It is also the category that pastes MCP servers and API keys into a config file with no Okta in the loop.
2.4 Quality / evals — hot problem, crowded tooling
LangChain: quality is the #1 production killer (32%). Observability 89%, offline evals 52%, online evals 37%. IBM just shipped Custom LLM-as-a-Judge and an AgentOps agent that writes tests and rewrites instructions. LangSmith Engine (Plus+) clusters failures and proposes prompt/code fixes, metered in LCUs. Langfuse has datasets, LLM-as-judge, annotation queues on the $29 Core plan.
Heat: real. New generic eval platform: dead. A wedge only works if it is narrower than LangSmith (e.g. “did this coding-agent diff stay in scope and pass this repo’s tests”) and faster than a SDK.
2.5 Cost — cooled as a production blocker, still hot as a personal bill
LangChain: cost dropped down the barrier list; model prices fell. Menlo: 14% of consumer payers at $100+/mo drive 60% of US consumer AI spend. Cloudflare built Code Mode specifically because MCP tool dumps burn context tokens. Helicone (the proxy people used for cost) is in maintenance mode (see §4).
Heat: medium for enterprises (they have AI Gateway / Copilot credits), high for indies whose Anthropic bill spiked overnight.
2.6 Governance theater vs. receipts
EU AI Act transparency rules are in force as of 2 August 2026 (Commission page, last update 3 Aug 2026). High-risk Annex III is deferred to 2 December 2027 by the AI Omnibus (political agreement 7 May 2026, in force 27 July 2026). Chatbot-style disclosure and “this is AI” labeling are live. Claiming “we make you AI Act compliant” is a landmine (brief constraint #4). Emitting a signed, shareable log of what an agent was allowed to do is a product.
Ninth Circuit, 4 August 2026, Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (Cooley alert 6 Aug 2026): when a user directs an agent and traffic is relayed through the user’s machine, the user — not the developer — “accesses” the site under CFAA/CDAFA. The agent is “a tool, not a person.” Direct server-to-server access, or greater developer control, may still be CFAA. ToS/contract claims survive. Do not build a product that logs into third-party sites for users. Do build user-side permits and receipts.
3. Underserved wedges a 1-VPS indie SaaS could own in 90 days
Filter: runs on one Ubuntu VPS (bind 127.0.0.1, nginx 80/443), value in <60 seconds, no sales call, users keep their own LLM keys, not EU Annex III, not a Langfuse clone, not Okta/IBM/Broadcom.
Wedge A — MCP permit gateway for people, not CISOs (strongest)
Job to be done: “I connected Claude Code / Cursor / a custom agent to GitHub, Stripe-test, Notion, and my homelab. I want English rules: allow / deny / ask, a monthly spend cap on my keys, and a signed receipt I can paste to a client or a lead.”
Why it is open: - Okta Agent SSO requires XAA-speaking agents + an Okta tenant. Agent SSO is free if you already pay for Okta. A 4-person agency does not. - Cloudflare MCP portals are excellent and tied to Cloudflare One / Workers. Not a $29/mo indie SKU. - IBM/Microsoft/Broadcom/Dataiku are procurement. - MCP 2026-07-28 made servers ordinary HTTP. A reverse-proxy permit layer is now a weekend-to-MVP, not a protocol science project. - Anthropic’s own spec move to OAuth/OIDC still leaves a hole: tool-level allow/deny/ask and spend, in English, with a playground.
90-day shape: one URL. Paste it as the MCP endpoint. Rules in a textarea. Ask-mode sends a magic link / Slack ping. Receipt is a hash-chained JSON + verify page. BYO keys. No token resale.
Kill risks: becoming “enterprise GRC”; scraping/CFAA agents; selling model access.
Wedge B — agent-permit.yaml in the repo (viral, Dependabot-shaped)
Same enforcement as A, but the policy lives next to the code and the hosted runtime is the default CI/MCP sidecar. A GitHub App comments on PRs that add a new MCP server without a permit. This is how you get distribution without ads: every repo that adds MCP becomes a lead.
Why it is open: GitHub/Microsoft will eventually ship org-level MCP allowlists (Copilot already has enterprise MCP default-deny in docs). They will not ship a pretty, self-serve, cross-IDE policy for a solo Cursor user this quarter.
Wedge C — Spend cap + kill switch for BYO keys (Helicone vacuum)
Helicone processed 14.2T tokens across 16,000 orgs, then Mintlify acquired it 3 March 2026 and put the service in maintenance mode (security, new models, bugfixes; no roadmap). LangSmith LLM Gateway and Cloudflare AI Gateway exist but are platform-tied. LiteLLM is DIY.
A thin OpenAI-compatible proxy: budgets per agent, per project, per day; hard stop; webhook. Do not resell tokens. User’s key, user’s bill, our cap.
Why it is not enough alone: cost is no longer LangChain’s #1 barrier; a pure cost proxy is a feature, not a company. Bundle with Wedge A.
Wedge D — Coding-agent “in-scope” receipts, not generic evals
Do not build another trace UI. Build: given a git diff produced by Cursor/Claude Code, answer in 60 seconds (a) did tests pass, (b) did the diff touch files outside agent-permit.yaml paths, (c) here is a shareable badge. Quality is the #1 production killer; coding agents are the daily habit. LangSmith/Langfuse evals are application-trace evals, not repo-diff evals.
Wedge E — Freelance / client agent receipts (narrow, maybe too narrow)
A signed “this agent, under these rules, spent $X of the client’s key, called these tools, produced this artifact.” Useful for agencies billing AI work. Market is smaller than A–D. Keep as a mode of A, not a standalone company.
Explicitly not wedges (already owned or illegal here)
- Horizontal LLM observability (Langfuse $29, LangSmith $39/seat, Phoenix, Datadog).
- Enterprise agent identity (Okta, Entra/Agent 365).
- “AI Act compliance certificate.”
- Token wallet / prepaid inference (brief: no resale of model access).
- Browser agents that log into third-party sites (CFAA residual risk; ToS; brief kill).
- Quantum classroom or QCaaS (brief kill unless purely educational with no hardware claim — still a demand kill).
- Social network (mission: take social out).
4. What is already owned
Microsoft — the default control plane for anyone on M365
| Product | What they own | Who it is for | Price posture |
|---|---|---|---|
| Copilot Studio | Build/publish agents; data policies; connector/MCP governance via Power Platform; credit caps; Purview maker audit; security scan before publish | M365 / Power Platform tenants | Copilot credits; admin center |
| Microsoft Agent 365 (GA 1 May 2026) | Observe / govern / secure: centralized agent registry, Entra identities for agents, Conditional Access, Purview DLP, Defender | Commercial, per-user license, best with E5 | Procurement, not $19 |
| GitHub Copilot enterprise policies | MCP default-deny, model allowlists, org overrides | GitHub Enterprise | Seat SKU |
They do not own: a self-serve permit URL for a developer who is not in that tenant.
Okta — identity of record for agents that speak XAA
- Agent SSO (GA 24 Aug 2026): free on core SSO. First-class directory identity + short-lived tokens for Cross App Access agents.
- Okta for AI Agents (GA May 2026): shadow discovery, A2A, secrets, certifications, kill switch. Separate subscription.
- Coverage hole (even Okta’s own table): Agent SSO does not answer “what can they do?” Full behavioral governance is the paid SKU, and only for agents they can see.
They do not own: tool-call allow/deny/ask for a local Claude Code process using a raw MCP URL.
IBM — agent ops for the Orchestrate estate
- watsonx Orchestrate agentic control plane; AI Gateway (Bedrock now, Foundry/Vertex next); Trace Inspector; custom LLM-as-judge; AgentOps Agent GA 31 Aug 2026 (eval → GEPA/ACE optimization). Pricing: Standard/Premium, contact us, AWS Marketplace / IBM Cloud Catalog.
- They are explicitly going after cross-platform inventory so “where it was built” stops mattering. That is the enterprise version of Wedge A’s inventory, sold by IBM.
They do not own: a $29 developer playground.
Broadcom / VMware — packet-path AgentMinder
- AgentMinder (announced 31 Aug 2026): identity + intent + runtime policy on every tool call + OTel audit. Coupled to Private AI Cloud, vDefend shadow-AI discovery, Avi WAAP.
- Buyer is a VCF shop. Irrelevant to cryptobook.space.
Dataiku — KPI control tower
- Agent Management (early access 9 Mar 2026, standalone): Copilot Studio, Agentforce, Bedrock, Vertex, LangChain, ServiceNow, etc. Question: “is this agent worth keeping?” not “is it up?”
- Gartner Data & Analytics Summit launch. Enterprise analytics buyer.
Langfuse — cheap, good-enough traces + evals + prompts (MIT)
Opened langfuse.com/pricing:
| Plan | Price | Notes |
|---|---|---|
| Hobby | $0 | 50k units, 30-day data, 2 users |
| Core | $29/mo | 100k units, 90-day, unlimited users, in-app support. Overage $8/100k graduated |
| Pro | $199/mo | 3-year data, SOC2/ISO/BAA |
| Teams add-on | +$300/mo | SSO |
| Enterprise | $2,499+/mo | SCIM, audit logs, SLA |
Self-host OSS is free. A Langfuse clone is not a genius wedge (brief). They already have tracing, cost, evals, prompts, playground, LLM-as-judge.
Helicone — owned by Mintlify, frozen
Opened Helicone blog, 3 March 2026, Cole Gottdank: acquired by Mintlify; “services will remain live for the foreseeable future in maintenance mode” (security, new models, bug/performance fixes). 14.2T tokens, 16,000 orgs, 33M end users. Gateway-shaped hole in the market, not an observability hole.
LangSmith — the full agent-engineering suite, usage-metered
Opened langchain.com/pricing:
| Plan | Seat | Included |
|---|---|---|
| Developer | $0 (1 seat) | 5k base traces/mo, then PAYG |
| Plus | $39/seat/mo | 10k traces, Deployment, Engine, Fleet, Sandboxes, LLM Gateway |
| Enterprise | custom | self-host/hybrid, custom SSO, SLA |
Usage: LCU $1.50 (compute/work), LSU $1.00 (traces/storage). Plus includes LLM Gateway (cost, rate limit, fallbacks, PII redaction, BYO key, “use Gateway with coding agents”), sandboxes, Fleet (natural-language agents + remote MCP), Engine (autonomous failure clustering). Extended trace retention historically 400 days; SaaS cap moving to 180 days (LangChain changelog 14 Sep 2026 — seen in index, not re-opened here; do not over-cite).
They own: teams already on LangChain/LangGraph who want traces + evals + deploy. They do not own: a policy URL you drop in front of Claude Code without adopting LangSmith.
Others in the blast radius (do not fight head-on)
- Cloudflare MCP portals, Code Mode, shadow-MCP Gateway, AI Gateway — platform-tied.
- Datadog / Arize Phoenix / AgentOps (the startup) — observability.
- WSO2 Agent Manager (GA mid-Sep 2026, per trade press not opened as primary — treat as “enterprise API vendors are shipping agent inventories”; do not over-cite).
5. Buyer: who pays $19–99/mo on a card today, no procurement
Procurement is where Microsoft/Okta/IBM/Broadcom/Dataiku live. The card buyer is someone who already pays Anthropic/OpenAI/Cursor and will add a line item the way they added Langfuse Core ($29) or LangSmith Plus ($39/seat).
Primary buyer (best fit)
Individual developers and 2–15 person product teams shipping agents or using coding agents daily.
Evidence:
- LangChain sample: 49% of respondents are in orgs <100; 50% of those already have agents in production. Daily agents = coding assistants.
- Menlo 16 Sep 2026: 55% of US AI users pay; regular agent users 92% pay; 14% of payers at $100+/mo = 60% of US consumer AI spend. A $19–49 guardrail is rounding error next to the model bill, if it prevents one runaway loop.
- Okta: employees bypass official tools because personal accounts are easier (80%) and the team already uses it (78%). The card buyer is that employee or that team lead, not the CISO.
- MarketsandMarkets security report: SMEs are the fastest-growing agentic-security segment; they want “easy-to-deploy tools that do not require deep expertise.”
Persona sketch (concrete):
- Indie / agency builder — sells custom GPT/Claude/MCP agents to clients. Needs a URL they can put in front of the agent, a spend cap on the client’s key, and a PDF/JSON receipt. Pays $29–99 of their own money to look professional. No legal review.
- Startup platform engineer (5–20 people) — rolled Cursor + Claude Code out to the team. Someone’s Anthropic bill hit four figures. They will pay $39/mo for a shared permit + budget before they will buy Okta for AI Agents.
- Power user (Menlo $100+/mo cohort) — already lets agents act without approval (32% have done it once). Will pay for a kill switch the way they pay for 1Password.
Who does not buy at $19–99 on a card
- Anyone whose agent sits in Copilot Studio / Agent 365 / Okta / watsonx / VMware. Their “governance” is already a line item in an E5/Okta/IBM contract.
- CISOs. They buy Okta/CrowdStrike/Microsoft. A 1-VPS indie will lose that deal and should not try.
- Healthcare/HR/credit/education-admissions buyers (Annex III / US legal landmines).
Pricing analog (opened pages)
- Langfuse Core $29 is the market-clearing “I have a production LLM app” price.
- LangSmith Plus $39/seat is the market-clearing “my team ships agents” price.
- Target: $19 playground / $39 team / $99 agency with usage overage only on policy decisions and receipts, not on tokens (tokens are the user’s). Charge for protected tool-calls or verified receipts, not for inference.
Conversion motion that matches the buyer
Homepage playground: paste an MCP URL or a sample tools/call JSON → see allow/deny/ask in under 60 seconds → copy a gateway URL. GitHub App optional. Stripe Checkout. No SOC2 claim. No “AI Act compliant” claim. Disclose that the product is software that enforces your rules and emits logs.
6. Five product hypotheses, ranked
Score: Demand (what Sep 2026 buyers already feel) × Ease of adoption (time-to-value, no SDK required) × Low regulation (not Annex III, not CFAA, not money transmission, not fake compliance). Scale 1–5. Rank by product of the three.
Rank 1 — Permit Gateway: English rules + allow/deny/ask + spend cap + signed receipts
Demand 5 × Adoption 5 × Low-reg 5 = 125
- What: A single HTTPS endpoint that fronts MCP (and optionally OpenAI-compatible tool calls). Policy in English and/or YAML: which tools, which argument patterns, max $ per day on the user’s own key, ask-the-human on write tools. Every decision is a signed receipt (hash chain + public verify page).
- Why demand is now: MCP is the standard (400M SDK downloads; 950+ Claude connectors). Shadow MCP is a named Cloudflare product. Okta says only 34% apply human-grade controls to agents. Coding-agent users paste servers into config today.
- Why adoption is easy: one URL. No SDK if the client already speaks MCP or an OpenAI base URL. Playground on the homepage.
- Why low-reg: transparency / limited-risk. Disclose AI. Do not claim AI Act/NIST compliance. Do not touch biometrics, employment, credit, education admissions, law enforcement. Users keep keys. No funds held. No logging into third-party sites (Ninth Circuit: stay on the user’s side of the wire).
- 90-day MVP on this VPS: nginx → Node/Python gateway → Postgres receipts → Stripe. Bind 127.0.0.1. Policy engine = allowlist + regex + dollar cap. Ask-mode = email/Slack webhook.
- Not a me-too of: Langfuse (traces), Helicone (dead roadmap), LangSmith (evals+deploy), Okta (IdP), IBM (control plane), Broadcom (VMware).
Rank 2 — agent-permit.yaml hosted runtime (Dependabot for MCP)
Demand 5 × Adoption 4 × Low-reg 5 = 100
- What: A repo file plus a GitHub App plus the Rank-1 runtime. PRs that add MCP servers or widen tools get a bot comment. Default policy: deny write, cap spend, ask on
rm,push --force, payments. - Why: Viral distribution. Matches how developers already adopt Dependabot, CodeQL, pre-commit.
- Adoption drag: needs a GitHub App review and a YAML schema people will bikeshed. Still ships in 90 days if Rank 1 exists.
- Low-reg: same as Rank 1. Do not auto-merge. Do not claim to be a security auditor.
Rank 3 — BYO-key spend cap / kill switch (Helicone-shaped, policy-first)
Demand 4 × Adoption 5 × Low-reg 4 = 80
- What: OpenAI-compatible proxy. Hard daily/monthly caps per project/agent. Kill switch. Webhook. Optional cache. Never sell tokens.
- Why: Helicone maintenance mode (3 Mar 2026) left 16k orgs on a frozen proxy. Menlo power users spend $100+/mo. Cloudflare Code Mode proves token waste is a felt pain on MCP.
- Adoption: change
base_url. Classic Helicone motion. - Reg drag: proxying prompts is a data-handling product (DPA, region, no training). Not high-risk, but not “just a static site.” Do not store bodies longer than needed. EU transparency: disclose the proxy is in the loop.
- Do not ship this without Rank 1’s tool-level permits — a cost proxy alone is a feature LangSmith Gateway and Cloudflare AI Gateway already sell.
Rank 4 — Coding-agent in-scope receipt (diff + tests + permit, not traces)
Demand 4 × Adoption 3 × Low-reg 5 = 60
- What: Drag a PR or
git diff. Get a badge: tests, path allowlist, spend, model. Shareable. Built for Cursor/Claude Code output, not for LangGraph traces. - Why: Quality is the #1 production barrier; coding agents are the daily tool; Langfuse/LangSmith evals are the wrong object (traces, not diffs).
- Adoption drag: needs a GitHub integration or local CLI; “60 seconds” is true only if the playground has a canned repo. Still viable as a view on Rank 1 receipts.
- Low-reg: developer tooling. Not employment decisioning (do not score people).
Rank 5 — Agency / freelance agent receipts as a standalone SKU
Demand 2 × Adoption 4 × Low-reg 5 = 40
- What: White-label verify page: “Agent X, under policy Y, spent $12.40 of the client’s key, called
repo.read14 times, never calledpayments.create.” - Why it scores lower: niche buyer, longer explanation, easy for Rank 1 to include as a toggle. Too narrow as the only product (brief candidate C).
- Keep as a packaging of Rank 1 for the $99 agency plan.
Hypotheses not ranked (killed)
| Idea | Kill reason |
|---|---|
| Langfuse/Helicone/LangSmith clone | Crowded, cheap, OSS; Helicone frozen does not mean “rebuild Helicone” |
| “AI Act / SOC2 compliance” SaaS | Legal landmine; Annex III deferred but claiming compliance is still banned by brief |
| Browser agent that logs into SaaS as the user | Ninth Circuit is fact-specific; ToS; CFAA residual; brief explicit kill |
| Enterprise agent identity | Okta Agent SSO is free; Entra Agent 365 is GA |
| Quantum circuit classroom / QCaaS | Demand/monetization kill; no hardware; brief |
| Social / community for agents | Mission: take social out |
| Generic multi-agent orchestrator | ServiceNow, IBM, Microsoft, Salesforce already bought or built this (Moveworks $2.85B, Fin $3.6B) |
Implications for the CryptoBook pivot (for PM, not a decision)
- The genius wedge is not “governance.” Governance is what Okta, Microsoft, IBM, Broadcom, and Dataiku shipped between May and early September 2026. The genius wedge is governance for people who will never see those products: a drop-in MCP/tool permit with English rules, a spend cap on their own keys, and a signed receipt.
- Ship Rank 1 + Rank 2 as one product. Rank 3 is a mode (the proxy). Rank 4–5 are views/exports of the same receipts.
- Price like Langfuse Core, not like Agent 365. $19 / $39 / $99, card, BYO keys.
- Do not mention quantum. Do not rebuild a social graph. Do not sell tokens. Do not say “compliant.”
- Legal posture to print on the site: we enforce your rules on your tools with your keys; we log decisions you asked us to log; we are not your lawyer, auditor, or identity provider; agents that browse third-party sites do so as you (Ninth Circuit, 4 Aug 2026).
Sources actually opened
- Bain & Company via PR Newswire, 7 May 2026. “SaaS’ next $100 billion opportunity could come from agentic AI.” https://www.prnewswire.com/news-releases/saas-next-100-billion-opportunity-could-come-from-agentic-ai--bain--co-research-302765161.html
- MarketsandMarkets via PR Newswire UK, 20 Aug 2026. “Agentic AI Market worth $205.88 billion by 2033.” https://www.prnewswire.co.uk/news-releases/agentic-ai-market-worth-205-88-billion-by-2033--report-by-marketsandmarkets-302856176.html
- MarketsandMarkets via PR Newswire, 4 May 2026. “Agentic AI Security Market worth $13.52 billion by 2032.” https://www.prnewswire.com/news-releases/agentic-ai-security-market-worth-13-52-billion-by-2032--marketsandmarkets-302761232.html
- Menlo Ventures via GlobeNewswire, 16 Sep 2026. “2026 State of Consumer AI” ($40B spend; 41% tried an agent). https://www.globenewswire.com/news-release/2026/09/16/3363086/0/en/menlo-ventures-report-consumer-ai-spend-tripled-to-40b-this-year-even-as-user-growth-barely-budged.html
- LangChain, 12 June 2026. State of Agent Engineering (1,340 responses, Nov–Dec 2025). https://www.langchain.com/state-of-agent-engineering
- Okta, 24 Aug 2026. “Okta brings first-class identity to AI agents with Agent SSO.” https://www.okta.com/newsroom/press-releases/okta-brings-first-class-identity-to-ai-agents-with-agent-sso/
- Okta, 27 May 2026. “AI Agents at Work 2026” (Apprize360 survey, March 2026). https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/
- IBM, 3 Sep 2026. watsonx Orchestrate: AI Gateway, Trace Inspector, AgentOps Agent GA. https://www.ibm.com/new/announcements/new-in-ibm-watsonx-orchestrate-cross-platform-agent-discovery-custom-evaluation-and-agentops-agent-goes-ga
- Broadcom via GlobeNewswire, 31 Aug 2026. AgentMinder + vDefend + Avi for agentic AI. https://www.globenewswire.com/news-release/2026/08/31/3353355/19933/en/broadcom-delivers-end-to-end-security-identity-and-observability-for-agentic-ai.html
- Dataiku, 9 Mar 2026. “Platform for AI Success” / Agent Management early access. https://www.dataiku.com/company/news/dataiku-launches-the-platform-for-ai-success
- Microsoft Learn, Copilot Studio security and governance (updated Aug 2026). https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance
- Microsoft Learn, Agent 365 overview (GA 1 May 2026; page 19 Aug 2026). https://learn.microsoft.com/en-us/microsoft-agent-365/overview
- Langfuse pricing (opened 18 Sep 2026). https://langfuse.com/pricing
- LangSmith / LangChain pricing (opened 18 Sep 2026). https://www.langchain.com/pricing
- Helicone, 3 Mar 2026. “Helicone is joining Mintlify.” https://www.helicone.ai/blog/joining-mintlify
- Anthropic, 28 Jul 2026. “Bringing MCP 2026-07-28 to Claude” (400M SDK downloads). https://claude.com/blog/bringing-mcp-2026-07-28-to-claude
- Cloudflare, 14 Apr 2026. “Scaling MCP adoption” (portals, Code Mode, shadow MCP). https://blog.cloudflare.com/enterprise-mcp/
- European Commission, AI Act overview (last update 3 Aug 2026; Omnibus high-risk dates; transparency in force 2 Aug 2026). https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- NIST AI 100-1, AI Risk Management Framework 1.0, Jan 2023. https://doi.org/10.6028/NIST.AI.100-1 and https://www.nist.gov/artificial-intelligence
- Cooley, 6 Aug 2026. Ninth Circuit Amazon v. Perplexity, No. 26-1444 (opinion 4 Aug 2026). https://www.cooley.com/news/insight/2026/2026-08-06-ninth-circuit-rules-on-ai-agent-access-to-third-party-websites-under-cfaa
Not used as citations (searched but not opened, or blocked): Gartner 25 Jun 2025 “40% of agentic projects canceled by 2027” press page (bot-wall); Menlo 2025 enterprise $37B report body (URL returned title only); Reuters Gartner recap.
Researcher note: if every idea above is later killed, the patch is still Rank 1 with a narrower object — MCP tool-call permits for coding agents only, no generic “agent platform,” no identity-provider claims.