Work Rebuilt

Software vendor operations

The tools holding your jobs, files, and customer records are also holding part of the business together

Boundries

Most software enters a small business quietly.

Someone needs a better scheduling tool. A client asks for a portal. The office manager finds an app that cleans up approvals. There is a free trial, a short setup, and suddenly the problem feels smaller.

Then the tool stays.

Two years later it contains the customer history, job notes, photos, documents, invoice status, employee access, and a few automations nobody remembers building. It may send messages or create tasks on the team's behalf. Removing it would be less like canceling a subscription and more like taking a wall out of the office.

That is the part we tend to miss when comparing software. We look at features, price, and whether people will use it. All important. But a critical software vendor is also supplying part of the business's memory and continuity.

I'm George, founder of SystemFabric. I write about useful systems and better workflows.
You can also find a version of this article on substack >

The tool is inside the workflow

The risk is not limited to a dramatic breach or a company disappearing overnight.

A vendor can change its pricing model. A plan can lose a feature. An integration can break after an update. The only administrator can leave the company. A service outage can arrive on the day crews need addresses, a filing is due, or a client expects an approval.

Small businesses feel these problems quickly because there is rarely a backup department waiting nearby. The workaround is often one person, a spreadsheet, and several apologies.

NIST published a supplier due-diligence quick-start guide in July that looks at technology suppliers through areas including provenance, resilience, foundational cybersecurity practices, ownership and control, and supply-chain tiers. The full language is more formal than most small teams need.

The underlying idea is useful, though:

The software boundary is part of the system, even when the interface makes it feel invisible.

If an app holds client files, controls who sees project information, or takes action inside another system, the business has a supplier relationship—not just a login.

This does not mean every tool needs a six-week review. A color picker and a payroll platform deserve different levels of attention. The depth should follow the consequence. Ask what stops, leaks, becomes inaccessible, or has to be rebuilt if this tool has a bad day.

Five questions worth answering

For a critical vendor, I would want a one-page answer to five questions.

  1. What does it hold? List the important records and attachments, not a vague category like “project data.” Customer contacts, estimates, site photos, contracts, time entries, payment status, and internal notes may have different consequences.
  1. What can it see or change? Connected tools increasingly read inboxes, create tasks, update customer records, or send messages. Limit access to what the job requires. The FTC's small-business cybersecurity guidance makes the same practical point: vendor access should be need-to-know and limited to the time required.
  1. Can we get the useful record out? “CSV export available” is not enough if the export drops attachments, history, relationships, approvals, or the rules hidden inside the workflow. Export a sample. Open it. Make sure someone other than the current administrator can understand it.
  1. How does work continue without it? The answer does not have to be elegant. It may be a printable route list, a daily spreadsheet export, a local contact list, or a manual approval rule. A rough fallback is still better than discovering during an outage that nobody knows the next job address.
  1. Who owns the relationship? Name the person responsible for renewal dates, access reviews, vendor notices, backups, and the fallback plan. “Operations” is not a person. Neither is “IT,” especially when there is no IT department.

The useful artifact could be very small:

  • Vendor and account owner
  • Critical data and connected systems
  • People or roles with administrative access
  • Renewal date and pricing unit
  • Export method and last test date
  • Minimum fallback if the product is unavailable

This is not paperwork for its own sake. It is the map you want when the normal interface is gone.

Control and responsibility travel together

Local or self-hosted software can make ownership and portability more visible. It can also move updates, backups, security, and recovery onto the buyer. Cloud software can make all of that easier while increasing dependence on the vendor. Neither arrangement is automatically safer.

The useful question is who carries each responsibility and whether the business knows it.

That is why “easy to start” and “easy to leave” should be separate buying criteria. A polished import process tells you how badly the vendor wants your data. The export and recovery process tells you how well the relationship respects your business.

Start with the three tools the company could least afford to lose tomorrow. Write down the five answers. Test one export. Make one fallback usable.

You do not need enterprise procurement theater. You need enough of a boundary that a software surprise remains an inconvenience instead of becoming the operating plan for the week.

Weekly spots

NIST's supplier due-diligence quick-start guide is worth a look when a tool will hold critical records or connect deeply to the business. The language is formal, but its sections on provenance, resilience, security practices, ownership, and dependencies make a solid vendor-review prompt.

AI ROI Calculator

Stop wondering if AI is worth it.

Calculate your potential ROI in under 3 minutes.