The original positioning was an AI-augmented SOC: we investigate, we deliver the verdict, the customer pays us. Three months in I threw it out. The architecture had already become something else, and the positioning was the last part of the business still describing the old thing.
What was wrong with being the SOC
Two things, and the second is the one that actually mattered.
First, it drops you into the most crowded category in security services. "AI-powered managed detection" is a sentence hundreds of companies are already saying, most of them with sales teams, reference customers and budgets. Competing there as one person is not a strategy.
Second — and this is the part I was slow to see — it contradicted the architecture I had already built. The system deploys inside the customer's own tenant. The compute runs on their cloud bill. Nothing routes through my infrastructure. That is not the cost structure of a service business, where each new customer adds delivery cost. It is the cost structure of a product, where each new customer adds almost nothing. I had built a product and was selling it as a service, which is the worst combination of the two: a product's margins priced like a service, with a service's delivery expectations attached.
The reposition
The engine, not the SOC. A managed service provider deploys it into their client's tenant, it investigates, and the provider delivers the resulting security service under their own brand. Their client may never know the engine exists.
The buyer of record is the provider, not the small business. That single change fixes several problems at once. The provider already owns the client relationship. They already bill monthly. They already think in resale margin, so a wholesale price is a familiar conversation rather than a negotiation. And the small business — who genuinely does not self-diagnose a need for security investigation, and will not buy it directly — never has to be convinced of anything.
| As the SOC | As the engine | |
|---|---|---|
| Who signs | The small business | The service provider |
| Who delivers | Me | The provider, under their brand |
| Pricing shape | Per seat, negotiated | Flat per tenant, published wholesale |
| Tier-1 support | Mine | The provider's |
| Who does response | Ambiguous | The provider, on access they already hold |
Deployment is free, deliberately
The tooling that prepares a tenant — the scripts, the connector setup, the permission grants — is free and will stay free. This confuses people, so it is worth being explicit.
Tenant preparation is the provider's own billable work. They already charge their client for security configuration; that is a normal line on a normal invoice. Charging them for the privilege of doing work they are getting paid for is backwards, and it puts a toll gate directly in front of adoption. Free deployment tooling is what makes the thing trivially resellable, and the recurring subscription is where the money is.
The first months are free too, for a reason that is specific rather than promotional: the value of this system is partly accumulated. It learns the tenant — which alerts are routine, which service accounts are supposed to behave strangely, what the customer has already confirmed as expected. In month one, that accumulation does not exist yet. Charging full price for the noisiest month of the relationship is charging most for the least.
What the moat is, honestly
Not the investigation loop. The platform vendor is shipping agentic triage natively, and the correct planning assumption is that autonomous alert investigation becomes a cheap commodity feature. Building the story on the loop would be building it on sand.
Two things compound instead. The first is accumulated tenant context — not the facts themselves, but the mechanism that captures them: a non-expert answers a question in plain language in a chat channel, and that answer becomes a durable, operational fact that changes how future alerts are handled. Cancel and you do not return to neutral; you return to month one. That switching cost is built by the customer, out of their own answers.
The second is distribution to a segment the platform vendors will not chase: the long tail of small generalist providers running Business Premium tenants.
What this did not fix
Positioning is a hypothesis about who buys and why. Mine was coherent, internally consistent, and aligned with the architecture — and it produced zero conversions over the following quarter, for reasons that had nothing to do with whether the positioning was correct.
Getting the model right is necessary and it is not sufficient, and I spent considerably longer on the necessary half than on the other one.