The Agent Layer's Claim on the Customer Relationship
The most valuable asset in software was never the software, it was the customer relationship the software sat on top of. As agentic AI inserts itself between users and the apps they used to touch directly, that relationship is up for grabs. Whoever the customer talks to, trusts, and instructs becomes the new front door, and the SaaS vendor behind the agent risks demotion to a silent backend utility. This piece maps how the agent layer stakes its claim, why incumbents are right to be nervous, and what actually determines who owns the customer in a GaaS world.
Table of Contents
- The relationship was always the real product
- What "owning the customer" actually means
- How the agent layer inserts itself
- The three contested layers of ownership
- Why incumbents are not as safe as they think
- Where the agent layer's claim falls apart
- Strategic positions for the next five years
- Insights Most People Overlook
- References
The relationship was always the real product
Ask any SaaS founder what their company is worth and they'll quote net revenue retention before they mention a single feature. That's the tell. The durable value in software-as-a-service was never the code, code gets copied, undercut, and open-sourced within eighteen months. The value was the relationship: the renewal that happens on autopilot, the procurement contact who defaults to your logo, the admin who knows your UI in their sleep and won't switch because retraining the team is a quarter-long project nobody wants to own.
That relationship is built from accumulated switching costs, habituated workflows, and a login that the user reaches for without thinking. For two decades, the application was the relationship. You couldn't get the value without touching the vendor's interface, so the vendor stayed top of mind, stayed in the procurement cycle, and stayed in control of the roadmap conversation.
Agentic AI breaks that coupling. When an agent does the work, pulls the report, reconciles the invoices, drafts the response, books the logistics, the human stops touching the underlying app. And the moment a human stops touching your interface, your grip on the relationship starts to loosen, even if your software is still running underneath. This is the quiet structural threat that sits beneath the louder "SaaS is dead" headlines, and it deserves to be examined on its own terms.
What "owning the customer" actually means
"Owning the customer relationship" gets thrown around loosely, so it's worth being precise. Ownership is really a bundle of four distinct claims, and the agent layer contests each of them separately:
- The interface of trust. Who does the customer instruct and believe? When you say "book me a flight" or "close the books for May," who hears it?
- The point of accountability. When something goes wrong, who gets the call? Accountability and trust travel together, the party blamed for failure is usually the party credited for success.
- The data of record. Who accumulates the history, preferences, and context that make future interactions better and switching painful?
- The commercial moment. Who controls the renewal, the upsell, the pricing conversation, and the contract?
A vendor can win some of these and lose others. The danger for incumbents is that the agent layer is positioned to capture the first two, trust and accountability, which are the ones customers actually experience. You can own the system of record and still wake up one day as a faceless API behind someone else's agent. That's the system-of-record vs. system-of-action tension playing out at the level of the relationship itself.
How the agent layer inserts itself
The insertion happens gradually, then suddenly. It usually moves through three stages.
First, the agent shows up as an assistant inside the app, a copilot that drafts and suggests while the human stays in the driver's seat. This feels safe to incumbents; the relationship is untouched because the user is still logged in and clicking around. Salesforce, ServiceNow, and HubSpot all started here, and you can read their early moves as defensive habit-preservation as much as innovation.
Second, the agent moves to the edge of the app, operating across multiple tools to complete a workflow. Now the human is instructing one agent that orchestrates five backends. The user's attention consolidates onto the orchestrator. This is the "agent does the workflow the SaaS used to host" pattern, and it's where the relationship starts migrating.
Third, and this is the contested frontier, the agent becomes the customer's default counterparty. The human no longer thinks in terms of "I use Tool X and Tool Y." They think "I ask my agent." At that point the underlying applications are commodity execution surfaces, and the agent provider has annexed the relationship. Whether the agent is built by a startup, a foundation-model provider, or the incumbent itself is the entire ballgame.
The mechanics of this shift mirror what a16z has described as the move toward agents becoming the new system of action sitting above legacy systems of record, a layering that quietly reassigns who the user actually relates to.
The three contested layers of ownership
It helps to picture the stack as three layers, each fighting for the relationship.
The model layer
Foundation-model providers (OpenAI, Anthropic, Google) sit at the bottom and have the most direct line to consumer mindshare. When a knowledge worker says "I asked ChatGPT to handle it," the model brand has captured the trust claim outright, no SaaS vendor in the loop at all. The risk for everyone above them is platform dependency on a foundation-model provider: you can build the world's best vertical agent and still be one model-provider product launch away from disintermediation.
The agent layer
This is the orchestration tier, the vertical agents and agent platforms that package model capability into reliable, outcome-priced workflows. This layer makes the strongest defensible claim on the relationship because it owns the workflow context, the accountability for outcomes, and increasingly the data exhaust of every task it completes. The emerging "agent of record" concept lives here: the agent the customer designates as the trusted executor for a domain, with the lock-in that designation implies.
The application layer
The old SaaS apps. In the optimistic incumbent reading, they remain the indispensable system of record with the data moat. In the pessimistic reading, they get commoditized into the application layer, plumbing that the agent calls, invisible to the human. Most incumbents will land somewhere in between, and where they land depends almost entirely on whether they ship their own credible agent before someone else's agent makes them optional.
Why incumbents are not as safe as they think
The standard incumbent comfort blanket is the data moat: "agents need our data, our data lives in our system, therefore agents can't disintermediate us." There's real truth here, proprietary data and deep integrations are a moat agents can't easily cross. But it's a narrower defense than it looks, for three reasons.
The data moat protects the system of record, not the relationship. An agent can absolutely sit on top of your data, querying it through an API while presenting itself, not you, as the thing the customer trusts. You keep the data and lose the face. Gartner has flagged this exact dynamic in its analysis of how agentic AI will reshape enterprise software interaction patterns, where the application becomes a service called by an orchestrator rather than a destination the user visits.
Second, data moats erode at the integration boundary. The data-access wars are already starting, incumbents tightening API terms to keep agents out, but gatekeeping is a tax, not a wall. It buys time and breeds resentment, and resentment is what makes a customer receptive to the agent-native competitor who promises to never hold their data hostage.
Third, the buyer is changing. As McKinsey has documented in its work on the economic potential of generative AI and agentic workflows, value is shifting from software budgets toward labor budgets, which means the person deciding to deploy an agent is increasingly a line-of-business operator buying an outcome, not an IT admin renewing a seat license. That buyer doesn't have a relationship with your UI to protect. They have a problem and a P&L. The relationship you spent a decade building with the admin may not transfer to the person now holding the agent budget.
Where the agent layer's claim falls apart
It would be lazy to declare the agent layer the automatic winner. Its claim on the relationship has real failure modes, and honest strategy requires naming them.
Accountability is a double-edged sword. The agent that takes credit for outcomes also takes the blame for failures. When an autonomous agent makes a costly mistake, a misfiled compliance report, a wrong wire transfer, the customer's trust can collapse overnight in a way that rarely happens with a passive tool the human was supervising. Reliability isn't just an engineering problem; it's the precondition for owning the relationship at all. An agent that can't be trusted to act unsupervised never gets to be the counterparty.
Regulated and high-stakes domains resist disintermediation. In healthcare, finance, and law, the human-of-record requirement isn't going away, and the incumbent system that carries the audit trail and the liability framework retains its grip. These are the agent-proof SaaS categories, and they're more numerous than agent maximalists admit.
Switching costs reassert themselves at the agent layer. The agent that owns your relationship today builds its own lock-in tomorrow, accumulated context, learned preferences, integrated workflows. The relationship doesn't become free; it just changes landlords. Customers who fled SaaS lock-in may find agent lock-in equally sticky, which tempers the disruption thesis considerably.
Distribution still beats capability. The incumbent with ten thousand existing customers and a procurement relationship can ship a "good enough" agent and reach more of the market than a superior startup agent with no distribution. The relationship the incumbent already owns is itself a defense, if they move fast enough to put their own agent in front of it.
Strategic positions for the next five years
Given all that, the viable positions sort into a small number of plays.
Become the agent of record yourself. The cleanest incumbent defense is to be the agent the customer trusts, not just the system it calls. This is the logic behind every major vendor's agent push, and it requires the painful choice to cannibalize your own seats before someone else does.
Own an indispensable layer the agent can't route around. If you can't own the relationship, own the data of record or the system of action so completely that no agent can deliver the outcome without you, and price accordingly. Being essential plumbing is a worse position than owning the face, but it beats being optional plumbing.
Win a domain too consequential to delegate. Plant your flag where accountability, regulation, or trust requirements keep a human-and-incumbent in the loop, and make your reliability and auditability the product.
Be the agent-native challenger. For startups, the opening is precisely the relationship incumbents are too slow to defend. Show up where the buyer is a line-of-business operator with an outcome budget, promise data portability instead of lock-in, and own the trust claim before the incumbent ships its copilot. This is the core of the thin-wrapper survival question: the wrappers that survive are the ones that convert a model capability into an owned customer relationship, not the ones that just resell tokens.
The common thread: the relationship is the prize, and it's now decoupled from the software. Whoever the customer instructs, trusts, and holds accountable owns the future. Everyone else becomes a billable backend.
Insights Most People Overlook
-
The data moat and the relationship are two different assets, and incumbents conflate them. You can keep all your data and still lose every customer-facing moment to an agent that queries you through an API. The companies that survive will be the ones that recognize "we have the data" is not the same sentence as "we own the customer," and stop treating the first as if it proves the second.
-
Accountability, not interface, is the real ownership signal. Everyone watches the UI to see who "owns" the customer, but the deeper claim is who gets blamed when things break. The party customers call in a crisis is the party that owns the relationship, which is why agents that take on unsupervised, high-consequence work are making a far bigger land grab than copilots that merely suggest.
-
Agent lock-in will be stickier than SaaS lock-in, and that undercuts the liberation narrative. The "agents free you from SaaS captivity" pitch ignores that an agent accumulating your context and preferences becomes harder to leave than any login screen. The relationship is being re-monopolized, not democratized. Smart buyers should be negotiating context portability now, while agent vendors are still desperate for adoption.
-
The most dangerous competitor to a SaaS vendor is its own foundation-model supplier. Vertical agents fret about startups, but the entity with the most direct line to customer trust is the model provider the whole stack depends on. A single consumer-facing product launch from that layer can disintermediate everyone above it, and there's no contract clause that fully protects against your supplier becoming your front end.
-
Owning the relationship may matter more in a usage-shrinking world than in a growing one. As seat counts and software usage contract, the customers you keep become disproportionately valuable. The relationship isn't just the prize in the agent transition, it's the only thing appreciating while everything priced per-seat depreciates. That reframes relationship ownership from a marketing concern into a survival metric.
References
More in vs SaaS
- Enterprise Software Contracts in a Usage-Shrinking World
- How SaaS Valuations Are Being Rewritten for the Agent Era
- The Disintermediation of Professional Services: What Agents Actually Replace, and What They Can't
- The Bundled-Agent Strategy of the Mega-Vendors: How Platforms Hope to Outrun the Unbundlers
- Platform Risk: What You're Really Signing Up For When You Build Agents on a Foundation-Model Provider