saas

13 posts

github

Transitioning as a hubber (opens in new tab)

Arthur Searle describes transitioning at GitHub as a largely smooth experience, enabled by an inclusive, remote-first culture and strong workplace support. Using handles, written communication, flexible avatars, and gender-affirming benefits reduced many common sources of stress. His experience shows that transition can involve both bureaucratic challenges and profound joy when colleagues respond with acceptance and care. ## A Career Built at GitHub - Searle began in IT support and operations before teaching himself to code. - He joined GitHub’s IT Engineering team after a colleague’s referral and moved to Enterprise Security six months later. - His work has included: - Helping migrate GitHub’s main SaaS platform to infrastructure as code. - Speaking at Oxford University about version control. - Throughout his transition, his handle—“gleeblezoid”—remained constant, providing continuity at work. ## How GitHub’s Culture Supported Transition - GitHub’s remote-first structure reduced anxiety around appearance, commuting, and in-person interactions. - Much of Searle’s work happened through written communication in Slack and GitHub, limiting the pressure of speaking while undergoing voice training and hormone-related voice changes. - Employees commonly use handles and informal avatars, making gender assumptions based on appearance less central. - Searle was able to update his name and pronouns in internal systems, with colleagues consistently using them. ## Gender-Affirming Benefits - GitHub covered gender-affirming healthcare for employees. - Benefits included reimbursement for: - Voice training. - Hormone replacement therapy prescriptions. - Therapy. - The main remaining difficulty was ordinary administrative friction, such as changing his legal name in payroll systems. ## Acceptance, Joy, and Belonging - Searle contrasts his experience with people who remain closeted, repeatedly come out to new coworkers, or face extensive bureaucracy. - Colleagues treated his transition as a normal part of his life and expressed genuine happiness for him. - Small gestures had a major emotional impact, including hearing his name and pronouns used at work for the first time and receiving a shaving kit from a teammate. - He emphasizes that being trans is not defined only by hardship; there is also joy in living openly and being supported by others. GitHub’s example suggests that inclusive policies, flexible communication practices, and everyday respect can make workplace transition significantly safer and more affirming. For organizations, support should extend beyond formal benefits to the culture and systems employees use every day.

stripe

Solo founding is at an all-time high: Top performers have these traits in common (opens in new tab)

Solo founders now represent 63% of new Stripe Atlas C corps, but performance is increasingly polarized: median revenue is falling while top performers grow rapidly. Stripe’s analysis of thousands of solo-founded startups found that the strongest companies tend to be AI-native, global from launch, B2B-focused, and effective at retaining customers. Multifounder startups generally pull ahead over time, though exceptional bootstrapped solo founders can nearly match them. ## AI-Native Products - Top-decile solo founders were about twice as likely to build products whose core functionality depends on AI models. - By year two, AI-native startups generated nearly twice the revenue of other solo-founded companies. - Their advantage was broad-based, spanning approximately the 50th through 95th revenue percentiles—not merely the result of a few extreme outliers. - AI lowers the technical barrier, allowing founders to focus on solving problems quickly, shipping products, and finding distribution. ## Global Sales from Launch - Top-performing solo founders sold to an average of 10 countries in their first month, compared with three for median founders. - By month 24, they reached about 40 non-US countries, versus six for median founders. - International customers generated 51% of top-decile revenue, compared with only 2% for median companies. - Early access to large markets such as the US helped accelerate growth. ## B2B Business Models - Top solo founders were nearly 30% more likely to build B2B companies. - By month 24, the median solo B2B startup generated more than four times the revenue of the median B2C startup. - Among top performers, B2B companies earned nearly twice as much as comparable B2C companies. - This advantage persisted among bootstrapped startups, suggesting it was not primarily caused by easier access to funding. ## Early Customer Retention - Nearly 30% of customers at top-decile startups returned the following month, compared with 8% at middle-decile companies. - Top performers began recovering churned customers around three months earlier. - By the start of year two, their first-month customers were spending 47% more than at acquisition—roughly twice the increase seen among middle-decile startups. - In B2B, top solo founders retained initial customers at six times the rate of median founders. - Recurring billing was more common among top performers, by 26 percentage points in B2B and 20 points in B2C. ## Solo Founders Compared with Teams - Solo startups initially generated more revenue than multifounder startups, but multifounder companies led by month 24. - Top-decile multifounder startups produced 53% more revenue than top-decile solo startups, even after accounting for funding. - Among the very best bootstrapped companies, the gap narrowed to just 5%. - Exceptional solo founders compensate for limited headcount through speed, resourcefulness, hiring, advisors, and founder networks. Solo founders appear most likely to succeed when they use AI to move quickly, target business customers, sell internationally from the beginning, and validate demand through strong retention. Teams still offer a long-term advantage, but highly capable, well-connected solo founders can approach team-level performance without outside funding.

stripe

Five vertical SaaS insights from Sessions 2026 (opens in new tab)

Vertical SaaS platforms are responding to AI pressure by becoming more deeply embedded in customers’ operations rather than relying on software features alone. Payments, lending, compliance, and other financial or operational services create stronger retention and revenue opportunities, while AI products help platforms remain competitive at the software layer. The post concludes that platforms should monetize AI experimentally and prepare to support emerging agentic commerce. ## Expanding Beyond Software - AI makes software features easier to replicate, but vertical platforms retain an advantage through deep industry knowledge and workflow integration. - Embedded payments connect platforms to transaction processing, revenue tracking, and cash-flow management. - Median payments adoption increased from 27% in 2024 to 40% in 2025, while top Stripe platforms exceed 80%. - Successful companies make payments a company-wide priority: - Include payments in sales demos and compensation plans. - Set goals beyond Gross Payment Volume, including company-wide ARR. - Reinforce adoption through onboarding and customer success. - Embedded payments can generate approximately $4,200 in incremental ARR per adopting customer. - Platforms offering embedded financial products experience 11% lower annual churn, while multiproduct platforms grow revenue 49% faster than software-only peers. ## Building Operational and Financial Moats - Payments can lead to additional services such as capital, banking, cards, payroll, and bill payment. - TheCut’s Stripe Capital program generated $788,000 in accepted financing from 167 barbers within 24 hours. - Financial products help businesses purchase equipment, manage seasonal slowdowns, and fund marketing. - Operational services can also create defensibility: - Moxie embeds compliance tools to help medspas maintain licenses. - Slice negotiates wholesale pizza-box pricing for restaurants. - These specialized services are difficult for a new AI-native competitor to reproduce immediately. ## Developing Vertical AI Products - Most surveyed SaaS platforms—87%—see AI more as an opportunity than a threat. - Platforms are adding industry-specific AI tools, including: - Toast IQ, which identifies local food trends for restaurants. - Quipli, which generates leads from newly filed equipment-rental permits. - Clio’s assistant, which drafts legal documents, summarizes files, and surfaces client insights. - AI is positioned as a way to automate repetitive work while using the platform’s existing customer and industry context. ## Experimenting with AI Pricing - Eighty-six percent of SaaS platforms with AI features charge for them. - Pricing models include: - Bundling AI into existing subscriptions. - Premium tiers. - Stand-alone usage-based or outcome-based pricing. - Since 44% of platforms expect to change their AI pricing within a year, companies should test willingness to pay before committing to a model. - Charging separately can help determine whether AI delivers meaningful customer value. ## Preparing for Agentic Commerce - AI agents are expected to influence product discovery, purchasing decisions, and checkout. - Platforms are preparing with agent-readable catalogs and headless checkout APIs. - This infrastructure is intended to support a projected $5 trillion agentic-commerce opportunity. - Retail platforms still face foundational challenges, particularly inconsistent or poorly structured product data optimized for human shoppers. Vertical SaaS companies should combine AI innovation with deeper operational integration. The strongest long-term strategy is to offer industry-specific automation while using payments, financial services, and specialized workflows to become indispensable to customers.

gitlab

GitLab 18.11: Budget guardrails for GitLab Credits (opens in new tab)

GitLab 18.11 introduces spending controls for GitLab Credits used by the Duo Agent Platform. Organizations can set subscription-wide monthly caps, limit individual users, and monitor enforcement, making AI costs more predictable as adoption grows. The goal is to combine usage-based pricing with the budget certainty traditionally associated with seat-based licensing. ## Subscription-Level Spending Caps - Billing account managers can set a hard monthly ceiling in the Customers Portal. - When usage reaches the cap, Duo Agent Platform access pauses for all users until the next billing period. - Managers can raise or disable the cap mid-month to restore access. - Caps reset monthly and remain in effect until changed. - Because usage data is synchronized periodically, limited usage may occur after the cap is technically reached. ## Per-User Credit Limits - A flat per-user limit can be applied uniformly through the GitLab GraphQL API. - Custom overrides allow organizations to give higher allocations to selected users, such as staff engineers. - Limits apply to a user’s total consumption across all credit sources. - Reaching an individual limit pauses only that user’s Duo Agent Platform usage; their GitLab access remains intact. - Other users continue working until they reach their own limits or the subscription cap. ## Visibility and Notifications - Billing account managers receive email notifications when the subscription cap is reached. - Group owners on GitLab.com and instance administrators on Self-Managed installations can see users blocked by per-user caps. - Administrators can restore access by changing limits through the GraphQL API. - Per-user usage data supports monitoring, chargeback, and future budget planning. ## Benefits for Scaling AI Adoption - Hard caps make AI spending easier to forecast, approve, and include in quarterly budgets. - Per-user limits help distribute credits fairly across teams and cost centers. - Organizations can expand from small pilots to hundreds or thousands of developers without risking uncontrolled invoices. - Usage data helps platform teams understand consumption patterns and adjust allocations. ## Usage-Based Pricing with Guardrails GitLab contrasts its approach with seat-based AI tools, where organizations pay a fixed amount per user regardless of usage. GitLab Credits instead charge based on actual consumption while adding enforced spending limits, combining flexibility with predictable budgeting. ## Example Deployments - A 200-person engineering organization can set a subscription cap matching its approved monthly budget. - If usage approaches the limit, finance or billing managers can either increase the cap or wait for the next period. - A 2,000-person enterprise can apply standard limits to most developers while allocating higher caps to engineers handling complex work. ## Availability and Setup - The controls are available for GitLab.com and Self-Managed customers running GitLab 18.11. - Subscription-level caps are configured by billing account managers in the Customers Portal. - Flat and custom per-user caps are configured through the GitLab GraphQL API by namespace owners or instance administrators. Organizations adopting GitLab Duo Agent Platform should establish a subscription cap, define fair per-user allocations, and monitor usage regularly. These controls provide a safer foundation for expanding AI usage without sacrificing financial oversight.

stripe

How Stripe Radar helps prevent free trial abuse (opens in new tab)

Free trial abuse is accelerating, particularly among AI companies whose trials provide access to costly compute resources. Stripe detected 6.2 times more abusive trials between November 2025 and February 2026, with self-serve AI startups facing especially high exposure. Stripe argues that AI-powered fraud detection can identify abuse at signup and prevent substantial downstream losses. ## The rise of free trial abuse - Fraudsters increasingly cycle through free trials or use invalid payment methods without converting to paid plans. - AI companies are especially vulnerable because free trials can grant access to expensive compute and APIs. - AI startups with self-serve signup and direct API access experience 10 times more attempted abuse than enterprise AI companies. - Similar patterns affect SaaS companies, marketplaces, and other businesses offering free trials. ## Stripe Radar’s abuse-prevention controls - Stripe Radar now offers a one-click control to detect behavior violating common trial terms, including repeated signups and missed cancellations. - The system predicts abusive behavior with 90% accuracy. - A new analytics page displays blocked high-risk payments and, for unenrolled businesses, shows transactions that would have been blocked. - The model analyzes payment instruments, devices, payment history, card BIN data, virtual card indicators, email domains, session timing, and other risk signals across Stripe’s network. ## Results for AI companies - Cursor and other AI businesses use Radar to block suspicious users before they consume costly compute. - Within two months, Stripe blocked over 550,000 high-risk free trials across four high-growth AI companies. - Stripe estimates this prevented $4.4 million in downstream compute-related losses. Stripe recommends its free trial abuse control for businesses across industries. Companies interested in early access can contact Stripe directly.

cloudflare

Introducing the 2026 Cloudflare Threat Report (opens in new tab)

Cloudflare’s 2026 Threat Report argues that cyberattacks are shifting from brute-force intrusion toward high-trust exploitation. Attackers increasingly prioritize “Measure of Effectiveness” (MOE)—the greatest operational result for the least effort—using stolen tokens, AI, trusted cloud services, and social engineering rather than costly custom exploits. The report concludes that defenders must focus on identity, integrations, infrastructure resilience, and continuous monitoring of legitimate tools. ## Measure of Effectiveness (MOE) - MOE measures the ratio between an attacker’s effort and the operational outcome. - Threat actors favor: - Stolen session tokens over expensive zero-day exploits. - Reputation-based infrastructure such as LotX over custom servers. - AI-assisted automation over manually written tooling. - The most dangerous actors are those able to combine intelligence and technology into continuous, high-speed operations. ## Eight trends shaping the 2026 threat landscape - **AI-driven attacker operations** - Generative AI supports real-time network mapping, exploit development, and deepfake creation. - Lower-skilled attackers can now conduct more sophisticated, high-impact campaigns. - **State-sponsored infrastructure pre-positioning** - Groups such as Salt Typhoon and Linen Typhoon are targeting North American telecommunications, government, commercial, and IT services. - Their goal is to maintain access that can provide long-term geopolitical leverage. - **Over-privileged SaaS integrations** - Third-party APIs can expand a single compromise across hundreds of organizations. - The GRUB1 breach of Salesloft demonstrates the risks created by excessive integration privileges. - **Weaponized trusted cloud tools** - Attackers use services such as Google Calendar, Dropbox, GitHub, Google Drive, Microsoft Teams, and Amazon S3 to conceal malicious activity. - Legitimate enterprise traffic makes command-and-control communications harder to distinguish from normal use. - **Deepfake-based insider placement** - North Korean operators are using fraudulent identities and deepfakes to place remote IT workers inside Western companies. - These operatives support espionage and illicit revenue generation. - **Session-token theft** - Infostealers such as LummaC2 harvest active authentication tokens. - Attackers can then bypass multi-factor authentication and begin post-authentication activity. - **Internal brand spoofing** - Phishing-as-a-service tools exploit mail-relay blind spots where sender identity is not re-verified. - This enables convincing impersonation messages to arrive directly in trusted user inboxes. - **Hyper-volumetric DDoS attacks** - Botnets such as Aisuru are generating increasingly large distributed denial-of-service attacks. - The speed and scale of these attacks can overwhelm infrastructure before human responders can react. ## Living off legitimate cloud infrastructure - Attackers increasingly avoid known malicious servers and instead use legitimate SaaS, IaaS, and PaaS platforms. - Cloud services can be used to host payloads, redirect victims, deliver malware, or scale campaigns. - Amazon SES and SendGrid, for example, can be abused for phishing and malware distribution. - This “living off the land” approach—or “living off anything-as-a-service”—allows attackers to hide behind the reputation and normal traffic patterns of trusted providers. - Cloud-resource abuse is evolving from opportunistic infrastructure misuse into a deliberate nation-state strategy. Defenders should treat identity tokens, SaaS permissions, cloud activity, and trusted integrations as critical security boundaries. Organizations need least-privilege access, stronger token protection, continuous monitoring, automated DDoS mitigation, and detection that evaluates behavior—not just whether a service is legitimate.

cloudflare

See risk, fix risk: introducing Remediation in Cloudflare CASB (opens in new tab)

Cloudflare CASB now lets customers remediate risky SaaS file-sharing directly from the Cloudflare One dashboard, rather than merely identifying problems. The initial release targets Microsoft 365 and Google Workspace, removing public, organization-wide, or external sharing without deleting files or changing ownership. Cloudflare concludes that durable, workflow-based execution makes remediation scalable, observable, and easier to operate. ## CASB as a Centralized SaaS Risk View - CASB connects to services including Microsoft 365, Google Workspace, Slack, Salesforce, Box, GitHub, Jira, and Confluence through APIs. - It provides: - A consolidated view of misconfigurations, overshared files, and risky access. - Continuous scanning as users collaborate and adopt new tools. - Searchable and exportable findings for triage and reporting. - Previously, fixing findings required using each application’s admin interface or submitting tickets to application owners. ## File-Sharing Remediation - The new **Remove sharing** action can address: - Public links that allow anyone to view or edit files. - Company-wide sharing when only a few users need access. - Sharing with external domains or personal accounts. - Any of these risks involving files that match a DLP profile, such as customer records, credentials, or financial data. - Remediation removes the risky sharing configuration only: - Files are not deleted. - Ownership is not changed. - Progress and outcomes are tracked in CASB, while actions are recorded in Cloudflare One Admin logs and can be exported to a SIEM. ## Microsoft 365 and Google Workspace - The initial integrations focus on business-critical documents stored in: - OneDrive and SharePoint. - Google Drive, including Docs, Sheets, and Slides. - Common examples include temporary public editing links, company-wide documents forgotten after an event, and sensitive spreadsheets shared with contractors’ personal accounts. - Teams can now resolve findings directly in CASB instead of exporting CSVs and relying on application owners to make changes. ## Durable Remediation Architecture - Cloudflare designed the system for speed, resilience, and ease of use using: - Workers - Workflows - Queues - Workers KV - Secrets Store - Hyperdrive - The process is: - An API call sends a remediation job to a Worker. - The Worker places it on a Queue. - A second Worker starts a Workflow. - Credentials are securely provided through Workers KV and Secrets Store. - The Workflow gathers information and calls third-party APIs. - Hyperdrive records the final result. - Workflows’ native retries handle vendor API rate limits such as HTTP 429 responses, while built-in step logging shows retry activity. - Load testing and early customer usage produced a median completion time of 48 seconds and a p90 of 72 seconds. ## Planned Expansion - Cloudflare plans to add: - Quarantine actions that move or isolate high-risk files. - Custom Webhooks for ticketing, chat notifications, and external automation. - Carefully scoped autoremediation policies. - Custom CASB findings based on organization-specific patterns, data types, or access conditions. Organizations using Microsoft 365 or Google Workspace can use CASB Remediation to turn detected sharing risks into tracked, auditable fixes. The planned quarantine, webhook, and automated-policy features could further position CASB as an active security control plane rather than a passive reporting tool.

stripe

Analyzing how SaaS platforms are shipping payments and finance products in days (opens in new tab)

Stripe’s embedded components—prebuilt UI modules for payments and finance workflows—have seen rapid adoption, with active users more than tripling in a year. Usage data shows that large platforms and those serving in-person businesses are especially likely to adopt them, primarily to manage complexity, accelerate launches, and simplify onboarding. Most platforms also customize the components to match their branding. ## Large Platforms Adopt More Broadly - Platforms with more than 1,000 employees or $1 billion in revenue are nearly three times more likely to use embedded components than startup platforms. - Larger platforms use a median of three components, compared with two among startups. - Their main motivation is managing international compliance, localization, and the need to launch features quickly. - FreshBooks uses account onboarding across more than 160 countries, with automatic adjustments for language and regional requirements. - Tekmetric launched Stripe Capital after updating its Connect integration, while Kajabi introduced a Xero integration in six weeks instead of the usual six to twelve months. ## In-Person Industries Lead Adoption - Platforms serving industries such as automotive repair adopt embedded components at more than twice the median rate. - These businesses often have tighter margins, higher operating costs, and less experience with online payments. - Embedded workflows let platforms provide streamlined payment experiences without building and maintaining them independently. - TheCut uses embedded onboarding for businesses accepting both in-person and online payments. - Cloudbeds reduced hotel onboarding time from weeks to hours. - Jobber doubled Capital originations after adding financing capabilities. ## Most Platforms Customize the Experience - Seventy-one percent of platforms use Stripe’s theming features to match their own design systems. - Common customizations include branded colors, notification banners, and dashboard styling. - Consistent branding is especially important for sensitive workflows involving payments and identity verification. ## Expanding Component Capabilities - New components let platforms promote financial products such as Instant Payouts and Stripe Capital within their dashboards. - Disputes components allow platform users to manage payment disputes themselves, reducing operational support demands. - Stripe is continuing to expand the component library based on usage data and customer feedback. Embedded components are most valuable for platforms that need reliable, localized financial workflows without the cost and delay of custom development. They offer a practical way to scale payments, add new financial products, and maintain a consistent user experience.

figma

Figma's commitment to FedRAMP | Figma Blog (opens in new tab)

Figma is pursuing FedRAMP Moderate certification to make its collaborative design platform available to US government agencies and public-sector organizations. The certification process demonstrates that Figma meets rigorous security and privacy requirements and would allow government teams to safely design, prototype, and test digital services. Figma argues that its browser-based, collaborative workflow could help agencies iterate faster and improve citizen-facing software. ## FedRAMP Status and Purpose - Figma’s FedRAMP Moderate authorization is currently “in process.” - Listing on the FedRAMP Marketplace indicates that Figma has completed an audit and is moving through the final certification steps. - FedRAMP evaluates cloud applications against government security controls and categorizes them as low, moderate, or high impact. - Certification is necessary before Figma can fully host government data. ## Benefits for Public-Sector Users - Certification would allow government agencies, contractors, and civic-technology teams to: - Create software designs in Figma - Build and test interactive prototypes - Validate ideas through rapid iteration - Improve the usability of government applications - Figma says the certification will give customers confidence that their data and content meet demanding security and privacy standards. - Its browser-based and platform-agnostic design supports collaboration among distributed teams, including agencies and contingent workers. ## Public-Sector Collaboration and Modernization - The shift toward hybrid and remote work has increased demand for accessible, collaborative digital tools in government. - Figma connects this trend with broader efforts to improve customer experience and rebuild trust in government services. - The company believes public-sector organizations often work similarly to private companies despite having different missions and business models. - Collaborative design could help agencies ship services more quickly and achieve better outcomes for citizens. ## Building a Federal Government Team - Figma is expanding its federal-government organization, beginning with federal sales leader James Kohler. - The company is seeking people who understand government procurement and security requirements while also being able to build new programs from the ground up. - Kohler’s role is to adapt lessons from Figma’s private-sector work to the needs of government users. - Figma plans to encourage knowledge sharing between its commercial and government teams. ## Next Steps - Figma’s immediate goal is to complete FedRAMP certification and become authorized for federal use. - The company intends to continue engaging public-sector customers and sharing updates about its government efforts. Figma’s certification effort is a prerequisite for broader government adoption. If completed, the platform could give public-sector teams a secure way to collaborate on and rapidly improve digital services.

datadog

How Datadog's IT team automated account inactivity and SaaS spend management (opens in new tab)

Datadog expanded its Clarity auditing tool into Clarity License Manager (CLM), a system that tracks SaaS usage, reduces licensing costs, and improves security. CLM identifies inactive accounts, notifies employees, automatically deactivates unused access, and restores it quickly when needed. Its microservice architecture and application-specific adapters allow the system to scale across many SaaS products. ## The SaaS License Management Problem - Datadog used many commercial SaaS tools with substantial per-user costs. - License usage data was outdated and collected through quarterly manual audits. - IT Support had to contact employees individually, creating administrative overhead and a poor user experience. - Unused accounts also created security risks, including stale credentials that could be compromised. ## Goals of Clarity License Manager - Monitor and automatically deactivate inactive accounts, especially in sensitive services such as cloud providers. - Reduce the risk of leaked or abused stale credentials. - Limit the potential impact of security incidents. - Lower SaaS spending and support data-driven licensing decisions. - Preserve employee productivity through an easy account restoration process. ## Usage Monitoring and Automated Workflows - CLM gathers activity data through: - Direct integrations with individual SaaS APIs. - Google Workspace SAML audit logs for indirect integrations. - Employee activity is stored per application in an Amazon RDS-backed PostgreSQL database. - Employees receive email and Slack notifications after a configurable period of inactivity, with 90 days as the default. - Notifications explain the specific login or application action required to remain active. - If the employee does not respond after multiple reminders, CLM deactivates the account automatically. - Employees can reopen access by submitting a Freshservice ticket. - Accounts are restored within seconds, including their previous roles and permissions. ## Microservice Architecture - CLM consists of Python microservices running on AWS Lambda. - The services share a central PostgreSQL database. - Microservices provide: - Easier scaling as Datadog adds more SaaS applications. - Greater resilience and flexibility. - A modular foundation for future development. - The architecture introduced complexity because services required different APIs and libraries with overlapping functionality. ## Application-Specific Adapters - Each SaaS product is represented by an adapter shared across CLM microservices. - Adapters isolate application-specific API logic from the core workflows. - A typical adapter supports operations such as: - Retrieving users. - Fetching login activity. - Activating and deactivating accounts. - Onboarding and offboarding users. - This design provides: - Clear separation of responsibilities. - Reusable and flexible integration code. - Simpler microservices that do not need to handle each application’s unique behavior. CLM demonstrates how automated usage monitoring can simultaneously improve SaaS security, reduce unnecessary spending, and minimize disruption for employees. A modular adapter-based architecture is particularly useful when managing a growing portfolio of third-party applications.

figma

Inside Figma: a Q&A with our global sales team | Figma Blog (opens in new tab)

Figma’s global sales team operates as a product-led, consultative partner rather than a traditional vendor. Sales employees work closely with users, designers, product teams, and internal advocates to expand Figma’s impact across organizations. The team emphasizes collaboration, user empathy, continuous learning, and personal growth. ## Sales as a Partnership - Figma’s users are central to product development, community engagement, and internal operations. - Sales teams help organizations improve product development and scale creative processes. - Internal customer champions often become advocates for Figma, creating partnerships based on shared goals rather than transactional selling. - Sales involves more than designers; decision-makers include product, engineering, and other supporting roles. ## The Growing Importance of Design - Distributed work has increased the need for effective collaboration and accessible design tools. - Figma argues that design is moving to the center of product development. - Stronger design improves user experiences and can help businesses perform better. - The sales team helps organizations understand how Figma can connect designers and collaborators. ## Learning the Design Landscape - New sales employees receive structured onboarding, including a five-week program. - Team members learn from sales colleagues, designer advocates, and direct exposure to customer pain points. - Senior leaders may shadow support teams to better understand users’ challenges and product needs. - Continuous learning is treated as essential, even for employees without prior design experience. ## Product-Led Growth - Many prospective customers already use Figma, reducing reliance on conventional SaaS sales tactics. - Sales representatives can focus on helping existing users expand Figma’s role within their organizations. - Employees are drawn to the model because it feels more like advising and partnering than following a rigid sales cycle. - Figma’s strong product affinity and brand loyalty support this approach. ## A Collaborative Sales Culture - The team describes its culture as supportive, consultative, and low-ego rather than aggressively competitive. - Figma’s motto, “people over pipeline,” reflects its emphasis on personal development and employee well-being. - Success is recognized across the team instead of treated solely as an individual achievement. - Sales works cross-functionally with product and other departments, building relationships that support long-term growth. ## Career Growth - Joining Figma early offered employees the opportunity to help build sales processes from the ground up. - The organization’s rapid growth created opportunities for learning, leadership, and increased responsibility. - Employees were attracted by the chance to take risks, work in a scrappy environment, and develop alongside the company. Figma presents sales as an extension of its product-led philosophy: understand users deeply, collaborate across teams, and help customer advocates bring the product to more people.

figma

Figma raises $25MM Series B | Figma Blog (opens in new tab)

Figma announced a $25 million Series B funding round led by Kleiner Perkins partner Mamoon Hamid. Existing investors from Index, Greylock, and LinkedIn also participated. The funding supports Figma’s broader vision of making design accessible, collaborative, and web-based rather than limited by siloed tools and workflows. ## Series B Funding - The round was led by Kleiner Perkins’ Mamoon Hamid. - Hamid’s previous investments included SaaS companies such as Slack, Box, and Intercom. - Existing investors Danny Rimer of Index, John Lilly of Greylock, and LinkedIn co-founder Jeff Weiner joined the round. - This was Hamid’s first investment at Kleiner Perkins. ## Figma’s Founding Vision - Figma was founded five years earlier by Dylan Field and Evan Wallace. - The founders believed creative tools should empower users rather than constrain them. - Their goal was to make creation: - Accessible to more people - Collaborative instead of siloed - Built for the web - The company emerged from experimentation with browser-based design tools, supported initially by a Thiel Fellowship. ## Adopting a New Way of Working - Figma acknowledged that changing established design workflows is difficult and takes time. - The company credited its users, employees, and early investors for supporting its vision during that transition. - The funding announcement represented both financial growth and continued validation of collaborative, web-based design. Figma intended to use the momentum from its Series B to continue developing tools that make design more open, collaborative, and accessible across teams.

figma

New faces at the Figma helm | Figma Blog (opens in new tab)

Figma is entering a new phase as demand for design and collaborative tools grows across the technology industry. To support that growth, CEO Dylan Field announces Eric Wittman as the company’s first COO and Kris Rasmussen as Vice President of Engineering. Their experience scaling collaboration-focused businesses will help Figma expand its operations, revenue, technology, and team. ## Figma’s Growth Opportunity - Companies increasingly view design as central to creating products customers value. - Large organizations such as IBM and GE are expanding their design teams, while Facebook has pursued a high designer-to-engineer ratio. - Figma argues that the tools available to designers have not kept pace with this demand. - Improving collaboration remains the company’s guiding priority. ## Eric Wittman: Operations, Strategy, and Revenue - Wittman joins after leading Atlassian’s Developer Tools business, including Bitbucket. - As COO, he will focus on: - Recruiting and finance processes - Go-to-market strategy - Revenue and business operations - Company strategy and values - His career spans: - Customer support and product management at Macromedia, where he eventually led Flash product management - CEO of music player company Songbird - General manager of Developer Tools at Atlassian - Figma highlights his unusual combination of operational expertise and strong product enthusiasm. - Before the announcement, he had already helped Figma launch its pricing model and refine its strategic direction. ## Kris Rasmussen: Engineering Leadership - Rasmussen initially joined Figma as a part-time contractor but quickly became an influential, informal leader. - He is appointed Vice President of Engineering and will oversee major engineering initiatives and technical-team development. - His background includes: - Leading engineering at Asana during its early growth - Scaling engineering at Aptana, a web-application developer-tools company - Building personal projects involving 3D graphics - Figma values his ability to resolve disagreements, identify necessary actions, and combine technical skill with leadership. - His primary mission will be building a world-class engineering organization and infrastructure for collaborative design tools. ## Continued Hiring - Figma says it is still early in its development and expects significant opportunities and challenges ahead. - The company invites engineers, designers, writers, and product managers who are passionate about design to apply for open roles. Figma’s leadership changes are intended to turn growing demand for collaborative design software into scalable business and technical execution. Wittman will strengthen operations and commercial strategy, while Rasmussen will lead the engineering organization needed for Figma’s next stage.