RIPEDA Consulting
Apple Business ManagerMDMStrategy

Six to 150: the IT debt that catches every SaaS post-Series A

A six-person SaaS team closes Series A and scales to 150 staff in a year. Nine months in, they discover that nobody set up Apple Business Manager. The remediation is expensive. The setup that would have prevented it was small.

By RIPEDA··6 min read

A founder calls in November. The SaaS company closed Series A in February, scaled from six to ninety by October across three countries, and now needs a security review before a key enterprise customer signs. The founder mentions, almost in passing, that they should also “get the IT sorted.” Over the next hour the picture comes into focus.

There is no Apple Business Manager (ABM) tenant. Every laptop was opened by the staff member it was issued to and signed in to a new Apple ID that morning. There is no Mobile Device Management (MDM). Three contractors who finished engagements in May still have access to the production code repository. The customer relationship management (CRM) account is in the founder’s name. The product manager who left in July still has admin access to the deployment platform. The remediation will take approximately a quarter, scheduled around a team that is still hiring, still shipping, and preparing for a Series B raise.

We have seen this pattern more than once. The names change. The shape does not.

Why six-to-150 breaks IT differently

A SaaS company at six staff does not need IT structure. The team holds the configuration in its head. Onboarding is the founder handing a laptop across a desk. Offboarding has not happened yet.

The Series A close changes things overnight. Six in February is twenty by April, forty by June, ninety by October, 150 by the next spring. Hires happen in three time zones. Devices ship directly to staff homes. The team that used to know everything no longer knows anything.

Three categories of IT decision fail quietly in that window.

Fleet visibility. Devices issued without MDM enrolment. The company genuinely does not know how many laptops are out there or what state they are in.

Identity and access. Hires get accounts created as needs arise. Departures rarely trigger full revocation. Credentials accumulate.

Apple ID hygiene. Devices signed in to personal Apple IDs. Photos sync to iCloud accounts the company does not own. Apps purchased on personal cards belong to staff members, not the company.

These gaps are invisible while the team is shipping product and closing customers. They become visible all at once when an enterprise customer asks the security questions, when a board member raises governance, or when a major staff departure exposes that clean access revocation is not possible.

What the remediation actually costs

The honest answer is eight to sixteen weeks of focused work involving every staff member, every device, and every system.

Device audit. Every laptop, who has it, what state it is in, whether it can be enrolled retroactively in ABM.

Identity audit. Every account in every system, mapped to current staff, contractor, or departed-person status.

Access revocation. Departed contractors removed from every system. Departed staff with lingering access removed.

Foundation install. ABM, MDM, identity provider, password vault, written offboarding checklist.

The device audit alone often takes two to three weeks because every staff member has to confirm a serial number, surrender the device briefly for re-enrolment, and re-sign in with a managed Apple Account. Coordinating that across 150 staff in three time zones, around live product work, is a project. The identity and access audit is similar.

The work has to happen. The customer needs the answer. The board needs the answer. The security questionnaire needs the answer. The timing is what hurts. It hits when the company can least absorb the distraction.

What the preventative setup costs

For comparison, the foundation installed at twenty hires costs roughly two thousand dollars per year and one week of founder time. ABM registered. MDM vendor connected. Identity provider used as the front door for every system. Password vault rolled out. Offboarding checklist written.

That work, done early, means the device that ships to a new hire in Manila in October arrives pre-enrolled in the company’s MDM. The new hire signs in with a managed Apple Account and the laptop joins the fleet automatically. The contractor who finishes an engagement in May loses access the moment their identity provider account is suspended. The CRM account is in the company’s name from the day it was created.

A week at twenty hires saves a quarter at 150.

Why this catches founders

The pattern catches founders because it does not feel like IT debt while it is accumulating. The team is shipping. Customers are signing. Hiring is working. Everything the founders are measuring looks healthy. The IT structure underneath is invisible until the moment it is not.

The warning signs are not subtle once a founder is looking. Hires this month not knowing how previous hires’ devices were configured. A founder who cannot say how many laptops the company has shipped. A departed staff member surfacing two months later as still having access. Any of those is the signal. All of them are common in companies that have not yet installed the foundation.

When to think about this

The right time to set up the foundation is before the round closes. Pre-funding is when the founder still has time. Post-funding is when the founder no longer does. The work is small. The window is also small.

A company that arrives at Series A with a working IT foundation skips the remediation quarter. A company that arrives without one pays at the worst time, in the most painful way, and at three to five times the price.

Found this useful? Share it.

LinkedInPostEmail

Thinking through this for your business?

RIPEDA helps Apple-first organizations make these decisions every day.

Get in touch