My job involves talking to a lot of people. And because the people I talk to know that I’m talking to lots of other people, they not infrequently ask me what everyone else is saying about something.
Lately, the something they most often ask about is tokens.
Or more specifically, charging for tokens, the way software makers ranging from GitHub to Atlassian to SAP increasingly do. MSPs ask because they fear that vendors they buy from will soon adopt the same model and make budgeting for software difficult. Vendors ask, I suspect, because a) collecting predictable margins on AI-infused products without token-based pricing is difficult, b) MSPs could resist token-based pricing should it come, and c) it sure would be convenient if someone else would test how much resistance we’re talking about before they do.
And it turns out someone has, a young startup named Flamingo you first read about here in January that thinks a little differently about a lot of things. Michael Assraf, its founder and CEO, knows that his hybrid per-seat/per-token pricing scheme is a rarity among vendors that sell to and through MSPs. He’s also pretty confident that will only be true temporarily.
“For the longer term, I think that the entire industry is going to go that route,” Assraf (pictured) says.
So, apparently, do a few other people, because investors have just supplemented the $2.2 million of seed capital Flamingo raised last October with another $4.5 million. Their reasoning, like Assraf’s, begins with the undeniable fact that at a time when AI coding tools have radically shortened development times, the software moats innovators have long enjoyed are largely a thing of the past. Indeed, it took all of six weeks for Flamingo to build an RMM solution from scratch, and an even shorter five weeks to build an accompanying documentation and password management system.
“We care about the software and we’re going to build very good software, but it’s not where the big opportunity is,” Assraf says. “You’re not going to make money out of tooling revenue.”
You will, or at least can, make money on the labor AI-based tooling replaces. In the case of Simpro, per a recent story, that’s tasks like scheduling field service jobs. In the case of Upshop, per a forthcoming story, it’s tasks like managing a supermarket’s inventory. In the case of Flamingo, it’s tasks like running the help desk.
“For every dollar spent on software, there are five to six dollars spent on the people that click those buttons,” Assraf says. “So if you spend half a million on software for the IT department, you’re going to invest much more on the people and the labor that actually operates it and answers support tickets. Same for MSPs.”
By Assraf’s logic, the more his partners spend on AI labor the less they spend on labor overall and the more tokens they consume, in a value exchange that grows both the MSP’s bottom line and Flamingo’s top line.
Hence the vendor’s pricing scheme, which combines flat-rate software fees with usage-based token fees. The flat-rate part of the equation reflects Assraf’s take on what code is worth these days: Users pay $1 per device per month for RMM, PSA, remote access, SIEM, and four other platform modules or 80 cents a month on an annual contract. Those are prices Flamingo can afford to charge, according to Assraf, because its software is all either homegrown or open source.
“Even on 80 cents, we still make money,” he says.
But only a little. “We don’t make a lot of money on the tooling,” Assraf says. “Most of the money that we’re making is from the AI tokens.”
Flamingo’s monthly plan comes with 10 million of those; its yearly plan includes 25 million. Anything beyond that is billed at a pay-as-you-go price synced to match roughly what Anthropic and OpenAI are charging.
“You will pay us whatever you’re going to pay for tokens if you’re [working] directly with the LLM providers,” Assraf says. Except that Flamingo manages token consumption more efficiently than most MSPs, so it profits modestly on each token a partner uses.
At present, most of Flamingo’s roughly 400 early adopters are burning through 10-20x their monthly token allotment and paying accordingly. So far, according to Assraf, no one’s complaining or canceling as a result.
And that’s now, he adds, when Flamingo’s relying on frontier lab LLMs. The company will roll out LLMs of its own hosted in a SOC 2, Type 2 virtual data center by the end of the year, at which point partners will get twice as many tokens for the same price.
Assraf is quick to concede that his partners tend to be more AI-forward than the MSP mainstream. “Many of them are already using Claude Code and many of them are already using Codex and other tooling,” he says. “They’re already aware of this new token-based consumption pricing, so they’re OK with it.”
Everyone else will be too eventually, Assraf predicts, when they discover that paying more for AI is OK so long as it gets them more too.
“For now, what we’re seeing is that MSPs care about increasing their profit margins and they care about solving customers’ issues as fast as possible,” he says. They’ll pay for both by the token, in his experience to date, if you reliably help them with those goals.
Integrations, sort of
Like I said, Flamingo thinks differently about a lot of things. One of them is integrations, which have been all but sacrosanct in managed services for as long as there have been managed services. Most MSPs want the flexibility to construct bespoke stacks out of mixed-and-matched tools from multiple suppliers. Flamingo, per my January story about them, is the exceptionally rare example of an MSP-oriented software vendor that refuses to integrate with third parties anyway.
Or, starting soon, mostly refuses. The company is weeks away from introducing integrations with Microsoft 365 and Google Workspace that will let technicians manage end user tenants through the same interface they use to manage other client assets.
Coming later as well are additional integrations with popular solutions from ConnectWise, Kaseya, and others. Except that Assraf doesn’t consider them real integrations per se.
“We’re going to add integrations into the normal PSA and RMMs in order for users to import their data from those tools into ours,” he says. Right now, competing platforms have functionality in areas like billing that Flamingo’s still developing.
“Once we have the rest of that stuff,” he predicts of his partners, “they’re going to migrate completely to us.”
When ransomware gets real
Ransomware is an abstraction to most of us. It’s not for its victims or the ransomware recovery experts who help them. MSP and ransomware recovery vendor Oli Thordarson makes that clear on the latest episode of MSP Chat, and he shares some informed advice on avoiding ransomware too. Tune in here for the whole thing, and visit this page for a look at all the other, equally compelling topics we get into on the show.
MSPs want strategic advice. TD SYNNEX says we hear you.
In a post you saw here late in July, I shared thoughts from two experts about research from industry community GTIA showing that member satisfaction with partner programs is dipping. Everything both Danielle Ibran of IDC and Ryan Morris of Channel Mastered, the consultancy I help lead, are seeing in the channel tells them the issue is that partners want strategic advice on outcome-oriented growth strategies from their vendors, and partner programs aren’t providing it.
Turns out that’s what TD SYNNEX is seeing too. “We’re 100% getting that feedback from our partners,” says Augie Staab, the distribution giant’s director of MSP sales. “We saw it start to come up in our Direction of Technology survey.” Staab’s newly created role and the newly created team she now leads are a big part of how TD SYNNEX acted on that data, along with additional revenue-related data.
“We started seeing an accelerated clip of growth associated with the partners who either had an established MSP business practice or methodology, or were expanding into it,” Staab (pictured) says. Overall IT industry growth averages 7-9% most years, she notes. “Then you look at people who are working in that MSP space, and their clip is 12-15%.”
Probably, TD SYNNEX believes, because unlike traditional resellers who move on to the next client and project after implementing solutions, MSPs stick around to manage the technology they supply and help clients benefit from it.
“They’re winning more opportunities organically from those relationships,” Staab says, including in areas outside the services and software MSPs typically know best.
“It’s driving opportunities for incremental hardware as well,” Staab says, from businesses that need 10 laptops, say. “They’re becoming more prone to just go to the MSP that they’re working with day to day.”
TD SYNNEX has had sales resources for those MSPs before within its SMB reseller unit. The new group Staab leads is the first to focus exclusively on what she calls “pure play” firms making 70% or more of their revenue from managed services.
“We have the autonomy to build the support, train the reps, and build programs that are MSP-centric and going to help our MSP community grow,” she says. They also have 60 reps on staff, versus the roughly two dozen MSP-focused people in the SMB reseller group.
“We now have a lower account-to-rep coverage ratio, which allows us to get deeper with those accounts, have more strategic conversations, and do some consultation on what they should add to their service delivery stack,” Staab says.
Exactly what partners told TD SYNNEX they want in the Direction of Technology survey and implicitly told GTIA as well. It also aligns with TD SYNNEX’s larger people-plus-tech partner relationship strategy.
“One of the things that we’ve noticed in the market right now, especially with our competition, is that there’s this approach that MSPs need to be digitally led,” Staab says. “I’m all for digitalizing the business, making operations streamlined, smoother, and so on, but MSPs are specifically asking for a lot of consultation and guidance.” Staab’s new unit, along with the PartnerFirst portal the company launched a year ago, is part of how TD SYNNEX plans to give those partners both digital resources and personal attention.
The company’s forthcoming MSP partner program, set to launch toward the end of the year, is another component of that strategy. Staab won’t say much about it for now except that its design will reflect extensive partner input and that its membership benefits will include access to peer-to-peer enablement, in keeping with an aspect of the MSP community that Staab (like ConnectWise CEO Manny Rivelo once upon a time) marvels at.
“I’ve worked with traditional resale. I’ve worked with enterprise VARs,” Staab says. “I’ve seen every type of business and size of business. What I love about the MSPs is that they lean on each other.”
We’re all builders now, and we’re all on the hook
I wrote last week about the governance debt and data debt MSPs are encountering as they roll out AI tools and solutions. A recent conversation with a friend got me thinking about a more familiar IT-related liability: tech debt.
My friend is a professional developer at a healthcare research institute who uses AI coding tools every day and very much appreciates the productivity gains they’ve produced. But he’s also growing mindful of an issue that’s manageable now but may not be forever.
The code Claude writes, he says, is very effective but not especially elegant. It’s more like “spaghetti code” organized in sometimes inscrutable ways no human developer would choose. Which means that even he, who’s responsible for the code, can’t always explain why it works the way it works. What happens when something breaks and he’s home with the flu, on vacation, working somewhere else, or retired?
And AI code breaks all the time, too. Fully 75% of organizations surveyed by Futurum have already experienced a production incident involving AI-generated code, AI agents, and/or AI tooling. AI’s great at creating huge volumes of programming very rapidly, notes Mitch Ashley (pictured), vice president and practice lead for software lifecycle engineering at Futurum.
“It isn’t necessarily going to be thorough about making sure it’s been well-tested, making sure that it’s secure, making sure that if you’re talking to other third-party services, you know what it’s talking to,” he says.
The result is software quality issues that cost two-thirds of the organizations surveyed by Tricentis between $500,000 and $5 million a year and that forced Meta to cancel a major plan to replace human coders with agentic ones in the most public and humiliating way possible.
Meta and most of the companies Tricentis polled are big businesses, but MSPs aren’t immune from the same problems, as David Schwartz, CEO of service desk automation vendor Pia, explains during a recent episode of MSP Chat, the podcast I co-host.
“I’ve seen a lot of MSPs building their own tools,” he says, especially for ticket triage. And yes, they’ve saved money on licensing as a result, but Schwartz suspects they’ll eventually pay it back elsewhere.
“Most MSPs are not software businesses,” he says, which means they have limited expertise if any in security, governance, version control, R&D, and all the other things software businesses have deep in their DNA, not to mention limited time and bandwidth for the endless toil of maintenance.
And it really is endless, Ashley observes. “It’s much easier to create new code than it is to maintain current code.”
None of this should scare MSPs away from vibe coding, he adds, provided they embrace some minimum best practices for safety and efficiency. First, he says, be explicit in your instructions to your coding agent about employing safe development practices and scanning AI-generated code for known vulnerabilities.
“Those things have to be built into the environment as part of the framework, or the harness if you will, that even everyday builders build code with,” Ashley says. Pay particular attention to how vibe-coded apps handle user IDs and passwords, he adds. “The tools aren’t necessarily great about making sure that you’re not storing credentials locally.”
In fact, nothing should be stored locally, continues Ashley, who says MSPs should always put code in a trusted repository like GitHub that multiple people in their organization have access to, and back the code up regularly.
Sounds elementary, notes Schwartz, but it isn’t for a lot of people building their own code these days. “Most MSPs don’t really have a DevOps team that can truly own that,” he says.
Nor do their customers, many of whom are vibe-coding apps too. “We’re all builders now,” Ashley says. “Anyone can pick up a credit card or even a free account and start writing code with something.”
And if that puts IT professionals at risk, imagine what it does to technical amateurs. “That’s an opportunity for the advisors, the service providers, and the integrators who specialize in working with medium and small businesses,” Ashley notes. Eventually, he says, many such companies learn that AI coding creates more work than they expected. They’ll probably be happy to pay someone else to handle it for them.
Over on Business of Tech
Host Dave Sobel is pondering “silent disqualification,” the phenomenon an MSP experiences when a distributor, vendor, or potential client rules them out as a partner or IT provider based on a few bad numbers in a few critical fields in a qualification database they didn’t even know existed:
So here is the choice. Give the fields an owner. One person who knows what tier you sit in with every distributor you buy through, which of your platforms carry which validations and when those expire, and what the public record returns about your business when a machine scores it — and who re-runs that check every quarter, the way a buyer would.
Or leave it where it lives now, which is nowhere, and learn you were taken out of a market the only way a silent disqualification ever tells you: a quarter that came in light, with no losses in it to explain why.
Also worth noting
SCOUTz, from the founder who brought you RYTHMz, has emerged from stealth with an open-beta security sales intelligence platform for MSPs.
Barracuda has signed OpenAI’s call for collective action on cyber defense.
SPECTRA has launched a pilot certification framework of 20 AI deployment controls designed to give MSPs, SMBs, and insurers a common standard for validating the insurability of AI implementations. Much more to come in a future story.
Proofpoint’s Prism Investigator and Human Communications Intelligence now conduct AI-powered investigations directly across Microsoft 365 email, Teams, and files.
Blackpoint Cyber has added new ITDR capabilities to its CompassOne platform, including a historical Microsoft 365 compromise scan and nine new threat detections.
JumpCloud’s IAM platform now manages AI agents alongside people and devices.
Intermedia has launched AI Receptionist, a native AI voice agent for Intermedia Unite and Contact Center that answers and processes inbound calls.
Okta has added new capabilities for securing and governing AI agents throughout their identity lifecycles.
Recon, from Portal26, lets enterprises query their AI usage data in plain language for real-time risk, compliance, adoption, performance, and cost insights.
Parallels has added Nutanix Prism support to Parallels RAS, enabling IT teams to centrally provision, manage, and scale Nutanix-based desktops and applications.
MSP OneShare and IBPI have named TechRisks their IT-specific insurance partner, giving members access to specialized tech E&O, cyber liability, general liability, and other coverage. More on the story behind these orgs coming soon here too.
Bill Wosilius is the new CEO at mega mega MSP Omega Systems.







