ScenarioThe Fourth Swing6 minDutch original
Access to the source? Then you'll need the key first
We all moved to SaaS and let the custom work go. Now anyone can code again, and the custom work is coming back, but only if you hold the key.

Access to the source? Then you’ll need the key first. 🔑
Over the past years we all moved to SaaS. Everything had to become SaaS. No more updates to install, no SQL maintenance, no infrastructure to look after. And custom work was a thing of the past: “that is not how this application works.”
That saved us all of the above. But it also meant business processes had to adapt, and that is a bigger change than it looks.
Four times back and forth
Look at the movement of the past decades. It swings, and we are in the fourth swing now.
Factory. In the beginning we worked with IT as it came out of the factory. The system determined the process. That was how it was, and nobody found it strange.
Custom. Then we got used, very fast, to bending systems to fit us. We went from IT determines our process to our process determines how IT should work. Every organisation got its own version of the same package, and a whole profession appeared to keep it running.
Factory. With the cloud (private first, then public) and SaaS it flipped back. An application like that determines how your organisation works. Your process forms itself around what one vendor happens to offer. Of course you look for an app that fits your process, but it never becomes fully bespoke.
Custom. And now anyone can code again.
Coding happens in a language, and nothing speaks more languages than a language model. You say what you want to know; the model writes the code. And that code appears on your screen as a dashboard that does exactly what you meant. In your own house style. With reporting, with an email alert, with an analysis of the output thrown in.
Custom apps everywhere you look. Remarkable.
Where the key sits
And no, we are not abandoning SaaS tomorrow. Those earlier advantages have not gone anywhere.
But strip IT down and this is what is left. A SaaS application is nothing more than a collection point for your data. Your crown jewels. The same as that SQL server back then. The application is now a website you can reach through any browser.
The data is yours. The website is not.
For years that meant no custom work was possible. You are bound to the dashboards you are given, the reports that exist, and the place where the vendor happened to put a field. Want something outside that, and you hired an expert, or you stayed with Power BI and Excel.
Through an API. The key to your source.
That is the part being skipped in all the enthusiasm about vibe coding. Every one of those custom apps is nothing without access to the data, and that access is a key somebody has to hand over. As long as you have it, anything is possible. If you do not, you build a beautiful dashboard on top of an empty source.
So we are back in the custom era. IT supports the business again instead of the other way round. Do not let the AI tell you how to work; tell the AI how you work.
And then the uncomfortable part
There is a flip side to this fourth swing, and it is not symmetrical with the first three.
In the first custom era, access to the database had a face. There was a DBA, there was a vendor, there was somebody to call. Access was something you requested and something that was granted, and a person sat in between who could ask: what for, exactly?
Now it is an API key in an environment variable. Or worse: an agent walking in through an employee’s browser session. No key needed at all; you borrow one.
And that is where it tips from handy to risky. In the first custom era, custom work was expensive and therefore rare. Now it is free and therefore everywhere. Anyone in your organisation can build something that works, and everyone who builds something needs access, and nobody is keeping count of how many keys are out.
Ask yourself: how many API keys on your data were issued in the past twelve months? Who has them? Are they still needed? And who would notice if one of them was used by somebody else?
I know the answer for most organisations, and it is not “we know exactly”.
The key, not the vault
We spent years paying attention to the vault. Encryption at rest, encryption in transit, a data centre with a certification and a turnstile at the entrance.
All of that is right. But it is no longer where it goes wrong.
You can keep your data in a vault that is guarded around the clock. But if you are careless with the key, anyone can walk in.
That is where this custom era stops resembling the first one. Back then the question was whether we could build it. Now it is whether we still know who is inside.