Rubin monetized the scarcity of compute. The software constraint trade has to monetize the scarcity of something less tangible and harder to price: an enterprise’s permission for a machine to act. This page sets out the thesis in short form today, the full report follows, and the week’s earnings reactions serve as the first live test.
§1 — The thesis in one line
Model capability keeps rising and inference keeps getting cheaper. Neither produces a useful enterprise agent on its own. Before a company lets an agent do anything that matters, the agent has to understand the company’s vocabulary, find current information, keep state, obtain permission, coordinate tools and other agents, execute through real workflows, and prove or reverse what it did. The scarce asset is therefore not software code. It is organizational permission to act, encoded in software.
Agent deployment = min { Context · State · Permission · Orchestration · Verification · Recovery } · if one term fails, the agent stays a pilot
The companies worth researching under this thesis own an unavoidable control point somewhere in that loop and can turn agent activity into a billable meter: queries, compute, records, actions, workflows, traces, security events or credits. Data gravity alone is not enough. Owning a chat window is not enough. The vendor has to sit where the agent cannot go around it.
The single most important distinction. A physical constraint, the kind the Rubin 100 was built to track, is investable because supply cannot respond quickly: a fab, a substrate line or a gigawatt of power takes years. A software constraint is investable only when customers cannot bypass the control point. Software layers can develop simultaneously, be bundled, be routed around through open standards, collapse into one incumbent platform, or move between vendors in a quarter. So this is not “Rubin, but in software.” It is a more dynamic trade in which the bottleneck migrates, and the portfolio has to be weighted by evidence rather than by narrative purity.
§2 — The eight layers, and the grade the market gave each one this week
The stack below is the thesis’s map of where an agent can be stopped. The right-hand column is what actually happened to the listed expressions of each layer in the first three sessions of September, most of them fresh from their own earnings reports. Wednesday closes; the three-day reaction windows from the Print Record where a company reported this week.
LayerWhat it gatesListed namesThis week1 · Context and semanticsWhat “customer,” “revenue” or “approved supplier” means; governed, current dataSNOW · Databricks · SAP · CRM · PLTRSNOW +20% after hours on a third quarter of faster growth · PLTR −5.8% Wed, −8.4% on the week · CRM −0.5%2 · Operational state and memoryWhat is true right now; durable memory; safe write-backMDB · ORCL · Databricks LakebaseMDB beat for the eleventh straight quarter, −13.5% Wed · ORCL −5.2% Tue3 · Systems of recordThe authoritative object and the final write that makes an agent’s output realSAP · CRM · WDAY · NOW · ORCLSAP −1.1% Wed, −4.6% week · NOW −4.3% Wed, still +19.7% on the month4 · Orchestration and actionSelecting agents and tools, sequencing steps, approvals, routing across applicationsNOW · SAP · CRM/MuleSoft · MSFT · PLTRSee rows 1 and 3; no orchestration vendor reported this week5 · Identity and policyWhich agent acts, for whom, with which rights, for how long, under which audit trailOKTA · CRWD · PANW · RBRK · NOWPANW seventh straight double beat, −9.3% Wed, through its 50-day · OKTA −2.0%6 · Observability and evaluationTracing cost, failures, tool calls and downstream effects of every runDDOG · DT · ESTCDDOG −6.5% Wed, −23.5% on the month, under its 50-day · DT −3.8% · ESTC +10.3% window, then −13.8% on the week7 · Recovery and reversibilityContaining the blast radius, restoring clean state, undoing a destructive actionRBRK · CRWD · PANW · FTNTRBRK widest EPS beat in its record, −17.4% in three days; −11.9% on the week8 · Software delivery controlAs agents write more code: review, testing, provenance, secrets, deployment governanceFROG · GTLB · MSFT/GitHubGTLB +10.0% Wed on a 33% beat · FROG flat Wed, −11.5% week
Read the last column as a whole and one thing stands out. The market paid exactly two things this week: a consumption meter that is visibly accelerating (Snowflake: product revenue up 37%, the third straight quarter of faster growth, full-year guide raised) and a delivery-control name that was priced for nothing (GitLab). It sold every layer whose meter is still an argument: operational state, identity, recovery, and above all observability, where Datadog‘s month-long slide followed a quarter in which one large AI customer reduced usage. That is the thesis’s own falsifier list playing out in real time, and it is why the framework insists on evidence-weighting rather than a basket.
§3 — The sequence: know, authorize, orchestrate, observe, recover, govern
The eight layers are not a staircase. They are four partially overlapping stages, and the order is set by the question an enterprise has to answer before it grants an agent more autonomy.
StageBinding questionLayersLikely beneficiaries1 · Ground the agentCan it understand the business and reach authoritative, current information?Context; state and memory; systems of recordSNOW, Databricks, MDB, SAP, CRM, ORCL, PLTR2 · Permit controlled actionCan it act with the correct authority through real workflows?Identity and policy; orchestrationNOW, SAP, CRM/MuleSoft, MSFT, OKTA, PLTR3 · Scale trusted autonomyCan thousands of actions be evaluated, secured and reversed?Observability; runtime enforcement; recoveryDDOG, DT, CRWD, PANW, FTNT, RBRK4 · Govern the agent estateCan many agents and harnesses from different vendors coexist under one control plane?Meta-harnessing; software-delivery controlNOW, CRM/MuleSoft, MSFT, DDOG, RBRK, GTLB, FROG
Stage 1 comes first economically because an agent without trusted context is a chatbot. But its three parts overlap: semantics (what the words mean), operational state (what is true right now) and the system of record (which version is authoritative and where the final transaction is written). Snowflake and Databricks are strongest on governed context; MongoDB on live state; SAP, Salesforce, Workday and Oracle own the authoritative objects. The detail that matters most: the system of record is both the beginning and the end of the loop. The agent reads authoritative state from it first and commits the economically relevant transaction back into it last. That gives SAP considerably more strategic weight than an “enterprise application” label suggests.
Identity precedes action. An agent may be allowed to read a customer record, recommend a refund, initiate it, approve it, or execute and book it. Those are five different permission levels, and the workflow layer cannot safely run the last ones without knowing which agent is acting, on whose behalf, with which tools, for how long and under which approvals. Inside stage 2 the order is roughly identity, then policy, then orchestration, then transaction, with Okta, CyberArk (now inside Palo Alto) and increasingly Rubrik on the identity side and ServiceNow, SAP, Salesforce/MuleSoft and Microsoft competing to own the orchestration itself.
Observability starts early and monetizes later. Technically it belongs in the pilot. Economically it binds only when agents execute large numbers of multi-step production actions, and the progression runs from “did the model answer reasonably” through tracing, outcome evaluation and violation detection to remediation. That is why Datadog can benefit before full autonomy, because tracing volumes grow during experimentation, and why Rubrik’s strongest moment arrives later, when agents get write permissions and a company needs clean-state recovery and an undo button. The week’s tape put a price on that timing gap.
Meta-harnessing comes last. A harness makes one agent production-capable: context assembly, memory, model and tool routing, retries, guardrails, evaluation, approvals, execution. A meta-harness governs many agents and harnesses across vendors: registry, cross-agent orchestration, identity federation, common policy, observability, cost control, incident response, recovery. You need agent sprawl before fleet governance becomes indispensable, so the likely order is vertical harnesses first (SAP finance, ServiceNow IT, Salesforce service, Workday HR), horizontal harnesses in parallel (Microsoft Foundry, ServiceNow Action Fabric, MuleSoft Agent Fabric), and one governance plane above them last. Vertical harnesses may monetize earlier because the workflow is bounded and the write path already exists; the universal meta-harness has the larger theoretical market and the weaker evidence today.
Compare the two constraint sequences side by side. Rubin’s is physical: compute, then memory and networking, then power, then cooling, then data-centre capacity, each bottleneck becoming visible as the previous one expands. The software sequence is permission-driven: context, authoritative state, identity, orchestration, verification, reversibility, fleet governance. The principle is the same, deployment advances until it meets the next constraint. The difference is that software layers can be bypassed, bundled or absorbed, so the strategy has to rotate by evidence rather than assume every layer earns a Rubin-like scarcity rent.
§3.5 — Where the frontier labs fit: the inside of the agent, not the outside
The obvious objection to any software-constraint thesis is that the model providers will simply absorb the layers around the model. Part of that objection is right, and the framework says so. Frontier labs can increasingly supply tool use, memory, orchestration, sandboxing, permissions, evaluation, tracing and coding or security agents themselves. Claude Managed Agents already bundles an Anthropic-run harness with state, memory, permissions, scheduled execution, authentication, multi-agent coordination, tracing and error recovery, and bills it as model consumption plus a session-hour charge. OpenAI’s agent platform spans the same ground; Google now ships native agent observability across Gemini and its cloud. The labs are potential owners of several middle layers, not merely vendors to them.
LayerLikely frontier-model ownershipWhat stays external or contested1 · Context and semanticsPartial: file search, connectors, embeddings, context assemblyCanonical enterprise data, business definitions, lineage, permissions: SNOW, Databricks, SAP, CRM, PLTR2 · State and memoryStrong inside its own envelope: sessions, checkpoints, agent memoryAuthoritative live application state and transactional databases3 · Systems of recordLow: can read and write when permissionedThe ERP, CRM, HR or supply-chain record, its process semantics and legal or accounting finality4 · Orchestration and actionStrong partial: generic agent loops, tool routing, multi-agent coordination, MCP, sandboxed executionCross-enterprise process ownership, approvals and the final write: NOW, SAP, CRM/MuleSoft, MSFT, PLTR5 · Identity and policyPartial: authentication to the platform, scoped tool permissions, model-level policyEnterprise-wide identity authority, human-to-agent delegation, privileged access across every model and app: OKTA, PANW/CyberArk, MSFT6 · Observability and evaluationStrong first-party: the model’s own loop, prompts, tool calls, token cost, task qualityNeutral correlation across models, applications, infrastructure, network and business outcomes, and an evaluator independent of the model being evaluated: DDOG, DT, ESTC7 · Recovery and reversibilityLow: retry, restore a checkpoint, roll back its own session stateRestoring enterprise data, code, configurations and identities to a verified clean state: RBRK’s most defensible boundary8 · Software delivery controlStrong partial: generate and review code, find vulnerabilities, propose patches, open pull requestsArtifact provenance, enterprise CI/CD policy, secrets, release approval, heterogeneous supply-chain governance: GTLB, FROG, GitHub, security platformsMeta-harness overlayPartial: govern a fleet built mostly on the provider’s own models and runtimeA genuinely cross-model, cross-cloud control plane needs neutrality, external identity, full-stack telemetry and recovery: NOW, CRM/MuleSoft, MSFT, DDOG, OKTA, RBRK
Anthropic as the test case. Its move into cyber is direct: Claude Security scans repositories for vulnerabilities and proposes fixes, in public beta for enterprise customers, while the company simultaneously distributes its models through CrowdStrike, Microsoft Security, Palo Alto Networks, SentinelOne, Trend Micro and Wiz. That is competition in model-native vulnerability analysis and partnership with the platforms that own telemetry, enforcement and the existing security workflow. Its observability move is narrower and inside-out: Managed Agents traces execution and integration analytics, and the evaluation work addresses task quality and failure analysis. That can absorb first-party LLM observability and squeeze standalone agent-only tracing tools. It is not yet Datadog or Dynatrace monitoring the whole application, infrastructure, network and multi-model estate.
Boundary, not blanket threat. Frontier labs are best positioned to own the inside of the agent: reasoning, the generic harness, tool calls and first-party evaluation. Independent software companies remain better positioned around the outside: authoritative data, enterprise identity, cross-model telemetry, runtime enforcement, transaction finality and recovery. The investable question is whether that external boundary stays unavoidable and separately billable.
Open at the model, closed at the monetization surface. Open-weight models (the safer term than “open source,” since licences and training-data disclosure vary) cannot charge for possession of the weights, so the rent has to be captured in a proprietary layer around them: hosted inference and APIs (Alibaba’s Qwen through Model Studio, hyperscalers serving open models), an enterprise control plane (Microsoft, Google, Amazon; privately Mistral and Hugging Face), hardware and runtime (Nvidia’s NIM and AI Enterprise, which turn open-model proliferation into accelerator and runtime demand), applications and advertising (Meta, whose 2026 update ties AI improvement to ads, messaging and engagement), and data and workflow consumption (Snowflake, Databricks, SAP, Salesforce, ServiceNow). Closed providers face the same direction of travel: as model prices fall and routing gets easier, OpenAI, Anthropic and Google also monetize complements, enterprise subscriptions, coding, managed runtimes, security, connectors, evaluation, vertical workflows. The durable value migrates away from the model even while the leading model stays closed.
The equity conclusion is deliberately not “software vendors are under threat.” It is narrower: frontier models probably commoditize generic harnesses and first-party agent tracing, and in doing so make intelligence cheaper, which raises demand for the external control points, governed data, action, identity, neutral telemetry, enforcement and recovery, provided the vendors that own them keep their pricing power. Open models are bearish for undifferentiated model access; they are potentially bullish for exactly the six sleeves this framework tracks.
§4 — Base-case timing, 2026 to 2029
2026–27 context, systems of record, vertical orchestration · 2027–28 identity, observability, runtime control · then recovery and reversible action · 2028–29 cross-vendor meta-harness and transaction control
The most contested transition is from “the agent can answer” to “the enterprise permits the agent to act.” That is where the constraint investment moves from Snowflake and Databricks toward SAP, ServiceNow, Salesforce, identity, observability and ultimately Rubrik-style reversibility. The stages will not wait for one another: context and system-of-record integration are already developing alongside orchestration, observability and security are deployed before agents get full autonomy, and software-delivery control is a parallel branch rather than a final stage. GitLab and JFrog benefit only if usage, compute, artifact and security revenue grow faster than paid human seats compress, which is why the thesis files them as a separate basket, not as part of the enterprise data layer.
§5 — What would prove it, and what would break it
Proof, in order of arrival. By year-end 2026 the demand should be visible in usage and cohort KPIs. Through 2027 it should show in net revenue retention, current remaining performance obligations and guidance revisions. By 2028 write-enabled actions should be visible in transaction and workflow volumes. If the evidence does not progress on that schedule, “constraint” gets downgraded to “optionality.” Today the clearest proof positions are Snowflake (measurable acceleration on a consumption meter), ServiceNow (AI past $1bn of annual contract value, agentic production deployments up ninefold) and Salesforce (Agentforce plus Data 360 near $3.9bn ARR, with attribution caveats). SAP is the core strategic expression of transaction finality, but its financial proof is still cloud backlog rather than disclosed AI revenue. MongoDB, Dynatrace, JFrog and Rubrik are emerging proof: the architecture and the billing fit, the isolated agent dollars are incomplete. Palantir is the highest thematic fit and the highest expectations risk at once.
The falsifiers are the part of the framework this week made concrete. Agents stay read-only. Adoption never reaches the financial KPIs. Price declines per query, log, token or action beat volume growth. Model and cloud costs absorb the margin. Open tables, Postgres, MCP and portable agent frameworks remove the tollbooth. Hyperscalers or systems of record bundle the layer. Seat compression wins. AI attribution stays rhetorical, pilots and “AI customers” with no dollars. Orchestration stays commodity plumbing. And telemetry optimization, the observability-specific one: if customers sample, cap or internalize agent traces faster than machine activity expands, the apparent constraint never turns into rent. Datadog’s month is the market pricing that last sentence.
Portfolio construction, in the diary voice. This page does not own a generic software basket and call it a constraint trade, and it does not treat the research ranking above as a buy ranking; the ranking scores thematic fit and current evidence and says nothing about entry price. What it does is keep six sleeves separate in its own thinking, context, operational state, systems of record and action, observability, identity and enforcement, recovery, with orchestration and meta-harnessing as a cross-stack overlay, and weight them by what the numbers show. All of these names share the same exposure to enterprise budgets, long-duration growth factors and multiple compression; the June 24 pulse on software’s second leg laid out why that common factor is the bigger risk than any single layer. Spreading across products does not remove it.
§6 — The tape this morning
S&P futures flat (7,676) · Europe pre-open DAX -0.1% · CAC -0.2% · FTSE -0.2% · Stoxx 600 -0.1% · indications ~06:15 UTC
US 10-year 4.78% (touched 4.82% Wed, highest since Nov 2023) · US 2-year 4.39% (4.41% intraday, highest since early 2025) · WTI $90.0 -1.1% · Brent $94.4 · Gold $4,465 +1.2% · USD/JPY 157.3 -0.9% · Bitcoin $77,735 +0.6% · VIX 15.2 -7.0%
Wednesday ended the three-day slide: the S&P 500 rose 0.46% to 7,666.60, the Dow 0.56%, the Russell 2000 1.13%, with ten of eleven sectors up and materials (+1.69%) and communication services (+1.39%) leading. The growth index did not join in the same way: the Nasdaq-100 ETF (QQQ) rose only 0.23% to 709.24 and closed under its 50-day average at 711.59 for a second straight session. Software fell for a second day while chips rose behind Nvidia’s 3.2%: the software ETF IGV lost 2.60% and is down 6.0% over two sessions against 1.1% for the semiconductor ETF SMH, the live version of the divergence this page’s thesis is about. The bond market paused rather than turned. The 10-year touched 4.82% and settled at 4.78% after New York Fed president Williams said rising long yields reflect a solid economy rather than inflation fears; the 2-year at a 2026 high says a September hike is still priced at 62–65%. Gold climbed back above $400 in the GLD fund (402.78, +1.5%) a day after losing it. ADP counted 38,000 private jobs in August, the fewest since January, and the Fed’s Beige Book described an economy growing modestly, hiring “very slightly” and mentioning data centres 25 times, up from one two years ago.
Asia was mixed and volatile: the Nikkei closed 0.12% lower after swinging both ways, the KOSPI ended +0.26% after erasing a 1.8% gain (Samsung and SK Hynix both fell more than 2% intraday), Taiwan lost 0.67%, Hong Kong is 0.4% lower. The yen strengthened to 157.3 with a Bank of Japan hike nearly fully priced and board member Takata hinting the next move could exceed a quarter point. The ECB’s Nagel said a hike next week is more than 95% priced.
§7 — Reference portfolios
IndexWednesday (approx.)September so farSince Aug 27Rubin 100≈-0.6%-2.3%-5.1%HALO 100≈+0.3%-1.2%-3.0%Euro-AI 50-0.1%-2.4%-3.9%AW40≈-1.0%-2.9%-2.0%
Two September sessions have cost all four house indices ground while the broad market bounced on Wednesday, because the indices are heavy in exactly the names being graded this week: AI software and AI infrastructure. AW40, the index closest to this thesis, is the weakest of the four in September and is starting to give back its +19.8% August. Wednesday’s single-day figures for Rubin, HALO and AW40 are derived from the nightly equal-weight leadership frames and marked as approximate; the index workers post the settled closes tonight.
§8 — Money Temperature
Composite 49 🟡 · Label Mixed / transitional, below the 50 line · Change unchanged on the day · Cointegration monitor 7 of 7 tracked pairs flagged as breaking
The composite Money Temperature held at 49 for a second reading, one point inside the cold half. Two readings below 50 are no longer a single warning; a third would mark the regime change. All seven of the cross-asset relationships the monitor tracks, among them software versus semis, gold versus the dollar and the crypto-tech link, are flagged as breaking at the same time, which is the statistical version of a market re-sorting what belongs with what.
§9 — Cross-read
The Rubin thesis worked because the scarce thing was physical and could not be conjured: you cannot print a fab or a substrate line, and the market paid every layer of that chain in turn. The software thesis this page opens today is built on the same mechanism, deployment advances until it hits the next constraint, applied to something that can be routed around: permission. That single difference explains the week. The market is paying the one layer where the meter is already spinning faster (Snowflake’s consumption, up 37% and accelerating) and one name that had been priced for nothing (GitLab), and it is refusing to pay the layers where the rent is still a slide deck: MongoDB’s state layer sold 13.5% on an eleventh straight beat, Palo Alto’s identity story sold 9.3% on a seventh, Rubrik’s reversibility story sold 17.4% on its best beat ever, and Datadog’s observability meter has lost 23% in a month after one large customer showed the falsifier in action, telemetry that gets optimized faster than machine activity grows. None of that says the framework is wrong, and neither does the frontier-lab objection: the labs are absorbing the inside of the agent, the generic harness and first-party tracing, which makes intelligence cheaper and, if anything, raises the value of the outside, the data, identity, telemetry and recovery boundaries the independents still own. It says the market is applying the framework’s own time discipline harder than the framework does: proof by year-end in usage, by 2027 in retention and backlog, by 2028 in write-enabled actions. Read against the backdrop, it fits. The Nasdaq-100 is under its trend line for a second day, software has lost 6% in two sessions while chips held, Money Temperature sits under 50, the bond market has paused rather than turned with the 2-year at a 2026 high, and the Beige Book’s economy is one that grows through data-centre construction while hiring “very slightly.” In that tape, the layers with a visible consumption meter behave like Rubin did in 2025; the layers whose meter is a promise behave like software did in June. This page keeps its September frame, a cautious month with a 5% pullback as the base case, keeps its bond rule with IEF under 93.04, and adds one working rule from today’s thesis: in the software constraint stack, evidence of a machine-scaled meter is the entry ticket, and architecture without a meter is a watchlist, not a position. The full report will take each of the six sleeves in turn.
§10 — Watch next session
Zscaler (est. $1.09 on ~$0.88B) and Samsara (est. $0.16 on ~$0.48B) report after tonight’s close, both entering marked down (172.73 after −3.2%, 36.79 after −5.8%); both windows score Wednesday 9 September because of the Monday holiday.
Snowflake’s 20% after-hours bid against the software ETF: if IGV closes lower a third day while Snowflake holds, the market is paying the meter and selling the sector, which is the thesis in one session.
Datadog at 209.23, under its 50-day (249.78) and 23% down on the month: the observability layer’s first falsifier is live; a stabilization would say the customer-optimization episode is priced.
The Nasdaq-100 ETF against 711.59: a third close below the 50-day average confirms the September base case.
US 10-year against 4.82% into the ISM services index and jobless claims today; Fed’s Waller and Hammack speak.
Friday 12:30 GMT: August payrolls, consensus +55,000 after July’s −23,000, unemployment 4.1%, the first jobs report of the Warsh Fed, with a September hike 62–65% priced.



