FedRAMP (Federal Risk and Authorization Management Program)
A government-wide set of security and compliance controls a technology company must meet before U.S. federal agencies are allowed to put government data into its system. FedRAMP High carries ~425 controls (versus ~95 for SOC 2) and requires a separate enclave, encryption in transit and at rest, FedRAMP-only subprocessors, and assessment by an accredited third-party assessor.
The Federal Sponsor & Authorization to Operate (ATO)
After a 3PAO assessment, a company must find a federal sponsor — a CISO or CIO within an agency (or the DoD/DoW) willing to underwrite its cyber risk and grant an Authorization to Operate. This is the step where a senior official stakes their reputation and job on the vendor.
You Can't Buy a Sponsor
Every part of FedRAMP can be solved with enough money and time except getting the sponsor — paying for that is bribing the government and is illegal. Sponsors are won through funded mission owners, program budget holders, networking, and combined top-down (political appointees, agency secretaries) and bottom-up pressure.
Continuous Monitoring (the Forever-Audit)
FedRAMP is annually re-audited and requires monthly continuous monitoring: a check-in with the government across CVEs, misconfigurations, and overall security posture, with strict remediation SLAs (30 days for high-criticality findings, 90 days for medium).
The Exclusive Zip Code & Luxury Condo Model
Doing FedRAMP alone is like buying land in the most exclusive zip code and building your own house (permits, architects, supplies, inspection, forever). Knox instead runs the 'luxury condo building' on Main Street: customers move into a single-tenant floor, bring their own furniture (CI/CD, APM, hyperscaler), and inherit ~80% of the 425 controls plus Knox's agency sponsors.
Acquire-to-Accelerate (Buy the Authorization)
In an authorization-gated market, the fastest (if not cheapest) route to FedRAMP can be to acquire a company that already holds it, then build on that boundary — rather than pursue a multi-year organic authorization.
FedRAMP Duopoly Economics
Because so few vendors clear FedRAMP, entire federal software categories run on one or two authorized options — ITSM has only ServiceNow and Salesforce; the OMB HRIS RFP came down to Oracle and Workday. Monopoly/duopoly conditions push prices up and product quality years behind commercial equivalents.
The $1M Floor & Buying at Scale
The federal government rarely buys anything for under $1M — the contracting overhead makes smaller deals uneconomic — and it purchases for 10,000–100,000 users at a time, favoring vendors already proven at commercial scale.
Federal Readiness Self-Assessment
Before spending a dollar on federal, ask whether you've proven yourself at enterprise scale commercially — the one gate that can't be spun up. Commercial-first companies typically qualify around ~200 people / ~$50M revenue with a few enterprise logos; defense-tech, government-first companies can pursue it as early as 50–75 people.
The FedRAMP Halo Effect (Super SOC 2)
FedRAMP acts as a pre-diligenced, CYA-grade trust signal in commercial regulated markets. After a certification announcement the first inbound is often a financial-services or healthcare buyer, not a government agency — so FedRAMP behaves like a 'super SOC 2' that differentiates and closes commercial deals.
The Pricing Order of Operations
Design monetization in sequence: packaging first, then pricing structure, then the pricing metric (what you charge on, and whether forward- or backward-looking), and the price point dead last.
Jobs-to-Be-Done Packaging
Bundle features around the outcomes a customer is trying to achieve, not around a product-team ranking of which features get used most.
The Complexity Budget
The amount of pricing/packaging complexity a business can carry is capped by its ACV and the type of customer it sells to — high ACV can absorb complex enterprise pricing; low-ACV startup sales demand simplicity.
How AI Broke SaaS Cost-to-Serve
Classic SaaS had near-zero marginal cost and 80–95% margins; AI reintroduces a real, usage-driven cost to serve that most SaaS-native companies can't even measure, so pricing that doesn't follow cost loses money.
Outcome vs. Usage; Horizontal vs. Vertical
Outcome-based is what you price on; usage-based is how you meter it — and they can combine. Outcome pricing fits vertical products with a uniform outcome and is a trap for horizontal products where the same usage means different things to different users.
The Three-Question Test for Outcome-Based Pricing
You're a candidate for outcome-based pricing only if: (1) you can clearly define one outcome across your customer base; (2) customers agree to and accept that exact definition; and (3) the value of that outcome is similar across all customers.
Base Fee + Usage (CFO-Friendly Usage-Based Pricing)
Make usage-based pricing palatable by combining a recurring base fee with usage on top, wrapped in real-time visibility, per-team spend controls, caps/notifications, and token-level billing traceability.
The Validation Journey (Repricing Without Losing Customers)
De-risk migrating your most important customer by working backward: test new pricing on the least-important segment or market, then new business, then run validation interviews with your 2nd–5th customers, plus internal validation with the sales team, before migrating the anchor account.
Pricing as Product (Revisit Cadence)
Treat pricing and packaging as a living product surface, revisited every product-release cycle or sales cycle (whichever is longer) — not set once and left for five to seven years.
Human + Agentic GTM
A transformation framing in which agentic AI augments the revenue team rather than replacing it — the 'plus' signals that humans stay in the motion, owning relationships and accountability, while agents handle preparation and scale.
The AI-in-Motion Spectrum (Inverse to Deal Size)
The higher the deal value and the more up-market the customer, the less AI belongs in the customer-facing interaction — and the further down the tail (SMB), the more the agent can own the motion with a human reviewing the output.
ACV + Product Surface Framework
A two-variable decision model for how much AI to put into any motion: account value (ACV) and which product surface the customer is touching (and how mature that surface is).
Three-Segment Agentic Model
Split customers into enterprise (large advertisers), mid-market (D2C brands, performance agencies), and SMB, and assign a different agentic role to each based on that segment's customer-service needs and risk tolerance.
New Products Need More Human, Not Less
The newer and less proven a product, the more human-in-the-loop the motion should be — because the fastest way to learn from customers experiencing something new is to talk to them, not to automate the interaction.
The Centralize-vs-Decentralize Pendulum
AI enablement swings between a centralized owning group and fully decentralized team-by-team ownership; the healthy resting point is in the middle — cost-and-tool guardrails set centrally, process redesign owned by the teams.
The Data Foundation Gate
Whether you can decentralize AI at all is gated by the strength of your underlying data — a clean CRM and a healthy data stack are the precondition for letting functions own their own AI.
Measure Agentic GTM in the P&L, Not the API Bill
Judge AI initiatives by revenue and efficiency outcomes — speed to market, meeting volume, pipeline-stage conversion, revenue per head, ARPU — rather than by AI spend.
See the Whole Elephant
The operator's path to senior leadership: deliberately pursue new lines of business, international expansion, and reorgs so you see and understand the entire business, not just one function.
Feel the Pressure of a Number
The point of 'carrying a bag' isn't the title — it's going through a period where you genuinely feel the pressure of contributing to the top line, a career experience you have to go collect.
The Four-Priority, Color-Coded Calendar
Run your weeks against roughly four equal priorities, each assigned a color, and audit your calendar so it's about a quarter of each — a mechanism to keep strategic time allocation honest.
The First 90 Days: Absorb, Then Find the Truth
Spend the opening months of a new role absorbing information from two sources — the people on the ground doing the selling and implementing, and the available data — then marry those perspectives into a working theory of what's actually happening before setting priorities.
The Honest Plan: Missed Quarters Trace Back to a Planning Lie
When you miss a quarter, an intellectually honest post-mortem usually ties the miss to a planning or strategy assumption you weren't honest about — not to near-term deal execution.
Successful-Transaction (Outcome-Aligned) Pricing
Charge only when the AI agent completes the entire job correctly (e.g., reads and infers every field on a document 100% right), so price tracks roughly one-to-one with the value delivered.
Estimated ACV: Stacking Contracted + Forecasted ARR
Report usage-based revenue to the board by stacking two clearly labeled layers: contracted ARR ('take it to the bank') plus a conservative fraction of the forecasted amount booked as 'estimated ACV' (EACV).
Land Tight-Scope, Earn the Next Project
Start with a small, high-confidence use case you know you can nail, prove value fast, and use that win to earn the right to the next project — becoming the customer's primary consideration for what's next.
Use the POC to Close, Not to Sell
Qualify and sell the deal first, then run the POC only to confirm the solution works and the teams click — never as a desperate Hail Mary to generate intent that isn't there.
The POC Punch List
Before offering a POC, square away the MSA, legal and security, and budget, and get both IT and operations (the business side) at the table and excited. The POC then only validates the solution and the working relationship.
Post-Sales Joins Pre-Sales for Scoping
Have the implementation / agent-PM team scope the work during the sales cycle, so the buyer meets who they'll work with, gains confidence, and sellers can't over-promise.
The Plan as a Diagnostic (NUCO + Channel Model)
Build the revenue plan so every channel has its own win rate and ASP and new-logo ('NUCO') plugs the gap to the number — robust enough that a missed quarter can be traced to a specific assumption that broke, with leading indicators warning you a quarter or two out.
Top-Down Goal, Bottoms-Up Resourcing
Leadership sets a non-negotiable number; what's up for debate is only the resources required to deliver it. The exercise is iterative and cross-functional, and pairs with a proactive 'what would it take to 10x my org' model run before the CEO asks.
The SaaS Apocalypse (Native AI vs. AI Wrapper)
The fear that native-AI companies will displace SaaS incumbents that bolt AI onto legacy architecture — and the buyer's inability to tell a truly native-AI product from a SaaS wrapper.
Shared Risk via POCs
Meet the customer in the middle by proving value in their own environment through a proof of concept, sharing risk, then expanding — making the POC the default go-to-market move rather than a concession.
The New Multi-Threading (HR + IT + AI Committee + Security)
AI deals require selling horizontally across the functional buyer (HR generalists, HR ops, HR leadership), IT, an AI committee, and security — any of whom can veto or delay the deal.
The Economic Buyer Has Shifted
The economic buyer — the person with discretionary authority to say yes and move budget — has gone horizontal in AI deals; IT is often the new economic buyer even on an HR purchase.
Forward-Deployed Engineers as a Requirement
Embedding technical forward-deployed engineers into the implementation team to manage LLM change, build guardrails against hallucination, and hand-hold customers through early adoption — modeled as an accounts-per-FDE/CS gearing ratio in headcount planning.
Stacking Wins
An implementation philosophy (borrowed from Indiana football coach Curt Cignetti's 'stacking days, stacking wins') of engineering a continuous drumbeat of provable metrics and success stories the champion can tell internally.
GTM Engineer: Mid-Funnel Over Top-of-Funnel
Extending the go-to-market engineer role beyond top-of-funnel prospecting into mid-funnel deal execution — automated SOWs from call transcripts, company-specific deal coaching, and CRM-plugged GTM diagnostics.
MEDDPICC
The enterprise qualification methodology Scott helped develop; in AI's chaos the two most decisive elements he stresses are Champion ('no champion, no deal') and Decision Criteria — the capability shopping list a buyer uses to evaluate vendors.
Influence the Decision Criteria (Editable Weighted Scorecard)
Rather than extracting the buyer's decision criteria, supply it: an editable, weighted, unbranded capability scorecard that lets the customer objectively compare vendors for the problem they're solving.
Auto-Populate + Triangulate MEDDPICC
Auto-fill MEDDPICC in the CRM from Gong call transcripts while also keeping rep-entered MEDDPICC, then compare and contrast the two to triangulate what's actually happening in accounts.
The Build Order: RevOps + Enablement Before the First AE
When a company hires a go-to-market leader, RevOps and enablement are the first two hires; the ecosystem is built before AEs so reps ramp fast into a well-oiled machine.
Every Paradigm Shift Reinvents Advertising
Each new media/computing paradigm — radio, TV, web, social — builds a wholly new advertising infrastructure around it, and advertising never disappears. AI is the next paradigm and will get its own reinvented ad stack.
The Marketing Holy Grail (An Ad Made Just for You)
Instead of one agency-created, brand-approved ad shown to everyone, every person is served an ad generated specifically for them — the long-sought 'holy grail' that AI can finally deliver at scale.
Static → Dynamic: The Generative Ad Stack (Text → Assets → UI)
A ladder from a fixed banner to fully generated advertising: start with dynamic text generated to match the conversation, move up to generated assets, then to dynamic UI — the ad format and interface generated per user and per brand.
Sacred Real Estate / Build for the End User First
The publisher's surface area is treated as sacred, and the ad platform optimizes for the end user first, the publisher second, and the advertiser third — because end-user value drives engagement, which in turn makes advertisers happy.
CTR Is the Wrong Metric
Click-through rate is a misleading success measure because users can click without converting; the right target is the advertiser's actual objective (conversion/value), which should hold steady rather than decay if the ads are genuinely relevant.
The Naive Shoe-Ad Hypothesis & the Consumer Psychology Gap
The early assumption that 'user asks about shoes → show a shoe ad → they buy' is wrong; buyers research with an LLM but still purchase elsewhere to price-shop and earn rewards. Closing that behavior gap takes time, not just better technology.
High-Consideration Products Convert
The more expensive or complex a purchase, the more a buyer researches first — so AI ads convert best for high-consideration, financial categories (taxes, student loans, credit cards), amplified by seasonality like tax day.
Ads as Art
A north star of returning advertising to craft — the era when a Got Milk campaign or a full-page New York Times ad was a genuine piece of art — using generative tools to produce brand-true experiences people admire rather than block.
Clarity as the Ultimate Competitive Advantage
In a world of unlimited information and opportunity, the scarce edge is clarity — the ability to focus on the few highest-priority problems and not over-index on the feeling of stress. Individual clarity and organizational clarity move together.
Market Annealing
A concept coined by a16z's Martin Casado: unlike product-market fit (fitting a product to existing demand), market annealing means shaping the market itself — educating buyers, defining the demand, and shaping the product in parallel.
The Kitchen and the Hamburger Stand
The platform is a world-class kitchen that can prepare any 'meal' (extract value from any image or video data). Rather than acting as waiters serving every hungry customer a different dish, you build one focused 'hamburger stand' — a single killer app sold 100% outbound — to prove a restaurant can be built on top of the kitchen.
A Platform Needs a Killer App
A powerful platform doesn't create instant value on its own; it needs a killer application that lets customers get value immediately — the way Databricks needed notebooks before people could realize its value.
Value-Based Pricing on Pass-Through Infrastructure
Instead of marking up hyperscaler infrastructure and competing on its margin, pass that cost through at parity and charge on the usage or value delivered on top of it.
Pizza and Planning
A weekly leadership operating cadence with no fixed agenda or set times: the team gathers to solve the hardest problems and works until the set of things is finished, ordering pizza along the way.
The CRO Ladder (IC → Head of Sales → CRO)
A progression of accountability: an IC empowers themselves; a head of sales empowers through people and owns a team; a CRO takes accountability for the whole company — vision, strategy, fundraising, and product influence.
Non-Technical Debt (Partner, Customer, Employee)
Just as engineering accrues technical debt, an organization accrues partner debt, customer debt, and employee debt by taking on too many things at once and failing to fulfill the promises made.
Product-Market Fit → Go-to-Market Fit → Dynasty
A three-stage progression: prove genuine product-market fit once (a real problem, consumer-first), then achieve go-to-market fit by making the motion repeatable, then scale it into a 'dynasty' rather than a single lucky win.
Consumer-First, Not Tech-First
Build around a real consumer problem and behavior, deliberately not leading with the novel technology (crypto/blockchain) or a get-rich-quick token.
Quick Trade (Cashless Multi-Legged Liquidity Model)
A trading mechanic where a player offers unwanted items for a desired one; the system real-time-buys the target from one seller and real-time-sells the offered items to multiple buyers worldwide, netting a cashless swap.
The Laddering Approach to Adoption
Layering successive, lower-friction on-ramps into the economy — crypto, then credit card, then cashless quick trade, then an AI NPC negotiator — so each new rung pulls a broader persona into trading.
Ownership Evolution: Closed → Shared → Full Player Control
A staged handover of asset control from the studio to the player: start closed (assets exist but access is tightly controlled), move to shared responsibility ('you have a key, I have a key'), then to full player control (take it and go, even revoke the game's access).
AI Force Multiplier: Every Employee Becomes Three
When AI is integrated properly into how code is deployed and how engineers work, each person effectively gains a code reviewer, a junior programmer, and a security analyst — roughly tripling their output.
Multi-Model Adversarial Development
Using different AI models to challenge each other's work — e.g., writing a piece of code with Claude and having ChatGPT analyze it in the role of a security compliance officer.
The Three Pillars of Mythical
Mythical's build sequence: (1) economic tech — changing the economies inside games; (2) social interaction — new ways for players to compete and play together (Pulse Arena tournaments); (3) open platform — letting outside studios build on Mythical's stack.
It's Not You, It's Them (Fundraising Fit)
A reframe of investor rejection: a no usually reflects the VC's own vision or their LP-mandated 'deal box,' not a flaw in the idea — 'it's not a bad idea, it's just not the idea they have.'
Standardize Quote-to-Cash
Because every public SaaS company answers to the same SEC rules, quote-to-cash should be a standardized, out-of-the-box process — not a uniquely engineered snowflake per company. A 'unique' process is a problem to fix, not a competitive advantage.
One Unified Platform vs. Three Stitched Systems
Instead of a separate CPQ, billing system, and revenue-recognition system integrated between CRM and ERP, run a single platform that handles CPQ, AR/billing, and ASC 606 rev rec — sitting between the CRM and the GL with no reconciliation and one product catalog.
Slack-to-Quote AI Deal-Desk Agent
An AI agent that lets any seller generate a compliant quote by typing a plain-English request into Slack (or mobile, email, or the CRM). The agent parses the request, asks for any missing policy-required inputs, applies product rules, and returns a quote PDF.
Guided Selling
A business-focused Q&A layer that asks a seller simple questions (where is the customer located, what segment) and converts the answers into the right products, compliance, and discounting — instead of making the rep understand how the CPQ is configured.
The Flavors of Usage-Based Billing
Usage/consumption billing comes in distinct models: pure pay-as-you-go (no commitment, invoice on actual use), pre-committed plus overage (commit to a volume like 200,000 API calls/month, pay extra above it), and credit pools (buy a $100k pool and draw down across products, AWS/GCP-style).
Defining ARR for Usage-Based Revenue
A policy-driven method for turning variable consumption into a defensible ARR: for pay-as-you-go, take average consumption over a trailing 3-6 months and recognize a set percentage (e.g., 80%); for committed-plus-overage, the commitment is fixed ARR and overage recognition depends on how straight-line it is and what the auditor will accept (from ~95% down to ~20%).
Cancel-and-Restructure Without the Churn Penalty
When a customer adds licenses and renews early, you cancel the current term (crediting the unused period, like dropping a car lease) and restructure into a new term. Done right it's one opportunity, one order form, with credits and proration auto-calculated and reporting that shows it as upsell — not churn plus a new deal.
CPQ Is for Sellers, Not Deal Desk
The design principle that the primary consumer of a CPQ should be the seller, not deal desk or RevOps. Reps should be able to run even complex deals (multi-year ramps, partner margins, special payment clauses) and the entire post-signature lifecycle themselves.
One Order Object as Single Source of Truth
The seller creates an 'order' (draft during the sale cycle, confirmed once closed) and that same object generates the invoice and feeds finance. There's no separate quote-to-invoice re-keying, so numbers can't diverge between what sales sold and what finance bills.
The Four-Layer GTM Tech Stack
The consistent core set of capabilities the market keeps asking to have in one place: sales engagement (cadences and sequences), conversation intelligence, data and enrichment, and predictable forecasting.
Three Futures for the Consolidating Stack
Bernardo's three equally-likely scenarios for these platforms: (1) consolidation and rebranding succeed into specialized all-in-one platforms; (2) vendors can't escape their legacy branding and stay boxed into what they were known for; (3) a platform becomes the ecosystem — builds a CRM and takes on Salesforce and HubSpot directly.
The Living Vendor Scorecard
A re-evaluation discipline: dust off a structured scorecard and grade every vendor across its full, current feature set — not just its original category — and refresh it far more often than quarterly or annually.
Point Solutions vs. Pick a Pony
The core buyer decision: assemble best-in-class point solutions for each category, or align the whole go-to-market operation on a single consolidated platform. As tools commoditize, the pull is toward picking one 'pony,' driven by cost, bundling economics, and current negotiating leverage.
Value Misstacking
The mistake of misperceiving whether your highest value is functional or emotional and then stacking it incorrectly across messaging, content, and sales training — leaving real value unclaimed in the buyer's mind.
Worthiness Over Economic Value
A shift from measuring value in price (the only conventional unit) to a broader unit Miller calls 'worthiness,' since price answers none of the buyer's real questions about effectiveness or how the offer will make them feel.
Gravity: The Universal Law of Business
A metaphor treating value exchange between vendor and customer as gravitational attraction — heavier objects (more mass) pull lighter ones toward them — used to deconstruct why some offers pull customers and others don't.
Mass (Innate Value)
The first source of gravity: how valuable an offer is innately, before the market perceives it at all — a breakthrough technology is extremely valuable sitting in the lab before anyone knows it exists.
Proximity
The second source of gravity: getting an offer close enough to the customer that they know about it and can be pulled toward it — high-touch for enterprise, low-touch volume for SMB.
Anti-Gravity (The Gravity of Alternatives)
The third and most-overlooked source of gravity: the opposing pull of competing options that holds the customer in place and prevents a value exchange — the gravity of the next best alternative.
Fusion Event (Nonlinear Reward)
An occasional, outsized, nonlinear payoff that occurs when timing or the sudden significance of a job-to-be-done causes value to compound rather than add.
The Inner Core (Your Superpower)
The single element of value that is most strongly connected to your brand — unique and special to you. Tom also calls it your superpower, and cites data that it can represent as much as 70% of perceived value.
The Value Triangle (Functional / Emotional / Economic)
A triangle whose three sides are the ways humans subconsciously perceive value: functional, emotional, and economic. In any value exchange the brain stacks one element as primary — up to ~70% of the perception.
Jobs to Be Done + Outcome-Driven Innovation
Products are tools that help customers get jobs done. Whether a customer acquires a tool depends on the job they're trying to do and how functional or emotional that job is.
Lower the Cost of Customer Thinking
A maxim Tom credits to Kellogg's MBA program: the primary job of a marketer is to lower the cost of customer thinking. Adding feature on feature or benefit on benefit dilutes rather than compounds perceived value.
Plumbers and Poets
Tom's metaphor for RevOps: the 'plumbing' is instrumenting, maintaining, running, extracting, and visualizing the data; the 'poetry' is interpreting that data into a performance narrative. The combination is the value.
Expected Annual Contract Value / Expected Annual Recurring Revenue (EACV / EARR)
An informed estimate of what a usage-based deal will be worth over its first 12 months (or a chosen period), assigned even when zero dollars are contractually committed, so the deal can be reported, forecast, and managed.
Track Expected Value Against Actuals
A closed-loop discipline of tracking each deal's real consumption against its assigned expected value — daily, monthly, or otherwise, but at least through the first year — to see where estimates over- or under-called.
Data Baseline + Rep Judgment
A method for estimating expected value that starts from a data baseline — usage trends of similar companies and of a customer's first three, six, and nine months — then layers in rep discovery, safeguards, and discounts to land a defensible number.
The Commitment-for-Discount Trap
The anti-pattern of forcing usage into a committed contract by discounting the per-unit price — e.g., committing 25% of expected volume for a 10% price cut — to buy reporting predictability.