6.2mediumCONDITIONAL GO

Device Swap Runbook SaaS

Step-by-step guided workflow platform for IT teams executing bulk device rollouts with compliance guardrails.

DevToolsIT operations teams at companies with 100+ managed devices using M365/Intune
The Gap

IT teams manually cobble together procedures for device swaps, missing steps (like using TAP instead of password resets), creating security gaps (disabling MFA temporarily), and lacking visibility into which users have completed migration.

Solution

A guided runbook platform specifically for device lifecycle events — provides best-practice templates for common scenarios (phone swap, laptop replacement, OS migration), tracks each user through the workflow, flags security anti-patterns (like disabling MFA), and generates compliance reports.

Revenue Model

Freemium — free templates, paid for automation integrations and audit trails

Feasibility Scores
Pain Intensity7/10

Real pain confirmed by Reddit signals — IT teams are genuinely struggling with MFA/identity migration during device swaps and creating security gaps. However, this is episodic pain (happens during rollouts, not daily), which reduces urgency. Teams suffer through it every 2-3 years during hardware refreshes, then forget about it until next time.

Market Size5/10

TAM is narrow. Target is IT ops teams at 100-2000 device companies using M365/Intune — maybe 50-80K companies globally. At $200-500/month average, that's a $120M-$480M TAM ceiling. Respectable for a bootstrapped SaaS but not venture-scale. Expanding to all device lifecycle events (onboarding, offboarding, OS migration) widens it, but it's still a niche within IT ops.

Willingness to Pay5/10

Mixed signals. IT ops teams at mid-market companies have notoriously tight tooling budgets and strong 'we can script this ourselves' culture. The pain is real but episodic — hard to justify monthly SaaS spend for something needed intensely for 2 months then rarely. Compliance/audit angle improves WTP for regulated industries (healthcare, finance). The free template play may cannibalize paid conversion.

Technical Feasibility8/10

Very buildable as MVP. Core is a workflow engine with conditional steps, user assignment tracking, and pre-built templates. No deep infrastructure integration needed for v1 — templates can be informational with manual execution. Intune/Graph API integration for automation is well-documented. Solo dev could ship a functional MVP (templates + tracking + basic compliance flags) in 6-8 weeks.

Competition Gap8/10

Clear gap exists. Rundeck is too generic and DevOps-focused. MDM tools manage devices but don't guide humans through swap procedures. Process Street is generic checklists without IT intelligence. ServiceNow is overkill. Nobody is offering: pre-built device swap runbooks + security anti-pattern detection + per-user migration tracking + compliance reporting, all in one purpose-built tool for mid-market IT teams.

Recurring Potential4/10

This is the critical weakness. Device rollouts are project-based, not continuous. A company does a bulk swap, uses the tool intensely for 1-3 months, then churns. To survive as subscription: must expand to ALL device lifecycle events (onboarding every new hire, offboarding, break-fix replacements, OS upgrades) to create ongoing usage. Without this expansion, it's a professional services or per-project pricing model, not SaaS.

Strengths
  • +Clear competition gap — no purpose-built tool exists for guided device swap workflows with compliance guardrails
  • +Pain is validated by real IT practitioner discussions with specific, articulable frustrations
  • +Security/compliance angle adds urgency and budget justification beyond convenience
  • +Low technical risk — MVP is a workflow engine with templates, well within solo dev capability
  • +M365/Intune ecosystem is massive and growing, providing a clear distribution channel
Risks
  • !Episodic usage pattern threatens recurring revenue — bulk swaps happen in bursts, creating high churn risk unless scope expands to continuous device lifecycle events
  • !IT ops 'build vs buy' culture is strong — many teams will say 'I can build this in PowerShell and a SharePoint list' even if they shouldn't
  • !Template-led freemium may give away too much value — the templates ARE the product for many teams who just need the checklist, not the automation
  • !MDM vendors (Intune, Jamf, Kandji) could add guided workflow features as a checkbox, commoditizing the core value prop
  • !Mid-market IT tooling budgets are tight and procurement cycles are slow — selling $300/month tools to IT managers requires champion-building
Competition
Rundeck (PagerDuty Process Automation)

General-purpose runbook automation platform for IT operations. Lets teams define multi-step workflows, delegate tasks, and audit execution across infrastructure.

Pricing: Community (free/open-source
Gap: Zero device-lifecycle-specific templates. No awareness of MFA flows, Intune enrollment, or identity provider handoffs. Requires heavy customization to handle device swap scenarios. No compliance guardrails for security anti-patterns like temporary MFA disabling.
Oomnitza

Enterprise technology lifecycle management platform. Tracks devices from procurement to retirement with workflow automation for onboarding/offboarding.

Pricing: Custom enterprise pricing, typically $3-8/device/month, no self-serve tier
Gap: Focused on asset tracking and procurement workflows, NOT step-by-step guided runbooks for the actual swap execution. No real-time guidance for IT techs performing the swap. No security anti-pattern detection during migration. Overkill and expensive for mid-market teams that just need swap procedures.
Kandji / Mosyle / Jamf Pro

Apple device management

Pricing: Kandji ~$6-9/device/month, Mosyle ~$1-4/device/month, Jamf $4-12/device/month
Gap: MDM-only — they manage the device state but do NOT guide the human through the swap procedure. No runbook for the identity/MFA migration steps. No cross-platform guidance (phone + laptop + cloud identity as one workflow). No tracking of where each user is in a bulk rollout process.
Process Street / Manifestly

General-purpose checklist and workflow SaaS. Teams create recurring checklists with conditional logic, approvals, and integrations.

Pricing: Process Street: Free tier, Pro $30/user/month. Manifestly: $8-16/user/month
Gap: Completely generic — no IT/device-specific intelligence. No awareness of Intune, Entra ID, MFA providers, or TAP tokens. No security guardrail warnings. No bulk rollout tracking dashboard. You'd have to build all device swap logic from scratch and maintain it yourself.
ServiceNow ITOM / Freshservice

Enterprise ITSM platforms with asset management, workflow automation, and change management modules.

Pricing: ServiceNow: $100+/agent/month (enterprise
Gap: Massively over-engineered for device swap runbooks. Months of implementation. No pre-built device swap templates with security best practices. The workflow engine is generic — it won't flag that you're about to disable MFA as a security anti-pattern. Priced and scoped for enterprises, not mid-market IT teams.
MVP Suggestion

Web app with 3-5 pre-built runbook templates (phone swap with MFA migration, laptop replacement with Intune re-enrollment, OS migration). Each template is a step-by-step workflow with conditional branching. Core features: (1) assign users to a rollout batch, (2) track each user's progress through the runbook, (3) flag security anti-patterns with warnings (e.g., 'You are about to disable MFA — use Temporary Access Pass instead'), (4) export completion report. No Intune API integration in v1 — keep it informational/manual. Ship it, get 10 IT teams using it during real rollouts, then add automation.

Monetization Path

Free: 3 templates, up to 25 users per rollout, community-maintained templates. Paid ($199-399/month): Unlimited rollouts, custom templates, audit trail exports, team collaboration, security compliance reports. Enterprise ($custom): Intune/Graph API automation, SSO, API access, custom compliance frameworks. Upsell path: per-rollout pricing option for teams that won't commit to monthly ($99/rollout) to combat churn from episodic usage.

Time to Revenue

8-12 weeks to first paying customer. Weeks 1-6: build MVP with templates and tracking. Weeks 6-8: beta with 5-10 IT teams from Reddit/sysadmin communities. Weeks 8-12: iterate based on feedback, launch paid tier. The Reddit sysadmin community is an ideal early distribution channel given the idea originated from that pain signal.

What people are saying
  • We have a procedure but it doesn't seem like the best
  • Apparently we missed something in testing
  • we have to disable MFA on their account
  • treating device enrollment and MFA transfer as one atomic step, because they're not