
B2BaCEO · 2026-02-20 · 36 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
Aaron Levie makes the case that AI agents in 2025 are failing because they lack context - not just data, but the decision reasoning and organizational logic embedded in conversations, emails, and workflows that incumbents' systems of record don't capture. Context graphs stitch together event streams, documents, conversations, and decision metadata to give agents the "why" behind decisions. Levie argues this creates a trillion-dollar opportunity, particularly in functions where multiple systems of record exist (go-to-market, HR), where unstructured data dominates (compliance reviews, code reviews), and in operational roles (RevOps, DevOps, FinOps) that exist only to bridge disconnected systems. He positions this as potentially disruptive to Salesforce, SAP, and Workday, though he acknowledges incumbents retain advantages in access controls, permissions, and organizational workflows that have been embedded over decades. The discussion explores how companies like Player Zero are collapsing three independent functions (support engineering, QA, SRE) into one by combining code, support tickets, and observability data. A critical tension emerges around security: agents can't reliably keep secrets or enforce permission boundaries, making deterministic access control systems (Box's forte) more valuable in regulated industries.
A context graph captures decision traces - the reasoning, conversations, documents, and metadata behind decisions - scattered across tools like Slack and email that agents need to understand not just what happened, but why decisions were made, enabling them to act intelligently rather than just execute transactions.
These systems capture outcome data but not the event streams, decision reasoning, or unstructured context (emails, calls, documents) that explain why decisions were made, forcing agents to operate without the organizational logic and reasoning patterns they need to function effectively.
High-headcount manual workflows, exception-heavy decisions (deal desk, underwriting, compliance reviews), go-to-market functions (which use 5+ systems), HR systems, and operational roles (RevOps, DevOps, FinOps) will see the most disruption because they either span multiple systems of record or rely on unstructured data that incumbents don't capture.
No - anything in an agent's context window can be extracted via prompt injection, so regulated industries like law, finance, and healthcare must rely on deterministic access control systems rather than trusting agents to enforce permission boundaries.
These roles only exist because no single system of record connects data - agents can now automate what previously required human glue workers to bridge multiple systems, creating a new software market that was too small to underwrite before AI agents enabled unlimited capacity.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains genuine non-obvious ideas - the 'agents can't keep secrets' security thesis and the AI-coding access-control free-lunch observation are real insights - but they are spread across considerable meandering and mutual agreement. The insight-per-minute rate is moderate, dragged down by repetitive throat-clearing and abstract framing.
our general thesis at boxed is agents can't keep secrets
I think one of the untold reasons why uh, AI coding just takes off with zero friction is you almost never worry about access controls
The access-control framing for agents is a fresh and operationally useful lens, and the observation that engineering teams are structurally over-permissioned (creating an AI free lunch that other functions lack) is genuinely counterintuitive. However, the broader disruption thesis explicitly recycles the cloud-vs-on-prem analogy, and most enterprise-software market-structure arguments are well-worn.
there's nothing you can give an agent that it will ever be able to fully sort of keep track of in its context window that it's not supposed to share with somebody else
I think one of the untold reasons why uh, AI coding just takes off with zero friction is you almost never worry about access controls
Aaron Levie is a 20-year practitioner who has steered Box through the on-prem-to-cloud and now AI transitions and is actively building product in the context-graph space - not theorising from the sidelines. His credibility is earned operationally, not through thought-leadership branding.
I've been doing box for 20 years. I've been watching software for third for 26 years
the thing I feel most certain about is um, the kind of power law dynamics of software, uh, don't change as a result of vibe coding
A handful of named companies and rough figures appear (Oracle $500B, SAP $300B, Salesforce/Slack, Player Zero, Eightfold, Vivint) and the power-law market-share claim comes with actual percentages. But the central context-graph thesis is never illustrated with Box customer metrics, adoption data, or a concrete before/after case study.
Oracle's a $500 billion company. SAP is a $300 billion company
The top player in the space will be 70% of the market. The second player will be 20%, the third player will be 6%, the fourth player will be 2%
The host is clearly knowledgeable and contributes substantively to the thesis, but this means the format is closer to a co-presentation than an interview - Aaron's claims go largely unchallenged and follow-ups are additive rather than probing. The lightning-round questions at the end are generic and the episode ends without any real pushback on Aaron's bullish incumbents-will-be-fine framing.
What is the one assumption about the future of software that you feel the most certain about?
I totally agree with that
Computed from the transcript - who did the talking, and the words that came up most.
Aaron Levie has been on the podcast twice before. After we published our context graphs thesis, he wrote a response - so we invited him on to continue the conversation. A context graph is institutional memory for how an organization actually makes decisions: not how the process doc says it should, but how it works in practice. Enterprise software is very good at recording outcomes - the final price, the approved discount, the escalated ticket - but not the reasoning behind them. Which exceptions applied? What precedent mattered? Who approved what, and why? We call these missing records decision traces. Over time, they accumulate into a context graph: a living, queryable map of how an enterprise actually makes decisions, stitched across systems and time so precedent becomes searchable. We think the companies that capture that layer will define the next generation of enterprise software. Aaron read the piece and joined us to push it further. We get into how the services as software opportunity unfolds as agents scale, and what it actually takes to move them out of the sandbox and into production. Chapters: 00:00 Intro: Aaron’s third time on the podcast!
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign.
Speaker B: Thank you so much for being on the B2B CEO podcast. Gnr. Excited to have you for the third time.
Speaker C: Nonetheless, I, I hear it's a uh, I hear it's a record for the podcast. So uh, you're popular.
Speaker B: What did we say that's uh, or
Speaker C: you just run out of guests. Maybe we've, maybe we've, maybe it's a sign of uh, where enterprise software is that.
Speaker B: Well, given what's happened to the markets
Speaker C: this week, there's nobody left to do your podcast.
Speaker B: My portfolio is looking really bad. I was like at what point do I need to start selling my Atherton house?
Speaker C: Your uh, uh, your guys post was a little bit too uh, too powerful and uh, maybe you should have timed the market a little differently.
Speaker B: Yeah, maybe you can you know, start by just you know, describing what is a context graph and why does that matter? And we'll take it from there for sure.
Speaker A: So I think if you take a step back, 2025 was supposed to be the year of AI agents and I think the models actually did get better. But in enterprises agents still don't act like you'd expect them to. And I think the reason is actually pretty simple. Like agents can read data and take action, but they still don't know why decisions get made. And I think that reasoning is something we call decision traces. That those decision traces are scattered across tools buried in Slack and sometimes I don't think they get recorded at all. Um, and I think the winners of the future will be companies that can capture those decision traces and turn them into context graphs.
Speaker B: Aaron, you've been blogging prolifically from the very early days on AI more broadly and more recently on context graph. So I'd love to get your take on it.
Speaker C: Yeah. So uh, I mean I thought uh, your guys post was great. Um, very provocative. I didn't agree with 100% of it, uh, but the core notion of it I think was sort of spot on. Um, like agents, they only work when they have context. That context uh, often doesn't live in the kind of outcome of things. It lives within how people made a decision or uh, the guidelines that they have to follow to make a future decision. And many of our systems of record contain output information. They don't contain all of the stuff that was in people's heads that went into that decision. So you know, let's say that's it seemed like that was a core part of the thesis. Totally, totally agree with that. Uh, you know, I think there might have been obviously a pretty strong Conclusion that it will require an all new set of companies for all of the, all of the use cases. And as venture capitalists I would only expect you to make that claim.
Speaker B: It's a little self serving.
Speaker C: It's totally appropriate for that to be the uh, the emphasis. Um, and I do actually think that this is a very disruptive concept that will uh, certainly caused many incumbents to fail and miss the window. Um, ah, but at the same time I think there's some categories of software where what they do have or the workflow that they're involved in is sort of a natural launchpad for capturing that context. Um, and so then it's a little bit of a game of, you know, almost it's kind of like a race of all software of who can get the best context first per category and per job function or perhaps per line of business or workflow. Um, and I would say that it's very hard for me uh, from first principles to just say generically who wins and loses. Um, uh, because a lot of it actually just comes down to the execution of each individual firm how good their tech stack is, how well can they get the kind of products upgraded in this way. Um, but I totally think even, even it's one of these markets where um, and we saw the same thing with on Prem and cloud actually it's one of these markets where you could completely bet on every incumbent and still have the market size double for all new startups to emerge simply because either the categories are just going to be so much larger or there's so many categories of software that never existed that you'll now need obviously context graphs for and uh, that will just create the next set of 10 and 50 and $100 billion software companies.
Speaker B: I totally agree with that. I think if we go back to some of the work that we did around services as software and you and I have talked about that in the past as well. I think in all of the established Categories There's a 5-25x expansion in TAM just because of the automation of human activity. At the same time I want to come back to your point around incumbent systems of record and maybe you know, get a point of view from both you and Jaya. We do see that incumbent systems of record are really struggling to incorporate these new data types because you need, you need an event stream data not just the outcome that event stream has uh, to have state because you need to know which event happened, what the sequence of events matters. Each of these events has to be then associated with, with data and Metadata around documents, around conversations. Like when a pricing decision was made, it was made maybe on a zoom call, it was made maybe in an email. And so you have to associate the decision, the state of the decision with the underlying documentation. And I could go on and on, but that kind of data fabric does not exist. And I think for us that's the context graph. It's the ability to stitch all of those things together.
Speaker A: You know, Aaron, I think you actually made a really good point that there's um, there's a correlation between a software company's moat and the amount of data they house. And like what, what that got me thinking was is it the volume of data or is it the type of data that actually matters for agents? And also is there a difference between data and context? Because I think incumbents definitely have the most data. Like Salesforce probably has like what, 20, 25 years of customer data, SAP has like decades of uh, transaction data. And then you know, workday has all the information about like when I onboard in and everything. And you know, and maybe this is again a little bit self serving but I think what's more important is like again the why behind the what. And so I think that actually lives today outside of systems of record. And I think that um, the concern is, you know, if that organizational reasoning becomes the most valuable asset for the agents and then where, you know, where do the incumbents end up now? I think Salesforce is lucky. They kind of, they own Slack and a lot of reasoning does happen there. Um, but you know, I don't, I don't have a good take yet on the other ones.
Speaker C: I don't know if your piece was specifically written this way. Obviously the Internet, you know, deals in sort of binary outcomes. And so I think everybody sort of saw this as, as a zero sum, you know. You know this is, this clearly means the end of, of the system of record and these traditional platforms. And I've just now, you know, I've been doing box for 20 years. I've been watching software for third for 26 years. Maybe it's much more boring to talk about it this way, but things just end up being much more um, nuanced and sort of positive. Some back in the enterprise software, uh, cloud versus on prem versus Cloud, uh, almost every single on prem enterprise software company from let's say the 90s, uh, unless it got acquired or shut down is bigger today. Oracle's a $500 billion company. SAP is a $300 billion company. Uh, and so it just turned out that actually the cloud Companies were very disruptive. They served all new customers that could never have bought enterprise software. They solved all new use cases and at the same time the enterprise software players just kept evolving and modernizing. And so obviously this analogy is a little bit different, but I think on the context graph piece, first of all, I totally agree with your point. All data is not treated equal, um, for generating a useful set of context for agents. Then the question though is if I'm an it, if I'm an enterprise IT buyer, um, or implementer of enterprise it, and I've already implemented Workday to do all of my HR data and I have all of my organization built into this thing and IT has all of my understanding of my business and my people and my org chart. The question will be, uh, how hard is it for Workday to add the incremental context that, that an agent within Workday needs to make useful decisions versus how hard is it for a new company to emerge to get all the data that Workday has? Um, uh, and I think each category will sort of have its own race like that. Um, and I think you'll, and then in some cases it'll actually still be a hybrid. There'll be a new agent that actually pulls the data from Workday and it ends up being sort of complimentary and in workday's best interest to give that data to that agent because it only reinforces the sort of value of that system. In which case then actually maybe the value of many of the elements of the context graph sort of appear in that new startup. But the system of records, purpose and value didn't really reduce in the process. And that's I think, the hybrid state that we're going to have in a lot of categories. My general mental model is, um, if you had 100 times more agents in an enterprise, uh, then the question would be would those agents kind of reinforce the value of your core systems of record or would they, would they reduce them? And, and the concern I have is that if I'm an enterprise and I'm running mission critical transactions on an ERP system that is powering my supply chain and like I can't get anything wrong, 100 times more agents actually to me means the system that traffic cops those agents, the guardrails on what those agents can have access to and what they're able to actually execute work within in that supply chain, to me the value of that system goes up because actually getting all of that orchestration right becomes even more important and more valuable when there's a hundred Times more things trying to bang against that system by either adding data or reviewing data from it. And so, uh, I haven't found a lot of categories where that doesn't kind of obviously happen. Again, the X factor is will the incumbents respond? Will they build, will they either build agents in their platforms that are actually real useful agents, um, or will they have at least powerful APIs and not kind of close them off in some way where it's just sort of economically impossible for any external system to use them? But if those two things are true, then I think the value on the margin of a CRM system or of an HR system goes up. The value of that core system still has now increased because of the value that's being executed.
Speaker B: I also think there are functions where there are still multiple systems of record at play. So I'll take two extreme examples. Uh, in most companies you have one system of record for finance and all associated finance data. And you may use SAP if you're really large, you may use NetSuite if you're an emerging business and there's a lot of stuff in between. But you usually standardize on one. And I think replacing that, like when you talk to CFOs, the reaction is visceral. I hate it, but I'm not going to do it. So I actually think the relative value will change and it will vary depending on which company in terms of how they respond. But I think those systems are actually in decent shape. I'll take two examples however, which are very different. If you look at go to market systems. Despite Salesforce's dominance of core CRM, most companies are using half a dozen different go to market systems. There's CRM, there is something for demand gen. You have a sales engagement platform, you're taking your customer support tickets. Very few people have actually standardized on one platform. It's just the reality of how go to market systems work. In part because each of those teams in an organization likes to do best of breeding. In part it's a newer category. Same is True actually in HR people will use core HRIs. Maybe very different from your applicant tracking system. Could be very different from your performance management system. Those are the three big systems in hr. Ah, less in number than the go to market function, but still multiple systems. I think both of those functions will see a lot more change because the incumbents don't have all the data, they don't stitch it together. Uh, these are also two functions where a lot more of the data is unstructured and the incumbent systems don't capture that data by definition. Uh, so I think it'll vary function by function. And again, as you rightly pointed out, it depends on how the incumbents react. I mean, Salesforce and Servicenow and Workday are remarkably strong companies. I mean, I wouldn't ignore them for a second. I was, I was buying more Salesforce talk yesterday, even as I say this.
Speaker C: Yeah, yeah. I mean the, the only other, maybe just one or two other incumbent advantages and then, and then maybe maybe worth switching to the, the, you know, all the greenfield areas because, because for what it's worth, I think that will be $1 trillion. Um, uh, of all the new opportunity, I'm a little bit biased because this is sort of what we see all day long from the box side is, is, you know, once you've wired up your organization with things like access controls and permissions and who has access, what workflows are those involved in. And I couldn't quite get that into the enterprise, you know, the enterprise post that I did. But that ends up also being a bit of a moat and it's sort of correlated to the workflow piece. But people underestimate just how many years of sort of organizational, uh, wiring has been now kind of incorporated into software. And the challenge with agents is, as we all know, is agents would love to just tell you the answer to anything that the moment you ask it. And so unless the agent knows what you have access to and can only do things on your behalf that you're actually allowed to go and execute on, then all of a sudden, obviously you have a massive security challenge. So that's why to some extent you see agents using these systems as tools because it's this natural proxy for what does the user have access to. And so it's just this very convenient sort of relationship, which is the agent can only then do things in the tools using the permissions that I already in that tool, which then effectively ensures that you are able to maintain the same security and access control levels that you previously had. And so if you have a bunch of new agents that don't know what the permissions levels are because you're trying to recreate a new graph that is sort of outside of the existing systems, you'll end up with this huge uphill battle of how do I give the agent all of the appropriate knowledge about any given workflow? And if it's no if, I'm no longer in my sort of system that already has a lot of that workflow that's been built out, and so that's why again, another kind of incumbent advantage where that's at least a relevant dynamic.
Speaker B: I think you're spot on. And I actually think there's a class of companies in sort of communication and collaboration, uh, box for sure. I think Microsoft, I think Google with their suite, uh, okta, which doesn't do communication collaboration, but is often the platform for access control. I think these companies all have a very unique strategic position in the market and how powerful that is over the next decade will depend on how it evolves. Uh, but that's not true for all of the incumbents and that's part of why the story will be so different. Jay, I want to come back to you. One of the two space, one or two spaces that you are most excited about. Where do you believe a large chunk or a disproportionate chunk of the trillion dollar opportunity will get captured?
Speaker A: Uh, so I think it'll probably be in a few different places and I think you have to kind of come up with creative wedges here. But I think one is going to be like high headcount workflows, like I think where you see 50 people doing some process manually. I think it's because the decision logic is just too complex to automate with traditional tooling. And I think too m. You know, when there's too much judgment, there's too many exceptions. I think that's one signal. Um, another is like I think exception heavy decisions. So places like deal desk underwriting, compliance reviews, uh, places where there's a lot of escalation management. And then I think the third is like looking around like the glue functions. And so I think you kind of mentioned this earlier but like there's so many functions like Rev Ops, DevOps, Sec Ops, FinOps, like if you put an ops behind it, I think, you know, like why do those roles exist? And I think it's because like there's no single system of record and they're like kind of like the glue between like two or three different systems, um, and the bridge between different functions. And I think they're kind of like today their, their function is like just carrying context that software doesn't capture. And, and so I think those are, those are interesting places and I think you know, they have a bad rap because I think software hasn't been sold successfully to them. So, so I think we'll have to like, we'll, we'll have to see like I think one of the problems will be like which who's, who's going to be the buyer? Like will the CRO get excited about it if it's revops. Um, and like how will, how will, you know, startups push through to the buyers? So I think we'll still see a lot of challenges with them, but I think there are some interesting wedges.
Speaker C: I really like the ops, uh, point that you guys made in the piece. Um, uh, uh, and from a software standpoint, it's exactly this sort of, you know, I think where, where the agent opportunity, you know, kind of creates these new markets is like the total headcount with X ops in your organization is like three people per, per. Per, you know, whatever X is. So like if you were trying to sell, you know, marketing ops software before, there's like two people that need the seat of that software. So you could never underwrite building a software company for that. Um, but all of a sudden if like ops equals just, you know, unlimited agents, now you can get deployed because you actually are just bringing in the actual capacity of that work. Um, and so I think that's a huge area where you'll see a lot like there's no incumbent. It's never worked as a software category before because the tams were too small. Um, and you just have like complete, you know, all new use cases that the company can go and automate on your sort of 50 headcount thing. I think that's an interesting heuristic. The um, uh, Paul Graham actually just tweeted this one yesterday that I think just factors into my thinking as well, which is just anywhere where there's a large body of things you either need to process or produce that is obviously text based. Um, uh, which is on one hand you're like, okay, that's very obvious, but it's actually kind of counterintuitive where you make money from that. Um, you said things like compliance reviews as an example, but I think there's so many workflows in an organization that are basically just constrained by what is the mass of data that people can just understand, interpret, review, analyze and then be able to make a useful decision as a result of that information. Um, uh, and those are all categories where you just really never had software. Because previously, yeah, we could store the data, we could log the data, but we never really did anything with it. And so agents now let you actually do something with it for the first time. Um, I don't know totally how this market plays out, but like as an example, you've now seen like three or four or five different companies do these code review products. Um, which is like this great example of like there was not like a software category called code review.
Speaker A: Yeah. So, uh, Player Zero is one of our companies and they're building a, you know, production engineer and they're solving, I think, three, three big problems at once. But one is like tackling the support engineering workflows, like, and think, you know, uh, you know, tier three kind of like technical support, uh, issues. They're doing qa and then they're also thinking about, you know, AISRE workflows.
Speaker B: And the thing that's so interesting about that example is their context graph combines code support tickets and observability data. And it's taking three functions, which have been three independent functions in an organization, and it's collapsing them.
Speaker C: So then the question is like, how many, you know, how many players, zero markets are there where actually you need to sort of bring together three or five different functions and then thus, you know, a new, a new type of player is the only way that you could actually do that, which would be then a, uh, uh, kind of classic innovator's dilemma problem. For the most part. I have a. I generally think of an agent as an extension of what your, you know, your current worker does, and then it just gives you 100x the capacity. But obviously there's a lot of use cases where an agent should do something that was like 10% of 30 people's jobs and, you know, connect them all together. You know, obviously again, there's not going to be any incumbent that owns the data stream for that because. Because no human did. And so then there's nobody who has the access controls or the permissions even, you know, to be able to go and do that.
Speaker A: And I have a question, I think, because we're bringing up access controls a lot, but I think it's a very interesting point. You know, a lot of regulated industries, law firms, banks, health care, there's a lot of strict conflicts and you know, they can't access certain documents. But I think with document retrieval, it's easy. You filter query time based on some permission. But as agents learn patterns across documents, it's harder. Right. Like if an agent learns something from document A and a user can't document user can't access like document A, can the agent still apply what it's learned, you know, when answering that user's question? And I'm curious if you guys have seen anything around like permission inference?
Speaker C: Yeah. Um, uh, well, yeah. So this is sort of, to us, you know, what makes my life so much more pragmatic than I think, like, you know, if I was like a 19 year old entrepreneur again. I wouldn't even have to think about any of this stuff. But like now I'm, I'm this old man and, and I think about access controls.
Speaker B: Old is relative Aaron.
Speaker C: So all right, fine. Compared to maybe Jai, I don't know how old you are but uh, um. So I don't know of a good way. I'm sure somebody has a research paper out there. I don't know of a good way where an agent can know something and then ensure that it never is able to expose that to somebody else. Um, like with any degree of kind of prompt injection. Uh, and engineering you can almost always extract anything out of the context window. And so our general thesis at boxed is agents can't keep secrets. Um, uh. And so there's nothing you can give an agent that it will ever be able to fully sort of keep track of in its context window that it's not supposed to share with somebody else. Which basically means that you have to rely on deterministic systems to control those access, uh, the access levels. Um and so uh, again somebody out there has amazing research that have some kind of like inference sort of permissioning model. Um, I haven't seen it. M. I'm sure somebody's working on it. Maybe you know something, please tell me right now because we'll go look into it. Uh, but uh, it's not something that we've run into that would be practical at scale.
Speaker B: It's a very hard problem to solve. A couple of different companies actually Eightfold and Vivint that do deal with this problem. Uh, but they deal with it sort of at the context layer level where they actually determine what aspects of the graph an agent can traverse in its good old fashioned access control. But applied to the graph. Yeah, yeah.
Speaker C: And that totally makes sense. The gotcha with a lot of these things is, and this is why, this is why, um, uh, either existing software or new software that's being built but it has to kind of map to this model. Uh, like why this matters is so how did you give the access control though to the right people? It's great that there's APIs for all these things and it's great the agents can do that. But I as an end user still need to give something to my lawyer. I still need to give something to my investment banker. And so that's why you're still going to probably want to rely on some systems that you're familiar with. I still want to expose that folder. Uh, I'm biased to Box inside of a box environment or open something up in a slack channel. But you don't really extend permissions and access controls to people through lots of systems. All throughout your day you kind of rely on three or five or ten different things because your brain explodes. You have too many different permutations of things you have to manage for all the people you're working with. Um, and so that like, unless you have a way where a human can give access to somebody else, you know, something to somebody else and an agent can also access that thing, you need that complete system if you're going to be able to go and deliver on, you know, the graph that will actually drive the automation. I think one of the untold reasons why uh, AI coding just takes off with zero friction is you almost never worry about access controls. Like, you know, if you're an engineer on a team, you get access to everything.
Speaker B: You get access to everything. You're always over purpose. Yes.
Speaker C: And like. And so we have been in this completely free lunch zone of AI, you know, automation for the past couple of years, which is I just have an agent go look at some code and write more of it. But I can't do that if I'm on a team working with contracts. I can't do that if I'm an investment banker working on deals. I can't do that if I'm in life sciences, you know, working on an FDA drug trial where there's clinical information on that has PII on it. Like, like I don't have that free lunch that the engineer has. So this is the, this is sort of the real world that's going to cause, you know, either the incumbents to catch up or have enough time or just, you know, some of the spaces to look a little bit different than, than maybe what we've seen in the, in the first era of AI agents.
Speaker B: And they will absolutely look different. I do want to come back Aaron, to sort of, if you had to pick one or two areas where you think startups have a real advantage or opportunity, which would those be?
Speaker C: To me, the areas that I get most excited by from looking at startups is where have there been, where is their work that basically everybody would agree there needs to be more of this work done, but they can never. A company can't, can rarely sort of either hire enough people to do that work or, or they are bottlenecked in their organization by that work. It's kind of like a little bit of an imprecise kind of framework. But I just sort of think about it even as we build Box, like where are the places where if I could hire 10 or 15 more people in that area that'd be great. It would only be net positive. But we're constrained by some resource allocation process that makes that very hard to do. And those are usually the areas where it's just like you're going to see so much tailwind because companies will say shoot for the first time ever for a tenth of the price of somebody. I can now do more of that work. And oh, uh, by the way it's actually not replacing anybody because we could not hire enough of those people previously. And that's where I think some of the biggest opportunities are. Companies already have budgets ready to go and it's like a relief to them that agents can now do those things. So that's kind of tended to be my investment pattern on the startup side. And um, uh, uh, and you know we'll see, we'll see which spaces specifically in there, you know, kind of play out or maybe the only other thing is, is the other kind of relationship to that is where are things that people could never have done. So even if you had hired enough people it just wouldn't have been possible. I'm sure that, that you know, kind of Player zero is doing this but like the idea of like you know, you can't throw enough bodies at ah, at sre work for the one weird remote event that happens that takes down your site. So I, I, I, I tend to like those spaces which is like let's use AI as this new form of abundance. Uh to I'm a little bit less excited by like let's just replace the ten person team and make that uh, a seven person team.
Speaker B: Uh, Aaron, I want to sort of maybe transition a little bit to talking about some of the things you're doing at Box. I mean you're clearly a very successful incumbent and at the same time I think have been very open about the fact that you're reinventing the company. Uh, in this new universe, in this new AI world, are there one or two things that you know, you can share?
Speaker C: The maybe slightly snarky thing, like the thing I wanted to do uh, when you guys uh, did that post is I kind of wanted to just like quote tweet it and just be like this is what we're building at Box. I didn't want to like create a massive uh, you know, flame war with, with everybody else that also probably was, was going to quote tweet that. Um, no, I mean like we're Obsessed with the idea of context. Like, we think that like, I mean like you're going to have super intelligence in the form of a generic model and the only thing it can do to be useful for you is if you give it context. And like the only way it's going to be useful for your workflow is if it knows about your business. So like every, every single thing that was in that piece I fully agreed with. Um, and then it's just like, well, okay, like who can give the agent context? And the thing that we get excited about is a lot of that context does exist in corporate information already. Not all of it. You know, 80 to 90% of the key things that people need to know about it's, you know, it's the stuff of who do I talk to for this problem? What's the timeline on this roadmap? Um, how do I have an agent go and answer an rfp? Um, this information does exist in a lot of your unstructured data already. And so then it becomes a really big problem of how do I give the right information to the agent, um, uh, and not have it get confused by the wrong data or out of data information? Um, how does it work on the task for me effectively. So we're building out a lot of capabilities basically to solve that problem.
Speaker A: Curious how Box thinks about multimodal data, because one of the things I was thinking through isn't a lot of the data. That's m, maybe more associated with the reasoning. It's like screenshots, diagrams, video calls, recordings, conversations. Uh, but curious how you guys think about that in the new AI world.
Speaker C: Yeah, uh, I mean that data is becoming obviously vastly more valuable. Um, uh, as a result of now we can finally process it at scale. Now you can crack open that image, you can listen to an audio transcript, you can process a video, um, and then effectively that can factor into the exact same context that you have that would have been more text based data. We sort of, kind of just think about that as yet another data type. Um, and so we don't really treat it any differently than the text data. We just think of that as more unstructured data that now we can have agents understand. Um, uh, and then it's sort of up to our customer in terms of how do they want to use that for the purpose of making an agent better or for automating a workflow.
Speaker B: Makes sense. And now historically, this data inbox has never had, you know, it's never had a time component or a sequence component. How do you think that Plays out in the context of what you're doing or in the context of what you're seeing other companies do.
Speaker C: We aren't doing anything novel on that front. Uh, we actually, we have all of that data as exhaust from the system. So any customer could leverage that information, um, effectively using our APIs. So that would be if any context graph agent company out there wants to use that data, by all means, um, we'll pump that to you and then you can learn from whatever that workflow is. Um, um, I think to me the jury's a little out as to how often you will, will sort of for what use cases. You will sort of systematically look at that data versus which use cases. Do you want somebody to just like take an hour out of their day and really just write out the kind of like really best practice for this thing? I think certainly for like responding to system incidents across, you know, a, uh, trillion events on your platform, you're going to be looking at system data and you're going to be relying on that, I think for uh, a best practice on how you do, um, discounting in different industries. I still think there's a little bit of a human in the loop element where you want somebody to apply some judgment to say, yeah, this is actually kind of what we do. In which case that just might end up as a markdown file and it just might be in some folder that an agent has access to. And that's helping you in kind of your workflow as opposed to it sort of relying on every other event that's ever happened across all time longitudinally. Uh, I think different workflows will have different kind of patterns of behavior of what kind of data that informs the agent.
Speaker B: Uh, Aaron, we're sort of running into sort of our time constraints. I'm going to do two or three very quick lightning round questions. What is the one assumption about the future of software that you feel the most certain about? Um, at a time when everything's changing,
Speaker C: uh, the thing I feel most certain about is um, the kind of power law dynamics of software, uh, don't change as a result of vibe coding. You will have um, very kind of classic market share, uh, dynamics in every category of software to the end of time. The top player in the space will be 70% of the market. The second player will be 20%, the third player will be 6%, the fourth player will be 2% and so on. The idea that you kind of take an average enterprise in the same industry and you ask them what's their HR system or ERP system or CRM system or email provider. And they're going to say that we built it ourselves or we're all using different vendors because now there's 100 times more vendors that vibe coded them. I don't believe, I don't believe in that outcome. It's a misunderstanding of why companies buy software, um, and where the real kind of cost of running software actually is. Um, you know, it certainly is in the development of software today, but actually it's in the running of it, it's in the maintaining of it, it's in
Speaker B: the, it's in the trading people to use it. It's the extent to which you can rely on it. Absolutely spot on.
Speaker C: So those things don't go away.
Speaker A: Yeah.
Speaker B: So the next, moving on to the next question. Context graphs is definitely a trend that you've been watching very closely and fortunately for us, participating in very actively. What, uh, is the other major thematic trend that you're watching most closely?
Speaker C: Gosh, I would say the context stuff is taking 90% of uh, my headspace at the moment. Uh, because I really do think about, uh, the future of agents as effectively a race to, who can provide them with the best context. And so, so like, I think that will be the defining characteristic of the winners and losers of AI over the next decade.
Speaker B: Sounds like context graphs is going to be the most important thing in your life in 2026.
Speaker C: So I think it will be. Uh, and um, you know, the sister to context graphs is context length and like, you know, context rot. And can we sort of make sure that the model can actually make use of all the context that we're giving it versus, versus? It's sort of not able to execute on that data. Um, but yeah, these are things that I'm thinking about.
Speaker B: Last question. What is the advice you would give to a founder who's starting a new company today?
Speaker C: You know, probably back to where I would bet on the opportunities. I would actually go after spaces that um, are not sort of the AI version of the incumbent. Uh, I would, I would do the, I would do an AI products where there's no incumbent. Uh, go after, go after categories where there just was no good software because it wasn't a real software market before. It was just things that we did as people manually. And now agents can do them for the first time and then sell them to the people doing them manually. And, and the people that were doing them manual manually will get a 10x greater output. That sort of pattern I think will work for hundreds of markets, uh, over the next few years.
Speaker B: Thank you so much, Aaron, for joining us today.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.