SOFIA Killed BOB and Replaced POE with a Black Box Agent …

What’s the real future of Procurement Tech?

Twenty (20) Years Ago, we asked What about BoB? when the debate in ProcureTech between BOB (Best-of-Breed) vs. POE (Platform Oriented Enterprise) was getting drowned out by the emerging suite players.

Did you go out and assemble your own suite of best-of-breed modules to suit your needs, and then pay the consultancy integrators big bucks to integrate them, or simplify your life, settle for a 60% to 80% solution and buy a suite that gave you an all-in-one solution (and bypassed difficult and expensive integration requirements) that was hopefully strongest where your core needs were?

It was a valid hot debate because most suites were centred on one (or two) strong modules that the firm was founded on, with the other modules either hastily built to what the firm considered an MVP so that they could sell a (mini) suite or acquired (and partially integrated) so they could have a suite, even though some of the modules were loosely connected (and sometimes even built on entirely different UX philosophies with noticeably different user interfaces).

Furthermore, twenty years ago, the bigger the suite was, the worse or more disconnected part of the suite was. In the beginning, most vendors started as e-Sourcing or e-Procurement and mini S2C and P2P suites were built up around those modules, respectively. S2P suites were usually built by one mini-suite vendor acquiring another (or, in rare cases, a CLM or SXM vendor realizing they needed both and getting the help of an investment firm). You had frankensuites built from three (3) primary solutions (and, in some cases, fattened up by additional acquisitions over time), which felt as disconnected as they were to use. However, the one-vendor-throat-to-choke and one-implementation-team comforted the C-suite and those purchases were easier than trying to get permission to acquire a bunch of best-of-breed solutions and then write a big cheque to an integration consultancy that you hope can get the solutions to all work together, at least until major solution upgrades, in which case the consultancy will have to come back and upgrade the integration.

Then orchestration came along and SOFIA (Solution Orchestration Framework Integration Architecture) was supposed to settle the debate once and for all. With modern orchestration solutions, you were supposed to be able to bring your own best-of-breeds, integrate them all with modern orchestration, and either use their native intake, or bring your own, to open up their solutions to everyone who needs access. That was the theory. The practical reality is different.

I’m not sure if it’s still the case, but for years, neither you nor your consulting and integration partners could integrate your own solutions with Zip — Zip had to do it internally because it was too complicated and needed to be done a specific way. Oro, first designed to make Ariba usable and then to make other major last-generation suite solutions usable, provided you with a similar situation — partner solutions are pre-integrated and easy to onboard, other solutions took time. Then there’s Tonkean, now part of Coupa, that could integrate anything if they did it and you gave them the time to do it. Time being the key word. (They were essentially assembling an application for you … no quick out-of-the-box configuration!)

None work(ed) out of the box, and there’s two reasons for that.

The first is that you can’t quickly MVP generic orchestration solutions that are flexible, powerful, easy to use and work with today’s SaaS — the Enterprise has to be carefully thought out and designed and the coding talent needed is not the script-kiddie drop out talent that many (AI-first) firms are employing.

The second is that most platforms, frankly, weren’t even built for integration, which means that they definitely weren’t built for orchestration. Modern orchestration requires more than the ability to push some data in, and pull some data out. First of all, it requires the ability to push all data in and pull all data out. Secondly, it requires the ability to programmatically trigger and execute functions and workflows from external sources. Most platforms don’t support that (well). As a result, orchestration platforms don’t work. If the platform doesn’t have, and completely expose, its API (through secure channels to apps with appropriate security credentials), orchestration is not truly possible.

As a result, most of the big orchestration providers are trying to use AI-first tools (and vibe coding, which, as we’ve made clear many times, only produces vibes that are please to the smug sniffing coders who use it, not good code) to quickly code their own S2P apps and modules, and essentially reverting to a POE (2.0) solution — internalizing their orchestration solution as a platform oriented enterprise to build a next-gen classical suite solution. (Oxymoron intended!)

But is that the future? (Hopefully not!)

Remember When The Worst We Had To Worry About Was The Patent Pirates?


Those were the good old days
Those were the good old days
The years go by, but the memory stays
And those were the good old days

Good Old Days, Weird Al Yankovic, 1988

Twenty years ago, echoing the great Dave Stephens of Procurement Central fame, we cried about the software patent pirates plundering away your hard earned revenue as they scooped up patents from failing enterprises (or enterprises not willing to enforce them) for pennies on the filing dollar, and then sued any decently sized company that was offering software that sounded like it was covered by one of the patents in their hold, threatening to bankrupt the company with an expensive lawsuit that would be dragged out endlessly if the threatened company didn’t pay a patent licensing fee for a totally bogus patent claim. It worked well, until they got greedy and went after bigger fish who fought back and made it costly for them to make bogus claims.

When that was the worst corporate theft we had to worry about, in hindsight, it really wasn’t that bad.

Considering that today the Big AI players are stealing all of your copyrighted and corporate data and using it to train their systems in the best case, then using those trained systems to output similar derivative works for their profit in the average case, and allowing shareholders and foreign governments to access it in the worst case, the patent pirates don’t sound so bad — you had to have similar software for them to even consider targeting you!

The posts on your private sites, the published articles in major publications, and the books that took you years to write are being sucked into these LLMs without a penny of royalty to you or your publisher. If you’re an artist, they’re stealing your entire catalog from Youtube, Spotify, etc. to train their music generator app to output music that sounds like you (just with worse lyrics, off tones, and no heart or soul), and if you’re a corporate enterprise — everything on your website, in your emails, and in your private meeting notes for meetings you send your AI assistants to for note-taking purposes. Once they speech-to-text those meetings, all of the output is fed into the LLM training archive for “future improvement” before it is summarized and fed back to you.

Now, if that AI platform is owned by a company based in the USA, it doesn’t matter if the instance you’re using in the EU is hosted in the EU — US law gives them the right to access all your data at any time. And if you’re an American accessing DeepSeek … all that data is passing though Chinese government servers!

So not only are they using your information without your consent and without compensation, since the majority of the big players are in the US, they are using it without any repercussions as the US Federal Government put a 10-year moratorium on AI legislation, basically allowing these companies to steal all your data without consequence for the next decade! Because, even if they say it’s “just for training”, we all know that training data leaks out of LLMs with the right prompts in the right circumstance. There is no safe “just for training” instance, so if the data is your copyright, they’re giving it away for free. And if the data is your trade secret, its a trade secret no more!

And there’s nothing we can do! Our only hope is for every major publishing house and media company that does business in every country outside of the USA and China with copyright and IP protection legislation to launch lawsuits in those countries against these global AI companies that are stealing their IP and copyright and serving it up outside the US. Force them to defend hundreds of suits across the global stage, while lobbying other governments to create stronger protections and mandate consent before using content, and penalties for violating the law equal to at least 10X what the fair market value of the content is. Since the market won’t bankrupt these companies that shouldn’t exist based on the fact they lose more every year than 99.9% of businesses generate in revenue, let the media industry and legal systems do it.

It’s Time For a Resurgence of Keiretsu!

Keiretsu, which can be briefly described as a long continual business relationship, in one way or another, has been a significant force in the Japanese economy for over four decades and, despite its long and varied history, criticisms, the Structural Impediments Initiative, and economic downturns, is still a strong foundation for many supply chain relationships in Japan. But now it needs to be the foundation for supply chain relationships the world over.

Twenty years ago we were in a period of (rising) globalization. Opening markets with the (first) cold war behind us. Limited, contained, conflicts. Relatively stable fuel prices. Piracy (off the Ivory Coast) was being curbed. And with the introduction of modern e-Sourcing and e-Procurement tools, it was easier by the day to invite more (and more) suppliers to events, to swap them out on a whim for (semi-)commodities, and keep supply lines fluid.

Relationships went on the decline for all but the most strategic suppliers because they weren’t necessary. But that was then, this is now.

Now we have anti-globalization and isolationism. Sanctions and closing markets. Escalating conflicts and closures of seas, straits, and critical shipping lanes. Rising and unpredictable fuel prices. A resurgence of piracy. Suppliers failing as a result of a myriad of tariffs, trade wars, border closings, shipping lanes, etc. Carriers failing as a result of rapid rising in fuel prices, insurance, increased theft, seizures, and blockades.

Suppliers who can actually fulfill your orders that you can actually receive products from that were once a dime a dozen to add to the RFP are now few and far between.

That means, now, more than anything, with risk and volatility increasing by the day, relationships matter again. Relationships that are:

  • long term: to create economic efficiencies that can help both parties survive the economic storm
  • knowledge sharing: workforce and even executives
  • business sharing: both parties buy from each other when possible and introduce throughout their partner networks
  • stock sharing: of the financial or physical variety — that reinforces each partner’s financial status when relevant or ensures security of cross-supply when stock-outs must be avoided
  • mutually beneficial asymmetrical trade: that works best for both parties

And relationships that can:

  • move low-value-add production to subsidiaries
  • ensure continuous high quality production capability to avoid excess production & consumer problems
  • improve risk management, especially with regards to variable or uncertain demand
  • ensure increased sales mean a corresponding increase for subsidiaries that are essential to the parent company’s survival
  • prevent critical confidential IP and technological information from being disclosed to short-term suppliers that may not be so obliged to keep it in the future, despite agreements

Which can help keep your supply chains running smooth in these troubled times.

What e-Sourcing Is Not – A Necessary 7-11 Update!

Twenty years ago we wrote a post on e-Sourcing Resistance and what e-Sourcing is Not. In that post, we began by referencing “The 7 Myths of e-Sourcing” by the great Tim Minahan (before he went over to the dark side), where he tried to dispel the myths.

Since the original myths still persist today, we’ll start by reminding you of those — and then address the new myths that have arose / are arising so you don’t lose the path.

Tim’s Original 7. e-Sourcing is NOT about

  • lowering prices: it is about getting the best, fair, price you can get on a product, or service that meets your needs, but not about squeezing supplier margins so thin they go out of business
  • unfairness to suppliers: it’s not about forcing out or limiting to preselected suppliers, but creating an open, level, fair playing field
  • unfairness to incumbents: it’s not about forcing incumbents out, it’s just about ensuring they also play on a fair, level, playing field
  • keeping suppliers out: it’s not about making business more difficult to win, but easier to win
  • sales cycle lengthening: it’s about making sourcing processes right-lengthed
  • supplier burdening: it’s not about adding costs, technology, or resource requirements — but minimizing the burden on the supplier
  • eliminating relationships: it’s about finding the right supplier to build a relationship with

but with the rise of technology, and, AI, in particular, a new set of myths has arisen and needs to be dispelled ASAP. E-Sourcing is NOT an excuse to:

  • turn every Procurement event into a(n) (e-)Sourcing Event: just because you can, doesn’t mean you should … most procurements should be off existing contracts, most tail-spend should be spot-buys, and when the volume/cost is enough, simple RFQs; e-Sourcing is for goods and services that are strategic or custom, not tactical or commoditized
  • use AI to draft RFPs: with AI, you can draft RFPs, and incorporate as much as you want into those RFPs, and ask as many questions about as many things as you want — this might make your life easier, but it unfairly burdens suppliers when you ask for details you don’t need (at least until you are going to seriously consider them) — plus, AI will hallucinate, ask wrong questions (and then force a follow-up request later when it’s discovered) and waste time on both sides … RFPs need to be human drafted — they should be based on templates (and assembled using non-LLM AIs), and AI should be used to judge completeness, clarity, etc — and even recommend gaps to fill in (because, when well trained, 90% accuracy can be useful), but AI should never lead
  • use AI to conduct events agentically: AI should be used to automate the tactical, but humans need to be engaged at every decision point
  • use the same process for every event: some events should be simple one-shot mini-RFPs just to verify key product/service requirements; some events should be moderate two-stage RFI/RFPs to ensure the suppliers meet mandatory organizational requirements; others deep three-stage RFI/RFP/RFQ processes to first verify suppliers, than products and services, then BAFO pricing so complete information is known before a decision is made

e-Sourcing is about right-sized efficient execution of strategic sourcing events for both sides, nothing more, nothing less.

Supply Chain Security Is Becoming More Important By The Day: Part II

Yesterday we reminded you of the benefits of supply chain security, and then noted good supply chain security has gone from a nice to have to an absolute must have.

In fact, your entire supply chain now needs to be designed with security in mind as well as risk. It’s not just lowest cost and availability of supply any more. It doesn’t matter if the supplier is lowest cost, highest quality, able to produce more than you need in the best market conditions, and guaranteed component and material supply from local distributors and mines if you can’t get the products from their factory halfway around the world to your local warehouse.

In other words, you can’t choose a supplier:

  • in a sanctioned country
  • if the only shipping routes include war zones

… without a backup (for when something inevitably goes wrong):

  • where there are active trade wars between their country and your HQ or target country
  • where the majority of shipping lanes are currently high risk (of disaster, piracy, and/or theft)
  • where the government is pursuing an isolationist agenda that could significantly impact exports
  • where the available transportation companies don’t have good security measures

Then, once you select that supplier, you need to focus on ensuring you have end-to-end security. This involves ensuring that:

  • you use suppliers with good plant security
  • … who use carriers with good security
  • … and sub-tier suppliers with good plant/mine/farm security
  • you have (near) real time GPS (cell/satelite) tracking on every vehicle
  • you have RFID tracking on every pallet
  • you ship food and drink in tamper proof packaging
  • you ship electronics or dangerous products in tamper aware packaging
  • you have documented chain of custody for every pallet from supplier factory to your warehouse
  • you have physical security for valuable goods (and especially those that are hot targets, like truckloads of iPhones)
  • … this includes the use of ocean freight carriers, that spend a lot of time in international waters, that have their own private security force to deter piracy / terrorism

Otherwise, you’ll have an insecure supply chain and it’s just a matter of time before you get blocked, seized, pirated, terrorized, or sunk.