MuninMunin
Sign inStart free
Home/Journal/We let you leave. That's why you'll stay.
Essay · 7 min read

We let you leave. That's why you'll stay.

We built Munin in a month and gave the code away under MIT. Not as charity — as the business model. A field note on why, when software stops being scarce, the only moat left is being trusted to operate it.

A woman stands in an open doorway of a warm, lamp-lit room, looking out at a sunlit path winding through rolling hills.
A door only counts if it opens outward too.

In the last note I argued that apps were for clicking and Munin isn't — that once the cheapest operator in the system stops being a person, the UI stops being the product. This note is the commercial half of that argument: if the software isn't the product, what is? It's the half founders usually keep quiet about. I'd rather say it out loud.

So, plainly: we built the whole of Munin — knowledge, conversations, CRM, content, outreach, analytics, the lot — in roughly a month, and we licensed it MIT. The repo is public. You can clone it tonight, read every line, and have it running on your own metal by the weekend. We are not worried about that. We did it on purpose. The month was never the moat, and we'd rather be the ones to say so.

Why would a company give away the code under MIT?

Because the code stopped being the scarce thing. A small team with agentic tooling built all six Munin modules in about a month, which means a competent competitor can reproduce the artifact. What cannot be reproduced on that timescale is being trusted to operate it — EU residency, consent state, an audit log that survives a bad night, and somebody answerable at three in the morning.

I want to be precise about what "a month" does and doesn't mean, because the figure invites the wrong reaction in both directions.

It doesn't mean the work was trivial. It means the production of software has gotten radically cheaper, and a small team with good taste and agentic tooling can now ship in weeks what used to take a funded company a year. That is not a moat. It's the weather. Everyone is building in this climate now, whether they've noticed or not.

And it doesn't mean the result is a demo. The part that took the actual care isn't the part you'd time with a stopwatch — it's the apps sharing one Postgres with row-level security carrying the tenant boundary, the consent state that decides what an agent is allowed to surface, the audit log that survives a bad night, the EU-hosting posture, the on-call rotation behind it. The build was fast. The operating is not, and was never meant to be.

That gap — cheap to build, expensive to run well — is the whole essay. If a competent team can reproduce the code in a month, the code cannot be the thing you're paying for. Something else has to be. The interesting question is what.

How hard is it to leave Munin?

It is a sequence of tool calls, not a migration quarter. Every module exposes a matched pair — an export that hands you its data and an import that takes it back — across knowledge, conversations, CRM, content, outreach, and analytics. Because those are MCP tools rather than buttons welded to a UI, an agent can walk all six and move the whole tenant while you watch.

Most software companies treat the exit as a thing to make quietly impossible. The data lives in a proprietary store. The export is a CSV with half the fields missing. The integrations are a one-way street in. You don't leave, because leaving is a project, and the project never makes it onto anyone's quarter.

We went the other way. I want to be concrete about it, because a promise of portability that stays abstract is just a slogan.

The code is MIT. No open-core bait-and-switch, no "community edition" with the useful parts filed off — a pattern common enough across this category that the licence is the first thing worth checking. The thing we run is the thing in the repo.

And because they're tools behind the MCP protocol, an agent can walk all of them for you. Point it at your Munin instance and a fresh one you've stood up yourself; it reads each module out of the old and writes it into the new, the whole tenant moving across while you watch. No CSV with half the fields missing. No migration quarter. The exit is an agent run — the same shape as everything else Munin does.

We point you at the door rather than stand in front of it.

That should, by the conventional logic of this industry, be a terrible idea. It is the opposite of lock-in, and lock-in is supposed to be the business.

It is also the only claim in this category that costs the vendor something to make, which is exactly what makes it worth anything. Every competitor can write no lock-in on a pricing page. Very few can hand you the tool that performs it. A promise you are able to verify by leaving is a different kind of promise from one you have to take on faith, and the difference is the entire product.

If the software is free, what are you actually paying for?

The operation. Three things specifically: data residency and the security posture that keeps it true, an accountable party with an audit trail when an agent does something it shouldn't, and continuity — uptime, upgrades, the migration that doesn't lose a row, and the human who picks up at an unsociable hour. None of those live in the source code.

The same things that survive the undoing, it turns out, are the things you bill for. In the last note I said the parts that survive an agentic world are the unglamorous ones: the data model, the identity layer, the audit log, the consent state, the place where humans approve things. That list wasn't just an architecture diagram. It's a price list.

You're not paying us for the software. You're paying us to operate it — and operating is where all the scarce things live:

  • 01Residency and posture. The data sits in the EU, under a security and compliance stance that's real work to maintain and real liability to get wrong. Most teams would rather rent that than own it.
  • 02The accountable party. When an agent does something it shouldn't — surfaces a record it had no business surfacing, sends the wrong thing to the wrong person — someone has to be the legible, answerable party, with the audit trail to reconstruct what happened. That's a role, not a feature. It doesn't come from the source code.
  • 03Continuity. Uptime, upgrades, the migration that doesn't lose a row, the on-call human at the unsociable hour. The repo doesn't page anyone at 03:00. We do.

None of these are things you can fork. You can copy the code in an afternoon. You cannot copy being trusted to run it, because trust isn't in the artifact — it's in the operation, accrued over time, and it's the one thing that doesn't get cheaper as the tooling improves.

Which is why the number on the invoice is for the operation and not the software. Self-hosting is free, forever, and we mean it: MIT, whole repo, no feature withheld. Munin Cloud has a free tier today, and its paid pricing is flat per organisation rather than per seat.

That last part isn't a discount, it's the same argument in another costume. Per-seat pricing assumes the seat is where the work happens. If most of the operators in your system are agents, billing by the number of humans logged in is a unit of measurement that has stopped describing anything. We'd rather charge for the thing we actually do.

This isn't a new shape, exactly. Red Hat sold an operating system nobody could own, and built a serious company on support, assurance, and being the throat to choke. What's new is that the cost of building fell far enough that this stops being a story only about giant infrastructure projects and becomes available to ordinary business software — the CRM, the helpdesk, the modules that touch the customer record.

Doesn't giving the code away destroy the moat?

It replaces one moat with a sturdier one. Lock-in worked because leaving hurt, which is a hold that lasts exactly until a customer decides the pain is worth it. Portability works in the other direction: people hand the live operation of their customer relationship to a vendor they could walk away from, and choose again every month not to.

Here's the inversion the whole bet rests on. The open door isn't a concession we make despite wanting you to stay. It's the reason you'll stay.

Lock-in was the old moat: you stayed because leaving was too painful to attempt. It worked right up until it didn't — and it turned the last decade of SaaS into one long syncing project, a tax everyone paid and no one wanted. Portability is the new moat, and it works in reverse. You let people leave freely, and the freedom is exactly what makes them comfortable handing you the thing that matters most: the live operation of their customer relationship. Nobody hands an irreversible decision to a vendor they can't escape. They hand it to the one they could leave at any time and choose, every month, not to.

You stay because you could go. Take the door away and you've taken the trust with it.

What is Munin actually betting on?

That the operation outlasts the artifact. Producing software got cheap enough that the code stopped being the scarce thing, so Munin gives the code away under MIT and charges for what stays scarce: EU residency, consent state, an audit log, an accountable party, and a person who answers at three in the morning. None of that can be cloned from a repository.

So the bet is plainly this. Software has become a commodity in the only sense that matters commercially: the artifact is no longer the scarce thing, and pretending otherwise is a strategy with an expiry date. What stays scarce is the operation — the residency, the consent, the audit, the accountability, the person who answers when it breaks. We open-sourced the code because the code was never going to be the moat, and we'd rather build on the part that lasts than defend the part that doesn't.

Frequently asked questions

Is Munin actually MIT licensed, or is it open core? MIT throughout, with no enterprise/ or ee/ directory. The code running Munin Cloud is the code in the public repository, and no module or feature is withheld from self-hosters. The practical test for any project making this claim is to open the repo and look for a separately licensed directory before you believe the badge on the front page.

How do I export my data out of Munin? Every module ships a matched export/import pair as MCP tools — CRM, conversations, knowledge base, CMS, outreach, and analytics. An agent can run the whole sequence against your instance and a fresh one you control, in foreign-key order, without anybody hand-editing a CSV. Nothing about leaving requires our cooperation or a support ticket.

What does MIT mean for my business, compared to AGPL? MIT lets you fork, modify, self-host, and resell without publishing your changes. AGPL is copyleft: if you modify the code and offer it to third parties as a hosted service, you can be obliged to publish those modifications. For purely internal use the difference is small; if you plan to build a product on top, it decides what you are allowed to build.

If the software is free, how does Munin make money? By operating it. Munin Cloud is EU-hosted and free to start, and its paid pricing is flat per organisation rather than per seat. You pay for residency, the accountable party with an audit trail, and continuity: upgrades, uptime, and someone on call. Self-hosting remains free forever.

Is open-source software safe to run a customer database on? The licence is not the safety property; the architecture and the operator are. What open source changes is that you can read the row-level security policies, the consent handling, and the audit logging rather than take a datasheet's word for them — and you can keep running the software if the vendor's plans change.

Can I self-host Munin and move to Munin Cloud later, or the other way round? Yes, in both directions, using the same export/import tools. Because Cloud runs the same MIT code as the repo, moving is a data migration rather than a re-platforming, and the tool calls are identical whichever way you are going.

The argument, condensed

  • The artifact stopped being scarce — a small team with agentic tooling built all six modules in about a month. The moat was always going to be the operating, not the code.
  • Munin is MIT throughout — whole repo, no withheld features, no enterprise directory. The code we run in Cloud is the code you can clone.
  • Every module ships a matched export and import pair as MCP tools, so leaving is an agent run rather than a migration quarter.
  • What you pay for is the operation: EU residency, an accountable party with an audit trail, and continuity at three in the morning. None of it forks.
  • Portability is the moat. People hand the live operation of their customer relationship to a vendor they could leave, and choose again each month not to.

Clone it tonight if you'd rather read the code than the argument — the repo is MIT on GitHub, and Munin Cloud is free to start on if you'd rather we did the operating.

We let you leave. That's why you'll stay.

Kjell Rune Monsø, founder.