Case study · B2B SaaS · 8 → 200 employees

25x headcount growth, zero net-new IT

A SaaS startup scaled from eight founders to two hundred people across four countries — without hiring a network administrator or maintaining a single VPN appliance.

Vertex Systems — team scaling along a growth curve

Onboarding used to take days

At forty people, every new hire meant a ticket: VPN credentials issued by hand, three cloud consoles allowlisted one by one, contractors handed keys broader than the job. The panel below is the access workflow Vertex retired — and what replaced it.

  • ✓Day-one access with SSO, no ticket in sight
  • ✓Contractors scoped to one service, expiring weekly
  • ✓CI runners join and vanish as ephemeral nodes
new-hire access — retired vs replaced
vpn accountticket + manual setup3 daysRETIRED
cloud allowlistsper-console hand edits2 daysRETIRED
contractor keysshared, never rotated90+ daysRETIRED
sso loginone identity everywhere4 minLIVE
policy filereviewed like code15 linesLIVE

The policy file passes due diligence

"Who can touch production?" used to have a dozen answers across consoles and wikis. At Vertex it has one: a fifteen-line file the founders review in pull requests. Investor diligence sessions went from an afternoon of screen-sharing to a single file read aloud.

# vertex's entire production access story
group "eng" → staging:443, ci-registry
group "oncall" → prod-ssh:22, prod-db:5432
group "founders" → break-glass, expires 1h
tag "contractor" → one service, expires weekly
 
# reviewed in PRs. that's the whole file.

The challenge

Vertex's product lives in three clouds; the people building it live everywhere. At eight employees, a shared OpenVPN server was tolerable. At forty, it was a liability: new hires waited days for credentials, contractors got over-broad access, and every cloud console needed its own allowlist maintained by hand.

The switch

They adopted OpenVLAN on the free plan at ten people and never outgrew the workflow — only the plan. Onboarding became "log in with SSO and install the client"; staging and production access became tags in a policy file the founders review like code. When the team crossed the free tier's seat count, upgrading was a billing change, not an architecture change.

The results

From 8 to 200 people, the total human effort devoted to network administration stayed roughly flat — near zero. New hires get full access on day one without filing a ticket. And the "who can touch production" question has a one-file answer that passes investor due-diligence in minutes.

25x

headcount growth without dedicated network IT

Day 1

full-access onboarding for every new hire

3

clouds behind one flat, private network

"We grew twenty-five times, and the network never asked for a headcount of its own."
— Co-founder, Vertex Systems

What's next

Vertex is piloting AI-workload policies to control which model providers their training clusters may reach — one more block in the same policy file.

This case study is an illustrative example with fictional data for demonstration purposes.

Vertex FAQs

When did they outgrow the free plan?
Around 25 seats, when SSO became a requirement rather than a nicety. The upgrade was a billing change — the workflow, the policy file, and every device stayed exactly as it was. That's the point of starting on the free tier: you never migrate anything.
How do contractors get access?
They're tagged, scoped to the one service they're hired for, and the access expires weekly unless renewed. Nobody remembers to revoke anything — expiry does the remembering.
What does day-one access look like in practice?
Log in with SSO, the MDM already pushed the client, and the new hire's group grants staging by default. Four minutes from laptop to connected. No ticket, no waiting, no "temporary" shared credentials.
Who reviews the policy file?
The founders — in pull requests, like code. Fifteen lines currently. The diff shows up in code review, so a permission change gets the same scrutiny as a schema change.
Did 25x growth change the network at all?
Device count grew; architecture didn't. Adding the two-hundredth laptop looks identical to adding the ninth. The only thing that changed at scale was the plan tier and the length of the audit log.

Grow the network, not the network team