A couple of weeks ago ServiceTitan rewrote its Terms of Use to restrict automated and AI-agent access. If you've never touched ServiceTitan, think of it as the AppFolio of the trades: the system of record for plumbing, HVAC, and electrical companies. Same shape of business, same dependency on one platform, same vendor ecosystem hanging off the side of it.
Rich Jordan flagged the change on X and called it the opening round of a 2026 fight between legacy SaaS and AI agent usage. I think that's about right, and I'd read the new language as a preview of where your own software is heading.

What Actually Changed
Start with the definition, because it's doing most of the work here. ServiceTitan defines "AI Agent" about as broadly as you can: AI agents, autonomous agents, browser agents, RPA, bots, scrapers. If it logs in and clicks around on your behalf, it's covered.
The changelog language is worth sitting with too. ServiceTitan's technology now has to be accessed directly by authorized natural persons. Natural persons. That's the whole philosophical position in two words.
Since this is a document where the exact wording is the story, be precise about what follows. Agents aren't outlawed. What's flatly prohibited is the set of practices people currently use to hand an agent the keys:
- Sharing credentials with any third party, AI Agents included.
- Configuring your account in a way that enables that kind of access.
- Working around security measures.
- Using these tools to pull data on a customer's behalf.
Their API Terms close the other side of it, requiring that any AI system stay inside a scope that has been defined, disclosed, and approved up front.
Read that list again and notice who some of it is aimed at. "Configuring your account to enable such access" is a rule for the customer. The person who hands out a login is now the one breaking terms, and that's a meaningful shift from how a lot of us have quietly operated for years.
ServiceTitan's Answer
To their credit, CEO Ara Mahdessian jumped straight into the thread rather than letting it spiral.
His clarification: this is not a "no AI, no agents" position, agentic workflows aren't being restricted generally, and the update targets unauthorized access specifically. Customers who already have first-party, third-party, and custom agents connected keep their API access unchanged, and he says ServiceTitan is continuing to invest in the APIs.
The rest of his reply is the part I'd pay attention to, because it's the actual product argument. Customers run mission-critical operations on ServiceTitan. Agents can be misused about as easily as they can be deployed well. So customers want to know which agents have access, control permissions agent by agent, audit what each one reads and writes, and make sure an employee can't hand a company's data to an unvetted bot on a Tuesday afternoon.
I take him at his word on intent, and if I ran a system of record I'd want the same controls. Two things are true at once here. Those guardrails are real and customers genuinely want them. They're also the mechanism that decides who gets to build on top of the platform, and that decision has a cost that lands on somebody.

Podium Shows What That Cost Looks Like
Terms of Use updates get published constantly and nobody notices. This one came with a demonstration.
ServiceTitan ended its long-running integration with Podium, citing Marketplace standards, and gave the roughly 1,000 shared customers about 30 days. In peak season. Podium's CEO said they were blindsided. ServiceTitan's position is that it declined certification.
Set aside who's right. The operators in the middle are re-plumbing a piece of their customer communication stack in 30 days, at the worst possible time of year, over a certification dispute they had no part in and no visibility into. Whatever the merits, that's the bill for a decision made two levels above them.
This Isn't a One-Off
ServiceTitan's help docs already list a graveyard of integrations that are no longer supported, including HubSpot, Customer Lobby, FleetComplete, and Review Inc. The App Marketplace now leans hard on certified apps, and "tunneling," where a third party uses a customer's App Keys, is explicitly out.
Put the pieces together and the direction is obvious. Access moves from relatively open partner connections to controlled, auditable pathways that ServiceTitan can see, approve, and revoke. Meanwhile they're accelerating their own agentic tooling.
The strategy is coherent. If agents are going to sit on top of the system of record and do the work, the company that owns the system of record would rather own that layer than rent it out.
The Property Management Version Is Already Running
Everything above should feel familiar, because AppFolio is running the same play.
They're building their own agentic layer with Realm-X Performers while keeping API access controlled and charging on both sides of it, customers and vendors alike. Vendors get pushed toward the Stack marketplace, which is not cheap, and AppFolio is selective about who's allowed in.
The logic is identical to ServiceTitan's. These platforms hold the trust accounting, the lease data, the resident records, the owner disbursements. They're mission-critical systems of record. As agents get better at operating software autonomously, the platforms are choosing security, auditability, and a cut of the agent layer over being an open pipe anyone can attach a bot to.
There's a loop here worth naming. Gated or expensive API access doesn't kill demand for the data, it reroutes it. Integrators who can't get a sanctioned connection go find an unsanctioned one, which produces exactly the credential-sharing patterns ServiceTitan's new language now names. Which is, more or less, the risk Mahdessian says the update exists to mitigate. Everybody is responding rationally to everybody else and the customer is still the one holding the bag.
The Open Secret
So what happens with vendors who aren't on the Stack marketplace, either because they weren't invited or haven't paid to be there?
You know the answer. The customer spins up a login for the vendor to use. Or sets up scheduled report exports. Or both. This is how a large share of the PM tech ecosystem actually functions day to day.
And it works great, right up until it doesn't. Big updates on the Beagle vs. AppFolio lawsuit are coming soon, so stay tuned on that one.
The practical read for operators: any workflow that depends on a shared login or a scraped export is running on a policy that can change with a terms update and 30 days of notice. It might survive for years. It might not survive the next release. Price that risk before you build anything important on top of it.
Why This Is the Whole Ballgame
Back to ServiceTitan. Gokul Rajaram's read on the Podium cutoff is the sharpest thing I've seen on this, and it generalizes cleanly to our industry.
His argument, roughly: the system of record holds the data and the workflows, migration takes months, and that switching cost was the entire moat. It held for fifteen years because there was nowhere better to go.
AI-native companies get in through the integration. They read data out first. Then they start doing the work the system of record only ever recorded, like booking the job, answering the customer, chasing the estimate. The techs and CSRs spend their day in the new surface and the old system quietly becomes an expensive database.
The incumbent spots it in the API logs before anyone else does, and then has two options. Rebuild a fifteen-year-old architecture around agents that do the work, which takes years. Or revoke access, which takes an afternoon.
Then he lands it: "Partner API terms are a strategy document." When an incumbent narrows access to a category, it's telling you which product it doesn't think it can out-build.
Go read your PM software's API terms and marketplace rules with that lens on. The categories they're tightening are the categories they intend to own.

Further Reading
This is not a property management story or a home services story. It's what happens in every vertical once the system of record realizes the agent layer is where the next round of value gets captured.
Luke Sophinos has a diagram of the business owner's software journey that maps the whole progression in five steps: system of record alone, then point solutions layered on top, then business intelligence, then integration-as-a-service wedged in between, and finally vertical AI sitting on top of all of it. The system of record never disappears. It just keeps sinking further down the stack, further from the person actually doing the work.

Brendan Keeler wrote a manifesto on systems of record from the healthcare side, and it's one of the best things I've read all year. If you want to understand the forces at work in our industry, how the players are positioning, and where all of this is heading, get comfortable and dig in.
-Peter