Bottom-up adoption: Scattered signups into one company deal
Somewhere in a company you have never spoken to, eleven people are using your product on personal accounts and expensing it individually. Nobody in IT knows. Nobody in procurement knows. Your own CRM has eleven unconnected records with the same email domain.
That is not a leak in the funnel. It is the funnel. Any product that can be adopted without permission accumulates some quantity of this, and what separates the companies that convert it from the ones that do not is usually whether an administrator inside that company can discover it without your help.
What is bottom-up adoption?
Bottom-up adoption is a go-to-market motion in which individual users adopt a product on their own authority, then pull their team and eventually their organization behind them. The alternative, top-down, starts with an executive decision and pushes adoption downward.
Two conditions have to hold at once, and products fail this pattern by missing either:
Someone must get real value without asking permission. Usually that is one person. It does not have to be: for some products the smallest unit that gets value is a small team, and bottom-up still works if a team can adopt on its own authority without going through procurement. What breaks the pattern is not needing colleagues, it is needing an approval. Know which unit is yours, because it determines what the first experience has to accomplish.
The value must increase with other people. If it does not, you have a solo tool that spreads one user at a time through word of mouth, which is a slower and much less defensible business.
Figma shows what the second condition buys you when it holds: by the time it filed to go public, the people who came second outnumbered the designers the product was built for.1
What produced that is not disclosed in any filing, and our reading is that the decisive design choice was gating participation rather than access, so that looking at a shared file is free and commenting on it needs an account. That mechanism is covered in more detail alongside network effects; the point here is what it did to the user mix.
Where the spread actually comes from
The design question this pattern turns on is at what moment does an individual naturally need a colleague? Sharing for review, handing something over, needing a decision, needing data somebody else holds. Find that moment, then make inviting someone the easiest thing available at it. Burying invitations in a settings page is how adoption stops spreading.
Not all spread runs through invitations either. A team that visibly ships faster gets asked what they are using, and that question is the cheapest acquisition in the pattern. It requires only that the results are legible from outside the team, which is a product property rather than a growth tactic: results that leave the tool, work other people can see, work that shows up in somebody else’s week.
The ceiling is the moment permission is required
Adopting without permission works right up until permission becomes mandatory, and then everything changes at once.
The trigger is usually not a purchase. It is a security review, a compliance audit, a new CISO, an insurance requirement, or somebody noticing an unapproved tool holding customer data. At that point your product stops being evaluated on whether people like it and starts being evaluated on whether it can be sanctioned.
Companies meet this boundary in one of two states. Either the answers exist (SSO, audit logs, a data-processing agreement, a completed security questionnaire, someone to sign it) and the review is an administrative step. Or they do not, and enthusiastic adoption by dozens of employees converts into a mandate to stop using you, which is the most expensive way to learn what enterprise readiness means.
Let the admin find you
Here is a move that is cheap to build, rarely built, and worth more than most of the roadmap around it.
An administrator at a company with scattered adoption has a question you can answer trivially and nobody else can: who here is already using this? Give them a way to verify their domain and see it. The list of accounts, the teams, the usage, and an offer to consolidate the lot into one billed organization with the settings they need.
This does several things at once. It converts invisible individual spend into a single contract. It hands your champion the evidence they needed anyway. It gets you in front of the exact person who would otherwise be the obstacle, at a moment when they are not yet annoyed. And it reframes you from shadow IT to be eliminated into adoption to be formalized, which is a completely different conversation.
The mechanics matter. Domain verification has to be self-serve, the discovery has to work before anyone talks to sales, and consolidating must not disrupt anybody’s existing work. An admin who has to email you to find out what is happening in their own company will conclude the safest action is a ban.
Where permission cannot be skipped
| The condition | Adoption spreads | It stops at one desk |
|---|---|---|
| Unaided start | A person or small team can start on their own authority | Nothing happens without an approval |
| Collaboration upside | Value grows as colleagues join | Purely individual, forever |
| Data sensitivity | An individual can legitimately start | Regulated data makes unapproved use impossible |
| Price point | A person can start on a card, or free | Every start requires a procurement cycle |
Data sensitivity is a hard stop, not a matter of degree. Where regulation governs the data (health records under HIPAA, financial data, anything touching a government compliance regime), an individual putting real records into an unapproved tool is not a growth loop, it is a reportable problem for their employer. Those markets are reachable, but the motion is top-down and the product needs the compliance answers before the first user, not after the fiftieth.
What the rest of this section stands on
Everything that follows in Expand assumes this motion is working. Freemium assumes someone can start without asking. Upgrade triggers assume the person who hits a limit is near somebody who can pay. Land and expand assumes there is already a champion inside the account.
The test for bottom-up adoption is one question: could somebody at a target company start using your product today, on their own authority, without talking to anyone? If not, freemium, upgrade triggers and land-and-expand all describe a business you do not have yet.
Four questions your own database already answers
None of these needs a survey, a vendor or a quarter. Every one is a query against data you are already storing.
- How many accounts share an email domain but no billing relationship? For a bottom-up company this query is often where the pipeline already is.
- What share of new users were invited by an existing user, rather than arriving cold? This is the bottom-up engine’s actual output. Flat or falling means you are acquiring individuals and not spreading inside companies.
- How long from first individual signup in a domain to a paid team in that domain? Then look at the accounts where it never happened and find what stalled: often a missing admin capability rather than a pricing objection.
- How often does a security review appear in a lost deal? If the answer is “we do not track that,” you are almost certainly losing deals you believe you lost on price.
Seven moves, in the order they pay off
- Run the shared-domain query today. It takes minutes and it will change what you build next.
- Build domain discovery for admins, self-serve, before you build anything else on this list. The cheaper half is at signup: Elena Verna describes Miro nudging a new user whose email domain already belonged to a team to join that team instead of starting alone.2 The product knows; it just has to say so.
- Publish the security answers so a reviewer can find them without contacting you.
- Check an individual can genuinely start alone, by doing it, on a personal email, without any internal shortcut.
- Instrument invite-driven signups separately from cold ones, because they are different businesses sharing a funnel.
- Find the users who have invited five or more colleagues. They are doing your selling, usually without being asked and without being noticed. Interview them, support them, and give them better material.
- Ask your last three lost deals whether a review was involved. Track the answer permanently.
Adoption without permission gets people in the door. What they pay once inside is decided somewhere else entirely, by the first choice every product-led company makes and most make by accident: what somebody gets for nothing, and where that stops. Freemium is where the money starts, and it costs more than the infrastructure bill.
Footnotes
-
Figma’s 2025 Form S-1 reports that approximately two thirds of its monthly active users are not designers. Note the unit: monthly, not weekly, active users; this handbook has previously published the weekly version by mistake. The filing supports the user-mix figure and nothing else quoted here. Any explanation of why the mix came out that way, including the participation-gating account above, is our reading and is marked as such in the body. Company user, revenue and valuation totals frequently attached to this pattern for Notion and Slack come from secondary coverage rather than filings and are not used. ↩
-
Elena Verna, “Hey B2B, I bet you are measuring activation wrong,” 5 October 2023, describing mechanisms she ran at Miro. Her account rather than a company disclosure. ↩