Platform

The build or buy math for communications features

Aug 25, 2026 · 3 min read

Every build or buy debate about email and calendar features starts from the same artifact: a demo someone hacked together in a week. The demo is real. The estimate it anchors is not, because the demo skipped every part of the work that actually costs money.

The demo is not the estimate

Connecting one account and creating one event is genuinely easy. Google and Microsoft both publish decent APIs with generous docs for the happy path, and that first week convinces the room the whole feature is a quarter of work. What the demo omits is everything after the first token refresh fails, and everything a security reviewer will ask about six months later. The honest estimate starts where the demo stopped.

OAuth review is a project of its own

Shipping to real users means passing provider app review. The forms are the easy part. Sensitive scopes bring scrutiny of your privacy policy and data handling, and restricted scopes can require a recurring third-party security assessment that you pay for out of your own budget. Timelines run to weeks and sit outside your control. Treat review as a project with an owner and a calendar, not a checkbox at the end of a sprint.

It also never finishes. Adding a scope re-triggers review, and assessments recur on the provider's schedule, not yours. A policy change upstream can arrive with a compliance deadline you did not choose and cannot move.

Sync is the part you keep paying for

What you are really building is a distributed cache of other people's data, and caches need tending. Change notifications expire and must be renewed. Rate limits force queues and backoff. A historical sync of a large account takes hours and has to survive interruption halfway through. Providers return errors their own documentation does not list, and every one of them will eventually page someone on your team.

Budget the steady state, not the build. A defensible rule of thumb: whatever the integration costs to write, expect a comparable spend every year to keep it correct as provider behavior shifts underneath it.

You are now a custodian of tokens

The day the feature ships, your database holds credentials to your customers' mailboxes and calendars, and your breach blast radius stops being your own data. That changes your encryption story, your access controls, your incident response plan, and the security questionnaire attached to every enterprise deal from now on. The feature estimate includes none of it, and none of it is optional.

The opportunity cost line

The most expensive line in the ledger has no invoice on it. The two engineers who understand your sync layer are the two engineers not building the product your customers actually pay you for. And infrastructure of this kind is never finished, so the cost is not a one-time deduction. It is a standing claim on your best people, renewed every quarter whether or not you budgeted it.

When building is still right

Sometimes it is, and pretending otherwise would be dishonest. If communications is the product, own the stack; a scheduling company outsourcing scheduling is renting its core. Build too when you need provider behavior no vendor exposes, or when a compliance regime forbids another processor in the path. And at sufficient scale, per-account pricing eventually loses to infrastructure you amortize yourself.

Everyone else should run the numbers with all five lines on the page. A normalized API like Horato covers email, calendar, contacts, and tasks across Google and Microsoft accounts, with a paid tier at $10 a month for ten connected accounts. Set that against the review cycles and the sync plumbing, plus the standing claim on your engineers. The debate usually ends there, not because building is impossible, but because nobody joined your team to babysit provider APIs.