The App Store Is a Trap
Ron Reynolds · 2026-04-30 · 8 min read
Why Herd-Driven Software Selection Is Fragile by Design
Ron Reynolds | Founder, ComOS | April 2026 Shopify just announced it paid $1.3 billion to developers in the past year. Twenty-one thousand apps in the store. Twenty percent year-over-year growth in installs. The press release reads like a celebration of abundance.
Read it again.
What it actually describes is a merchant base that depends on twenty-one thousand strangers shipping code on their own schedule, with their own security postures, their own deploy pipelines, their own AI assumptions, and their own ideas about when — or whether — to patch a CVE.
That's not abundance. That's distributed fragility, dressed up as choice. The Hidden Architecture
Every Shopify merchant runs the same architecture, whether they realize it or not: A thin commerce kernel that handles catalog, cart, and checkout A pile of third-party apps bolted on for everything else: SMS, email, abandoned cart, dynamic pricing, inventory monitoring, returns, support routing, brand voice, access control, automation, analytics A constant integration tax to keep the pile from collapsing on itself
The 21,000 apps exist because the base system can't do those things natively. Each app is a separate database holding merchant data the platform owner can't audit. Each app has its own auth surface, its own webhook handlers, its own failure modes. Each one runs with the merchant's API tokens and ships code whenever the developer feels like it.
The merchant signed up with Shopify. Their actual operations depend on a dozen vendors they've never met. The Herd Replaces Judgment
Once an app store reaches critical mass, the selection mechanism stops being "is this good?" and becomes "is this popular?"
Watch what actually happens when a merchant picks an app:
1. They search the category 2. They sort by install count or rating 3. They pick one of the top three 4. They install it because other people installed it
Nobody read the code. Nobody audited the security posture. Nobody checked whether the developer is one person in a kitchen or a team of fifty. Nobody asked whether the company is profitable or about to be acquihired and shut down. The signal merchants are using is lots of other merchants picked this — which is the exact signal that creates lock-in for whoever got there first, regardless of whether they should have.
This is the real moat of any app store. It is not a quality moat. It is a legitimacy moat.
The first SMS app to hit ten thousand installs becomes the SMS app. New entrants with better technology can't break in, because merchants don't evaluate on technology — they evaluate on social proof. The incumbent stops innovating because they don't have to. The platform owner gets their cut either way, so they have no incentive to disrupt the herd. Merchants pay the tax of suboptimal tools forever.
App stores don't reward the best solution. They reward the first solution that achieved escape velocity in social proof. That's not a market. That's a popularity contest with switching costs. The Cascade Problem
Here's the part nobody likes to think about.
When the herd dynamic concentrates merchants onto the same dependencies, it also concentrates their failure modes. Most of the 21,000 apps are dormant. Most merchants are using the same fifty apps. Those fifty apps got there through herd dynamics, not through being right.
Every one of them is a single point of failure that thousands of merchants share.
When the incumbent SMS app gets acquired and the new owners triple the price, every merchant on it has the same problem at the same time. When a popular automation app pushes a bad migration, every store that depends on it breaks at the same time. When a top-50 app pulls in a compromised npm dependency, you have a supply-chain incident across a meaningful chunk of the merchant base.
Distributed fragility isn't resilience. It's just fragility you can't see until it cascades. The "Built For" Badge Is Theater
Platforms try to dress up the app store with quality signals. Badges. Reviews. Featured placements. Compliance audits. Built for Shopify. Premier Partner. App Store Verified.
That's discovery curation, not runtime safety.
Once an app is installed, it runs with merchant tokens, writes to the merchant's data, holds copies of customer records on the developer's infrastructure, and ships new code on the developer's deploy schedule. The platform owner is not in the loop on any of it. The badge is a one-time review that has no bearing on what the app does in production six months later.
You wouldn't run your business on twelve vendors you never reviewed. The app store model means you do. The badge just makes you feel better about it. The Bus Factor Goes Both Ways
People sometimes ask about ComOS's bus factor because there's one founder. It's a fair question. We answer it directly: the system is designed to run on agents, the documentation is dual-audience for humans and AI, every architectural decision is captured in the codebase and the docs, the entire platform is reproducible.
But notice that the same question almost never gets asked of the app store model.
A typical Shopify merchant's operations have a bus factor of whichever twelve app developers they happen to depend on this quarter. Any one of them could pivot, sell, sunset the product, raise prices, get hacked, or simply disappear. The merchant has no visibility into the health of those companies, no contractual claim on their continuity, and no path to migration that doesn't involve months of rebuilding.
Nobody asks about the herd's bus factor because the fragility is distributed enough to feel invisible until something breaks. Then it breaks at scale, all at once, and the platform owner shrugs because the contract was always between the merchant and the developer. Why ComOS Doesn't Have This Problem
There is no app store to herd into. There is one operating system.
The cart-abandonment agent isn't competing with forty-seven other cart-abandonment agents for installs. It's a first-party function of the system. It knows about inventory, because inventory is in the same OS. It knows about brand voice, because brand voice is in the same OS. It knows about customer history, payment recovery, shipping anomalies, and policy enforcement — because all of those are first-party functions of the same coherent system, designed by people who understood how the pieces have to interact.
Every action runs through one decision engine, one confidence-scoring layer, one autonomy-control surface, one audit trail, and one rollback window. A bug found anywhere gets fixed once, for everyone, by us. A capability added anywhere is available everywhere. A security patch deploys to the whole network, not to whichever fraction of vendors happen to be responsive that week.
When a merchant joins ComOS, they don't have to make twelve herd-driven app picks that will define the next five years of their operations. They don't have to evaluate, integrate, monitor, replace, and pray. They get a coherent system. The integrity of their business doesn't depend on twenty-one thousand strangers. The Honest Translation
The Shopify pitch is: 21,000 apps to choose from.
The honest translation is: 21,000 vendors you'll have to evaluate, integrate, monitor, replace, and pray don't break — and you'll mostly just pick whatever the herd picked, hope it's good, and find out in eighteen months when something cascades.
That's not a platform. That's a marketplace of risk dressed up as choice. The herd dynamic guarantees most merchants end up running the same fragile stack, so when it breaks, it breaks them all at once. And the platform owner has no incentive to fix it, because the herd dynamic is what creates the lock-in that makes the platform valuable in the first place. The Category Difference
This isn't a feature comparison. Every platform claims more features.
The argument is structural. The integrity of a business shouldn't depend on twenty-one thousand strangers shipping code on their own timeline, evaluated by merchants who picked them because other merchants picked them.
One operating system. One team. One accountability chain. One coherent design where every operation is a first-party function, every decision is logged, every action is reversible, and every component was built to integrate with every other component because they were built together.
That's not a better app store. That's the end of the app store as the model.
The agent era makes this even more obvious. When agents become the primary buyers and operators of commerce, 21,000 apps to choose from isn't a feature — it's friction. The merchant whose entire operation is already agent-reachable through a single coherent system doesn't need to shop a marketplace of fragile dependencies. They just open the gateway.
That's the difference between celebrating a $1.3 billion payout to third-party developers and building a system where the platform itself does what twenty-one thousand apps were assembled to approximate.
The app store made sense in the era of human-driven workflows and feature-by-feature differentiation. It does not make sense in the era of agent-native commerce, where coherence beats catalog size and accountability beats abundance.
The herd will figure that out. Eventually. The merchants who figure it out first will be the ones who stopped picking from a marketplace of risk and started running on an operating system.