The SaaS Distribution Course #10: How Herd Security Built a 90% Trial Win Rate on Founder-Led Outbound
A source-backed course on Herd Security's founder-led system: narrow account selection, outbound, qualified trials, rapid product feedback, retention, and the scale gate.
TL;DR
Herd Security did not begin with a large audience or a fashionable acquisition hack. Founder Brandon Min says the company's early customers came from founder-led outbound and a few warm connections. The surprising result appeared later: Herd reported a 90% win rate once a prospect entered trial, 100% net retention and expansion, and some customers asking to renew and expand three months early.
Those figures are founder-reported. Herd did not disclose the cohort size, observation period, customer count, outbound volume, trial-entry rate, CAC, or payback. The reusable lesson is not “cold email converts at 90%.” It is a four-stage system: narrow the account, earn a serious trial, respond while intent is high, then require retention evidence before scaling the channel.
What you will build
This course gives you a founder-led distribution operating system for a narrow B2B SaaS. The output is not a sequence of generic sales emails. It is a connected set of six assets:
- a strict account and buyer filter;
- a verified trigger for founder outreach;
- a trial contract with one proof event and one decision date;
- a response loop that turns trial evidence into product decisions;
- a cohort checkpoint based on renewal and expansion;
- a scale gate for outbound, inbound, and partner experiments.
This system is for you if
- your product has a named B2B buyer and a considered purchase;
- a prospect can test the promise in a bounded evaluation;
- the founder can still change the product in response to repeated evidence;
- you have no large audience and need controlled access to a market.
Do not use it if
- every free trial requires bespoke work that can never become product;
- your buyer cannot name a proof event or decision owner;
- you need volume to hide weak retention;
- you plan to count warm introductions as cold outbound performance.
Case snapshot: what the evidence actually supports
| Stage | Herd evidence | Limit | Builder output |
|---|---|---|---|
| Market | Continuous security awareness and AI adoption instead of annual compliance-only training | Established category with large incumbents | One changed behavior and one dissatisfied buyer |
| ICP | Primarily 500 to several thousand employees; security/GRC buyers | Industry remains broad | Account size, accountable role, trigger, and disqualifier |
| Acquisition | Founder-led outbound plus a few warm connections | No volume, reply rate, or exact source split | Source-labelled account list |
| Proof | Founder-reported 90% win rate once a prospect entered trial | No cohort size, period, or trial-entry rate | Trial contract and proof event |
| Response | Customer calls connected to rapid tickets and product work | Release count does not measure quality | Request taxonomy and response SLA |
| Retention | Founder-reported 100% net retention/expansion and some early renewals | Cohort and revenue base undisclosed | Retention checkpoint before scale |
| Transition | Plan to expand outbound, inbound, and additional channels after the seed | Not yet a proven scaled motion | One measured experiment at a time |
Herd announced a $3 million funding round in May 2026, which The SaaS News independently reported. The financing validates the public event, not the distribution economics. Min said the private close happened in January after eight to nine months of fundraising and roughly a year of traction.
The model: founder access becomes proof, proof becomes retention
The system can be written as one causal chain: narrow account → specific problem → qualified trial → fast response → renewal and expansion → permission to scale. Each stage answers a different question.
- Account: is this buyer likely to share the product's premise?
- Outbound: can the founder earn a relevant conversation without an audience?
- Trial: does the product change a real workflow under a deadline?
- Response: can the team remove repeated friction while intent is high?
- Retention: does the promise survive after the sale?
- Scale: can another person or channel reproduce the result at known cost?
This structure prevents a common mistake. A founder sees a high close rate and hires sales before asking how prospects entered the qualified stage. Or the founder sees replies and buys more data before checking whether customers renew. Herd's own next goal at interview time was to quantify how much predictable return came from each dollar put into a channel. The system was promising, but its economics were still unfinished.
Step 1: make the ICP operational
Min described Herd's main target as mid-market companies, roughly 500 employees to several thousand, with a security, governance, risk, compliance, security-awareness, or human-risk owner. The company could serve other sizes, but the key fit was behavioral: the customer wanted security awareness to become continuous rather than an annual checkbox.
That premise is more useful than a sector label. A bank committed to continuous behavior change can be a better fit than a software company buying only the cheapest compliance certificate. Your account filter needs both firmographic fit and a visible reason to share your worldview.
Account worksheet
- Company range: ______ employees or ______ revenue.
- Accountable role: ______ owns the problem and budget.
- Current weak process: ______ is slow, manual, risky, or ignored.
- Change trigger: ______ happened in the last 90 days.
- Quarterly reason: the problem must be addressed before ______.
- Disqualifier: reject the account when ______.
Pass condition: you can reject at least half of a broad market list before enrichment. Stop condition: the ICP still reads “any company that needs our product.” Do not write messages until the exclusion rule is real.
Step 2: use outbound as controlled market access
In The SaaS CFO interview, Min says founder-led outbound and a few warm connections accounted for what Herd had closed. He also says the traditional version of outbound is under pressure because buyers receive so much low-quality contact. The interview does not reveal his exact copy or activity volume. Any “proven Herd template” would therefore be invented.
Copy the operating principle instead. Use one verified trigger and one problem per account. A trigger could be a new compliance requirement, an incident, an AI policy rollout, a new GRC leader, or an expansion that changes training needs. The trigger is evidence, not an opening-line decoration.
Weekly activity ledger
| Count | Why it matters | Decision rule |
|---|---|---|
| Qualified accounts | Measures research discipline | Reject weak-fit accounts before contact |
| Delivered messages | Separates data quality from copy | Repair data before adding volume |
| Positive replies | Tests trigger and problem | Look for a repeated pair, not a lucky answer |
| Accepted trials | Measures qualification | Do not celebrate meetings without proof intent |
| Won customers | Measures trial conversion | Keep trial-entry rate beside win rate |
| Renewed customers | Tests durable value | Do not scale on top-of-funnel data alone |
Keep cold outbound, warm introduction, inbound content, event, and partner sources separate. Herd's wording combines outbound with a few warm connections. Preserve that ambiguity instead of assigning every win to cold email.
Pass condition: one buyer-trigger-problem combination produces repeated positive replies. Stop condition: after 100 verified accounts, every response is random. Change the segment or trigger before increasing volume.
Step 3: turn the trial into a mutual contract
Herd's reported 90% result starts once a prospect reaches trial. That boundary is the article's dominant lesson. A trial should not be an unmanaged free account. It is a shared experiment with an owner, a workflow, an expected change, and a decision date.
Herd's current demo page says a tailored walkthrough normally takes 20 to 30 minutes, the company responds within 24 hours, and most organizations can onboard within one week. Those are vendor-reported operating claims, not universal benchmarks. They do show how the company makes evaluation concrete.
Trial contract
- Workflow: what changes for which operator?
- Baseline: how is the job done today, and at what cost?
- Proof event: what observable result means the promise worked?
- Deadline: when must the proof exist?
- Blockers: security, integration, budget, legal, and procurement.
- Decision: who reviews the result, and on what date?
Pass condition: buyer and seller can name the same proof event and decision date. Stop condition: the prospect wants open-ended access but will not provide an owner, workflow, or review date.
Step 4: compress the evidence-to-product loop
Min described an internal system where call evidence could create tickets and start engineering work. He reported as many as 15 to 20 feature releases in a day and tracked time from customer request to delivery. “Feature” is not defined, so release count is a poor target by itself. The valuable part is the connection between active evaluation evidence and a product decision.
- Classify the request as bug, missing proof, integration, preference, or off-strategy.
- Connect it to the account, buyer, trial stage, and expected outcome.
- Check whether the same friction appears in at least one other target account.
- Choose the smallest safe change that can unblock proof.
- Return the change while the evaluation is active.
- Record whether it altered activation, conversion, support load, or retention.
Pass condition: a blocker for a high-fit trial receives a product decision within 48 hours. That decision may be “no.” Stop condition: one large prospect pulls the roadmap beyond the agreed ICP, or a custom change has no reusable evidence.
Step 5: let retention authorize scale
Min reported 100% net retention and expansion. He also said some early customers wanted to renew and expand three months before their contracts ended. These claims are encouraging, but the cohort size, period, and revenue base are missing. Do not turn an early snapshot into a permanent “zero churn” claim.
Review trial win rate, 30-day activation, renewal, expansion, support cost, and founder hours per win together. A high post-trial win rate with weak renewal means the trial overpromises. Strong retention with few accepted trials means acquisition or proof design is broken. Expansion that depends on indefinite bespoke work may hide service cost inside SaaS revenue.
Pass condition: at least two cohorts retain under the same core promise, and the founder can describe why without relying on unscalable custom work. Stop condition: hiring is justified only by a close-rate headline while channel cost and delivery load remain unknown.
Step 6: add channels only after instrumenting the first one
At interview time, Herd had identified one or two distribution channels and planned to expand outbound and inbound with the seed funding. Min's explicit goal was to understand what predictable return came from each dollar invested and to find additional channels. This is a transition plan, not evidence that inbound or partnerships already scaled.
Herd had an existing Okta integration and said 90% of its customers already used Okta. The May funding announcement also named growth of the partnership ecosystem as a use of funds. An integration can improve trust, onboarding, and access to an installed base, but it is not a distribution channel until sourced pipeline, conversion, and cost are measured.
Channel experiment card
- Channel: scaled outbound, content, event, integration partner, or referral.
- Job: create awareness, conversation, trial, or expansion.
- Input: money, founder hours, team hours, and data.
- Leading event: the first measurable signal.
- Lagging event: won, renewed, or expanded revenue.
- Kill date: when the experiment ends without evidence.
Pass condition: the new channel creates qualified trials without lowering retention or hiding cost. Stop condition: the team reports impressions, leads, or partner meetings but cannot connect them to trial and renewal cohorts.
Your 7-day implementation plan
- Day 1: write the account filter, buyer, changed behavior, and disqualifier.
- Day 2: source 30 accounts around one verified trigger. Label every source.
- Day 3: write one short message with one ask. Review all claims manually.
- Day 4: create the trial contract, proof event, blockers, and decision date.
- Day 5: build the request taxonomy and a 48-hour product decision rule.
- Day 6: create a dashboard from account source to renewal and expansion.
- Day 7: review the evidence. Continue only when the buyer, trigger, problem, and proof repeat.
The week does not end with a large send. It ends with a small, reviewable system. Your first target is learning density: how much reliable information each qualified conversation produces.
Lead Scorer implementation: reproduce the motion with approval gates
Lead Scorer can organize the research, qualification, enrichment, draft, and feedback loop. It cannot manufacture product-market fit, guarantee Herd's numbers, or send without review. Keep the founder responsible for the ICP, proof event, claims, and final outreach decision.
Phase 1: encode the market boundary
Start with the icp-offer-context skill. Record the target account, buyer, weak
current process, approved proof points, and hard disqualifiers. Then use icp-scoring-rubric to turn the definition into a weighted 1-10 model. Create
separate company and lead lists with create_list. Keep cold outbound, warm
introductions, content engagers, and partner referrals in different lists so attribution
survives.
Copyable prompt: “For this product, define a 1-10 ICP rubric. Give 35% to buyer and problem fit, 25% to a verified change trigger, 20% to urgency, 10% to implementation fit, and 10% to evidence quality. Hard-reject accounts committed only to the legacy process.”
Pass condition: the agent can explain every score with sourced facts. Stop condition: more than half the score depends on guessed technology, revenue, or intent.
Phase 2: score before spending credits
Load candidates, then use get_leads_pending_scoring and submit_lead_score. Enrich only the keepers with enrich_leads. Run find_lead_contact_info last, first with a dry-run estimate. Email and phone discovery
are the expensive step; keep human confirmation above the configured credit threshold.
Use three gates: reject below 6, manually review 6-7, and allow 8-10 into contact discovery only when the trigger has a source and date. These are starting thresholds, not universal truth. Calibrate them against accounts you know.
Phase 3: draft a controlled campaign
Create a draft with create_campaign and add only approved leads with add_leads_to_campaign. Use generate_campaign_drafts or write_campaign_drafts for per-lead copy. The ask should be one bounded conversation or
trial, not an automatic sequence built around unverified fear.
Review every message, proof claim, sender identity, timing, and disqualifier in the web UI. Nothing in this workflow approves, activates, or sends the campaign. If evidence is thin, the correct output is a skipped lead.
Phase 4: make trial and objection states explicit
Track invited, accepted, activated, proof reached, won, lost, renewed, and expanded as explicit tags or list stages. Store the decision date and next proof action. When prospects object, classify the objection as targeting, timing, trust, product gap, integration, price, or no priority.
Feed repeated objections into Content Studio as sourced content items. A useful answer can
become a product note, sales asset, or public article. If the content attracts the same buyer,
capture those visible engagers with create_audience_source and score them in a separate
list. That creates a measured objection-to-content-to-signal loop without pretending inbound and cold
outbound are one channel.
What failed, what is premature, and what remains unknown
The source does not document a clean failed acquisition channel. It documents a structural limit: traditional outbound is noisy, and Herd had not yet quantified channel return. It also documents a premature claim to avoid. Planned inbound expansion and partnership investment are not the same as repeatable inbound or partner distribution.
The financing story contains its own warning. Min describes about 150 investor conversations over eight to nine months and says investors still wanted revenue, logo velocity, retention, and expansion. A strong product story did not remove the need for operating evidence.
Saveable checklist
- one buyer, one changed behavior, and one hard disqualifier;
- one sourced trigger per account;
- cold, warm, inbound, event, and partner attribution kept separate;
- trial owner, proof event, deadline, blockers, and decision date;
- 48-hour product decision for high-fit trial blockers;
- trial-entry rate beside post-trial win rate;
- retention and founder hours reviewed before scale;
- credits confirmed before contact enrichment;
- every outreach message remains draft until human review;
- no new channel without a leading event, lagging revenue event, budget, and kill date.
Sources and evidence limits
- The SaaS CFO: “How AI is Changing Security Awareness Training”, published July 2, 2026. The stored Podscan transcript was audited from character zero to its effective end.
- Herd Security's May 2026 funding announcement and independent funding coverage from The SaaS News.
- Herd's current demo and onboarding page, used only for vendor-reported operating claims.
- Herd's Okta integration announcement, used as product and partnership evidence, not proof of partner-sourced revenue.
- Herd's security-awareness product page, used for current product positioning and time-to-value claims.
The 90% post-trial win rate, 100% net retention/expansion, early-renewal timing, release speed, and channel description are founder-reported. No public customer count, ARR, CAC, outbound activity, trial-entry conversion, payback period, or partner-sourced revenue was found. This course therefore teaches the sequence and its decision gates. It does not present Herd's early percentages as general benchmarks.
Frequently asked questions
Did Herd Security convert 90% of all cold outbound prospects?
No. Founder Brandon Min reported a 90% win rate only after a prospect entered trial. Herd did not publish outbound volume, reply rate, meeting rate, trial-entry rate, cohort size, or overall lead-to-customer conversion.
What was Herd Security's early acquisition channel?
Min said the company closed its early business through founder-led outbound and a few warm connections. The exact source split and message activity are not public.
When should a founder scale this motion?
Scale only after the same buyer, trigger, trial proof event, and renewal pattern repeat across cohorts, and after founder hours, channel cost, conversion, and support load are measurable.