Applications built by non-developers.
WHAT THEY PROVIDE
Building applications with limited coding Speed for straightforward needs Business users solving their own problems
WHAT THEY SUIT
Forms and data collection Simple workflows Departmental applications Prototypes
WHAT THEY DO NOT SUIT
Complex logic High volume Anything requiring rigorous testing Systems the business depends on entirely
WHAT THE RISKS ARE
Applications nobody maintains Data outside governance Duplication of existing capability Dependence on the individual who built it Security and access not properly controlled
WHY THAT SECOND-LAST POINT MATTERS MOST
The builder leaves, and nobody understands it.
WHAT GOVERNANCE SHOULD REQUIRE
Registration of applications built An owner Review of anything handling sensitive data Standards for access control
WHAT TO PROVIDE
Approved platforms, and guidance.
WHY APPROVED ONES
Uncontrolled adoption produces data in places nobody knows about.
WHAT TO ENCOURAGE
Solving genuine local problems.
WHAT TO PREVENT
Applications becoming business-critical without oversight.
WHAT TO REVIEW
Which applications have grown beyond their intended scope.
WHAT TO DO ABOUT THOSE
Bring them under proper management, or replace them.