Please ensure Javascript is enabled for purposes of website accessibility
Home AI Governing the Citizen Developer Boom Without Killing It

Governing the Citizen Developer Boom Without Killing It

headline for Governing the Citizen Developer Boom Without Killing It

Each large organization already has an informal software vendor working within it, and this person isn’t actually a vendor; rather, they are a member of the operations team who became fed up with having to wait for IT and therefore worked out how to solve their own problem without governing.

It’s not exactly a new development, but what is new is just how easy it has become and how rapidly the practice is now spreading beyond the small number of individuals who previously spent time quietly creating their own spreadsheet macros or Zapier chains. The more pressing question for many enterprise leaders at the moment isn’t whether this is occurring, but whether anyone actually knows the full extent of it.

Key Takeaways

  • Many organizations face a visibility problem with shadow IT, as a significant portion of their software spending occurs without IT oversight.
  • Employees often turn to unauthorized tools due to lengthy IT processes, leading to a rise in citizen development.
  • Governed citizen development ensures visibility and compliance, contrasting with ungoverned shadow IT activities.
  • Effective governance involves cataloging approved tools, empowering teams, and establishing technical requirements for internal applications.
  • AI-assisted, no-code tools accelerate citizen development, making proper governance even more critical for organizations.

The Visibility Problem

Shadow IT, referring to technology that is adopted or developed without formal approval from IT, has always been a known risk. The difference these days is how extensive it has become. Industry research on enterprise software spending shows that 30% to 40% of total IT budgets at large organizations currently pass through channels that entirely avoid official procurement and oversight. That’s no mere rounding error; it means a substantial part of enterprise technology spending is taking place somewhere IT cannot see it.

In some instances, IT leaders have cited the tools they had blocked, only to find out later that a large number of people were still using them on personal accounts. The policy was in place, but there was no visibility.

The lack of visibility is probably a more serious problem than the spending itself. Surveys on unauthorized software use show that the majority of employees use at least some unapproved application during their work, while only a small number of organizations say they know the full extent of it. It is not that most companies are deliberately ignoring shadow IT; they truly do not know how much of it there is.

Once you consider why it happens, none of this is surprising. A sales operations manager needs a tool to track deal handoffs. Filing a request with IT means joining a backlog behind higher-priority requests, waiting weeks for a meeting, and possibly being told the request isn’t high enough priority to be included in this quarter’s development. Signing up for a free tool, or nowadays explaining what is needed to an AI-assisted builder, takes just an afternoon. The motivation to go around IT has not disappeared; in fact, the tools that make it easy to go around IT have become much better.

Why Locking Governing Down Doesn’t Work

Many IT and security professionals automatically react by trying to shut this down: they block unauthorized tools, require every internal build to go through a central team, and see any unapproved software as a breach to be detected rather than as a signal worth investigating. Even though such a response can be understood, it also tends to fail.

The term “citizen developer” originated with Gartner, which describes it as a role, not a job title—thus referring to someone in operations, sales, or another department who creates applications without holding an official engineering position. Just stopping such behavior does not mean the fundamental need disappears; on the contrary, it causes people to resort to their own personal devices, unmonitored accounts, and tools that IT is never made aware of until a failure takes place or a security audit uncovers something unexpected.

Those organizations that deal with this issue usually adopt a different approach: it is not citizen development that is the problem; it is citizen development without governing. There is a real distinction to be made between a business user creating an internal tool with the help of IT, using an approved platform and adhering to basic data handling rules, and that same person building the same tool completely without being noticed since asking for permission seemed like a waste of time.

What Governing Actually Looks Like in Practice

person using governing it system

A number of practices distinguish those organizations which manage this situation well from those that either secure everything or allow it to run without any control.

A central catalog of what exists. Whenever any internal tool has been approved, no matter if it was developed by IT or by a business unit, it is entered into this catalog with a named owner and a brief description of the function it performs and the data it handles. This one action deals with a major aspect of the visibility problem, since most shadow IT is not malicious; it is simply not visible.

A small team that enables rather than gatekeeps. Usually consisting of a few people from IT or security who check platforms for security and compliance, compile a brief list of those platforms which are approved, and stay on hand to answer any questions, so that it is not necessary for each request to go through the full review procedure before anyone can start building.

The basic technical requirements should be non-negotiable. Any platform intended for use in citizen development should have real audit trails and role-based permissions built in by default; a tool which cannot show who made what changes or which treats access as all-or-nothing should only be used for the most trivial and non-sensitive types of data.

Every tool should have a review cycle and a designated owner. Even when software is developed by a business user there still has to be an answer to the question of what happens when this person changes roles or leaves the company; otherwise, a useful internal tool will one day become a liability because no one will be able to explain how it works.

Where AI-Assisted Building Fits Into This

The fact that AI-assisted, no-code tools are now available really speeds up citizen development, which is precisely the reason why governing is more important than ever. Since a working version of an internal tool can be created in just a few days from a simple description, the distance between “I need this” and “I built this without telling anyone” becomes even smaller.

Platforms that are designed specifically for use by enterprises, such as AgentUI, generally incorporate governance directly into the product rather than adding it on later as IT would; they include built-in audit trails, permission settings which do not need a developer to set up, and a human team on the platform’s side who can identify cases where sensitive data is being used. This is quite a different approach from a business user signing up for a free tool using a personal email address with no supervision whatsoever.

A few related pieces worth your time:

The Real Governing Choice Enterprise Leaders Are Making

The actual choice facing enterprise leaders is not whether or not to adopt citizen development. That decision was already made when software became easy enough for non-engineers to produce it well. The true choice lies between governing citizen development, characterized by visibility, clear guidelines, and well-defined ownership, and the ungoverned form which is currently in operation, largely unseen, within a significant portion of the technology budgets of large organizations.

It is not the companies that have the most stringent rules who have worked out this approach; rather, it is those who have given up on seeing the demand to build as something to be suppressed and have instead regarded it as something to be channeled.

Subscribe

* indicates required