惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
Martin Fowler
Martin Fowler
B
Blog
The GitHub Blog
The GitHub Blog
T
Tailwind CSS Blog
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
DataBreaches.Net
月光博客
月光博客
人人都是产品经理
人人都是产品经理
IT之家
IT之家
GbyAI
GbyAI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
C
Check Point Blog
罗磊的独立博客

StarCIO Digital Trailblazer Community

5 Ways AI Governance Lowers the AI Hallucination Tax Twenty-Five Years Later: My 9/11 Story 150+ AI Tools for Agile Product Managers AI Bubble Burst? 10 Signs, 7 Ways for CIOs to Prepare For It How Knowledge Management Drives AI’s Context Layer: 5 Industry Examples Building the AI Agent’s Brain: Knowledge Graphs vs. Semantic Layer vs. Context Layer Technology Evaluations: Understanding AI Ecosystems AI Talent in a World of Continuous Change Should Citizen Developers Vibe Code — or Vibe No-Code? 5 Leadership Skills for the AI Era: What Changed and What's New AI Companies Bet on Subscriptions: Many Will Repeat SaaS’s Worst Mistakes Scoring AI ROI in Customer Experience: What CIOs Need to Know 5 Essential Questions for CIOs on Planning IT Careers in the AI Era 6 Key Requirements for Securing AI Agents Before the POC Data Management Debt in the AI Era: What CIOs Need to Know AI Cost Debt Is Real. Here’s How FinOps Helps CIOs Avoid It Low-Code Development in the AI Era: What CIOs Need to Know College Graduates are Very Pissed Off About AI The Autonomous Enterprise in the AI Era: What CIOs Need to Know Agile Organizations in the AI Era: What CIOs Need to Know Critical Process Management in the AI Era: What CIOs Need to Know Marketing in the AI Era: What CIOs Need to Know The Future of Work: Here Come the AI-Enabled Devices Hybrid Clouds in the AI Era: What CIOs Need to Know AI is Only Reshaping Business. It’s Not Digital Transformation. Yet. Citizen Analytics in the AI Era: What CIOs Need to Know How to Deliver Bad News to Executives? An IT Leader’s Communication Playbook AI Coding Competencies: What Inspires Awe — and 5 Ways They Spark Dread Is AI Putting Your Leadership Job at Risk—or Opening Your Biggest Career Opportunity? Will Agentic AI Drive the Convergence of ITOps and SecOps
How Citizen Developers Should Respond to Allegations They...
Isaac Sacolick · 2026-08-10 · via StarCIO Digital Trailblazer Community

Drive has 700+ articles for digital transformation leaders written by StarCIO Digital Trailblazer, Isaac Sacolick. Learn more.

This article is brought to you by Quickbase. The views and opinions expressed herein are those of the author and do not necessarily represent the views and opinions of Quickbase.

This article is brought to you by Quickbase

The views and opinions expressed herein are those of the author and do not necessarily represent the views and opinions of Quickbase.

I have been a low/no-code developer and Quickbase builder for over two decades. I’ve also sponsored citizen development programs at enterprises, advised construction companies on adopting Quickbase’s capabilities, and written dozens of articles on driving digital transformation with low- and no-code.

The first half of my career was as CTO and CIO. I’ve seen some of my peers accelerate their app modernizations, control SaaS sprawl, and avoid productivity killers by adopting Quickbase. But I have also heard pushback from IT departments, claiming that citizen development and empowering business builders with no-code are shadow IT, especially when business teams procure platforms with minimal or no IT involvement.

How Citizen Developers Should Respond to Allegations They Are Shadow IT

Look, buying SaaS and other technologies without IT and security reviews is very bad, but I understand why it happens. In a CIO.com article, I shared seven steps to turn shadow IT into a competitive edge, changing CIO mindsets, and providing an approach to turn shadow IT into a net positive.

Quickbase is not shadow IT

Quickbase builders are on the right track because the platform has strong security, operational resiliency, and sustainable business innovation features that CIOs, CISOs, and IT leaders seek. But there are legitimate concerns if builders use development tools without defined practices and standards. C-levels call it governance, and the structures help ensure applications and pipelines are not just secure and resilient, but also supportable and extendable by other builders.

If you are a Quickbase builder, citizen developer, or lead a team of them, I want to share some best practices with you, as a fellow builder. In addition, here’s how to respond to IT and security leaders if they mistakenly label your efforts as shadow IT.

1. Establish disciplines about what gets built

Quickbase makes building apps and pipelines really easy. You can import a spreadsheet, customize an app selected from the Quickbase App Library, or use the new AI Smart Builder capabilities.   

That ease of use can translate into building one-time-use applications, duplicate apps, or complex apps that are difficult for other builders to maintain and extend.

Creating too many unsupportable apps is a top CIO concern, and builders should take notice. IT is plagued by legacy systems that are hard or costly to maintain, and technical debt, where apps with known defects or implementation issues aren’t easy to upgrade. The same issues can occur with citizen-developed applications.

The first step to address this concern is to create an easy process for reviewing ideas before building. The review process should include documenting a vision statement around the business value and identifying compliance factors. Additionally, reviewers should consider whether extending an existing application to fulfill the business need is more efficient than creating a new one.

Over ten years ago, I recommended this very simple portfolio management tool to help decide which ideas to build as apps. The one I use today is implemented in Quickbase.

2. Prioritize pipelines for integrations and automations

Shadow IT has a reputation for creating siloed applications that work for one department but don’t connect multi-departmental business processes. The result can be a mess: duplicate data entries, swivel-chair integrations (i.e., using multiple tools to accomplish one task), and emailed spreadsheets with process gaps.

Before deploying an app’s MVP (minimally viable product), consider its minimally viable integrations and automations. Demo these capabilities to stakeholders and IT leaders, as automations operate behind the scenes.

I automate workflow steps and integrate SaaS tools with a mix of Pipelines and Zapier. Here’s one example. You can build pipelines with Quickbase AI and Quickbase Pipeline Designer

3. Create policies and standards around secure implementations

Quickbase does its job by providing strong security and governance features. But it’s the builder’s responsibility to implement them.

Therein lies a second opportunity to sway IT leaders from detractors to supporters. If each Quickbase application and pipeline has its own policies, naming conventions, and administrative procedures, IT leaders will sniff out this mess that leaves a very bad taste in their mouths. If, on the other hand, security is configured according to standards, the structure makes it easier for others to review configurations and suggest improvements when required.

Here’s a quick guide to get started.

  1. Work with your IT and security teams to implement Quickbase policies consistent with your organization’s compliance requirements. If there are questions, review Quickbase’s data security and integrity compliance with them, which includes SOC1 – Type II, SOC2 – Type II, SOC3, the HIPAA Security Rule, DFARS CSA – CCM – STAR Level 2, and TX-RAMP Certified Cloud Product – Level 2.
  2. Define user access management standards, including who gets access, how sign-ons are implemented, onboarding procedures, and offboarding steps.
  3. Create policies and naming conventions around entitlements – who gets access to what data and which steps in a workflow. Then, configure permissions for defined roles consistently across all Quickbase applications. Quickbase allows defining realms and groups at the admin level, and then setting row- and column-based entitlements for each application.
  4. Create a standard for how apps are prototyped, then standardize lifecycles covering dev, test, deploy, and roll-back. The Quickbase sandbox allows creating environments for testing new features. Quickbase also provides a scaled solution management, so applications can run in dev and test environments before being promoted to production.

4. Centralize and document reusable data assets

Quickbase lets you securely connect data and workflows across applications. If you have relatively few applications, this may be the simplest way to share data in one application with another.

Over time, point-to-point integrations can be complex to maintain. Here’s an example.

  • The finance team might create a workflow for customer accounts in one application.
  • The account management team builds a second app storing customer contacts related to the finance team’s accounts table.
  • A customer support team develops a third app for support tickets that connects to accounts and customer contacts.

Now, if the customer support team needs to add new accounts and customer contact fields, they have to make changes in three applications maintained by three different builders.

This simple example illustrates an opportunity to separate entity and reference data into separate applications. In the case above, accounts and customer contacts could be separated into one application where these master records are maintained. Then, the finance, account management, and customer support teams can have a consistent way to access the master records.

5. Lead with controlled AI experimentation

I encourage you to experiment with AI – but do so in a controlled manner.

Quickbase has launched several AI features as part of Quickbase Intelligence Pack. These include Pave for building modern applications, an AI Smart Builder for developing Quickbase apps, and Quickbase AI Agent for querying information across Quickbase applications.

But before turning on all the features for everyone everywhere, I suggest a more pragmatic AI approach with a controlled rollout of ethical, controlled AI agents.

The process should start by teaming up with IT and information security to review their AI governance policies, then reviewing the controls available in Quickbase AI Control Center. Start with a small group trying out AI capabilities in areas that align with business value and risk. When promising use cases emerge, the team is now ready to communicate the opportunities and devise a rollout plan that extends to more builders and end users.

If you want to escape being labeled shadow IT, then building apps, pipelines, and now AI should have a consistent, secure, and standardized implementation strategy.

This article is brought to you by Quickbase.

The views and opinions expressed herein are those of the author and do not necessarily represent the views and opinions of Quickbase.