Low-code platforms let people build applications and automations with visual designers and pre-built components rather than writing everything from scratch. They can relieve pressure on development teams — if they are governed well.
The benefits
- Faster delivery of internal tools, forms, approvals and workflows.
- Business experts can build solutions close to the problem.
- Professional developers can focus on complex systems.
The risks
- Sprawl: hundreds of unmanaged apps with unclear owners.
- Data exposure: connectors that move sensitive data to the wrong places.
- Quality: apps built without testing, documentation or support plans.
- Lock-in: logic that is hard to move off the platform.
A governance model that works
- Approve a small number of platforms and set them up centrally.
- Separate environments for personal, team and enterprise apps, with stricter controls as impact grows.
- Define data loss prevention policies for which connectors can be combined.
- Require owners, documentation and review for business-critical apps.
- Create a community of practice and training for citizen developers.
5 best governance practices for low-code platforms
- Create environments by purpose. Separate personal productivity, departmental and enterprise-critical environments, each with appropriate controls.
- Apply data loss prevention policies. Restrict which connectors can be used together so sensitive data cannot flow to unapproved services.
- Register and classify apps. Maintain an inventory of apps, owners, data used and business criticality.
- Define a path to production. Apps that become business-critical should move to managed environments with testing, version control and support arrangements.
- Build a community of makers. Training, templates and a centre of excellence help citizen developers build safely and share good practice.
Where low-code delivers the most value
- Replacing spreadsheets and email-based processes with structured workflows.
- Building approval, request and inspection apps quickly.
- Extending enterprise systems with simple forms and automation.
- Prototyping ideas before investing in full development.
Common mistakes to avoid
- Banning low-code entirely, which drives shadow IT elsewhere.
- Allowing unrestricted connectors to external services.
- Leaving critical apps owned by a single employee who later leaves.
- Ignoring licensing costs as usage grows.
Frequently asked questions
Who should own low-code governance?
Typically IT owns the platform and policies, while business units own their apps and data.
Can low-code apps be secure?
Yes, when platform security features, data policies and access controls are configured and monitored properly.
A 90-day action plan
Days 1 to 30: discover existing apps, flows and connectors, identify owners and classify them by business criticality and information sensitivity.
Days 31 to 60: set up separate environments, apply connector policies, and publish simple guidelines and templates for makers.
Days 61 to 90: launch a community and training programme, define the route for promoting important apps to managed environments, and report adoption and risk metrics.
Questions to ask before approving an app
- What business process does it support, and who owns it?
- Which information sources does it connect to, and how sensitive are they?
- Who will support it if the creator changes role?
- How many people depend on it, and what happens if it fails?
- Does it duplicate an existing enterprise application?
Key terms explained
- Citizen developer: a business user who builds applications with visual tools.
- Connector: a prebuilt integration with another service or system.
- Centre of excellence: a team that sets standards and supports makers.
- Environment strategy: rules for which apps live in which managed spaces.
- Data loss prevention policy: rules that restrict how information moves between connectors.
The bottom line
Visual development tools let business teams solve problems quickly and relieve pressure on IT backlogs. The risks come from unmanaged growth: unclear ownership, uncontrolled information flows and critical apps without support. A balanced model with separate environments, connector policies, an app inventory, a clear route to production and an active maker community captures the benefits while managing the risks. The goal is enablement with guardrails, not restriction.
Further reading on low-code platforms
For authoritative, vendor-neutral guidance on low-code platforms, see the OWASP Low-Code/No-Code Top 10. You can also browse our free whitepapers.

