Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Citizen Developers Need Guardrails

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.

The short version: In 2021, about 38 million records — including vaccination data and Social Security numbers — were exposed through websites built with Microsoft's low-code tools by organizations including airlines and government agencies. The builders weren't hackers or careless engineers; they were using the tools as designed, with risky defaults.

Why citizen development needs guard rails

Low-code platforms let employees build apps, automations and now AI agents without IT. That speed is valuable. But builders often don't know how to secure data, and their creations can be shared widely or even published to the internet.

The business impact

  • Data exposure through apps nobody in IT knew existed.
  • Compliance risk when regulated data flows through unapproved connectors.
  • Growing AI risk, as Copilot Studio agents use the same platform.

Questions to ask your team

  • How many Power Apps, flows and agents exist in our tenant, and who owns them?
  • Can employees publish public websites or connect company data to personal services?
  • Do we have data policies controlling which connectors can be combined?

What good looks like

Separate environments for personal and business-critical solutions, data policies blocking risky connectors, an inventory of apps with owners, and review before anything goes public.

The decision

Encourage citizen development — with guard rails. Ask IT to put basic Power Platform governance in place before expanding Copilot Studio agents.

power apps data exposure impactPower Apps portals exposure2021

More on this story