TL;DR: C1.ai describes Union Station as an internal platform that centralises app deployment, authentication, infrastructure, onboarding, offboarding, and governance for internal tools, Slack bots, AI-powered apps, and other automations. The identity lesson is that teams reduce shadow accounts and unmanaged sprawl when the sanctioned path is easier than personal-account workarounds, because governance fails where deployment friction wins.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Union Station: The Internal Platform Powering C1's Agentic Enterprise Transformation”.
Key questions
Q: How should security teams handle internal apps that people will build anyway?
A: Treat the internal platform as the required identity boundary for those apps.
Q: Why do shadow AI apps create identity governance risk?
A: Shadow AI creates risk because the application can be adopted outside approved procurement and still move sensitive data.
Q: What breaks when internal automations are not registered in a governed platform?
A: Inventory breaks first, then accountability.
Practitioner guidance
- Define a single sanctioned deployment path Make the internal platform the default place where teams create apps, bots, and automations, so authentication, ownership, and infrastructure are attached from day one.
- Require RBAC for sensitive workflows Place privileged internal operations such as offboarding, vendor reviews, and other business-critical automations behind role-based access control in the platform.
- Attach inventory to deployment Do not allow internal tools to exist without registration, owner assignment, and a visible deployment record that security can audit later.
Bottom line: The article's core security lesson is that internal app sprawl becomes an identity problem as soon as tools, bots, and automations carry real business authority.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- How Union Station handles self-serve deployment for internal tools, AI-powered apps, and Slack bots
- The way shared authentication, infrastructure, and governance are wired into the platform
- Examples of the internal workflows already running on Union Station, including onboarding, offboarding, and vendor reviews
- How the team is thinking about request flows, managed runtimes, and MCP-driven app setup
👉 Read C1.ai's post on Union Station and governed app sprawl →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Governed app sprawl is an identity governance problem, not a developer convenience problem. The article shows that internal tools, Slack bots, and AI-powered apps become security assets the moment they touch authentication, ownership, or privileged workflow. When those assets are created outside a governed platform, identity teams lose visibility before they lose control. The practitioner lesson is that app sprawl and identity sprawl are now the same problem.
A few things that frame the scale:
- 28% of secrets incidents now originate outside code repositories, in Slack, Jira, and Confluence, and are 13% more likely to be categorised as critical than code-based leaks, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How should IAM teams evaluate modern IGA platforms?
A: IAM teams should evaluate IGA platforms on governance coverage, evidence quality, and how well they handle different identity types. The key test is whether the platform can support consistent decisions across human access, machine identities, and delegated workflows without creating separate control models for each one.
👉 Read our full editorial: Union Station shows how governed app sprawl becomes an identity platform