TL;DR: App visibility, ownership, and offboarding must exist from day one because unmanaged internal apps create identity sprawl as quickly as teams can build them, according to C1.ai.
NHIMG editorial: what this means for NHI practitioners
Questions worth separating out
Q: What breaks when internal apps are built without governed identity from day one?
A: The breakdown is visibility and accountability.
Q: Why do AI-built internal apps create governance risk even when the code is legitimate?
A: Because the problem is not the code alone.
Q: How do security teams know if app secret governance is failing?
A: Look for secrets with unusually long expiry dates, repeated re-creation of credentials, and application records that still authenticate after the original human owner has changed.
Practitioner guidance
- Establish app identity at creation Require every internally built app to have an owner, authentication method, and permissions profile before it can be shared beyond the creator.
- Eliminate shared credentials from internal apps Replace hand-written user lists and shared API keys with scoped credentials issued through governed identity workflows.
- Tie access reviews to application records Make application ownership and sign-in configuration part of the evidence used in recertification and offboarding decisions.
What's in the full announcement
C1.ai's full post covers the operational detail this post intentionally leaves for the source:
- How C1 AppHub packages sign-in, permissions, and credential handling into a self-hosted deployment pattern
- How the skills file instructs an AI coding agent to build and publish a governed application
- How applications appear in the identity graph with ownership, sign-in configuration, and permissions
- How the platform is positioned to support access reviews and offboarding for internally built apps
👉 Read C1.ai's announcement on C1 AppHub and governed internal app deployment →
C1 AppHub: what changes when teams build and govern apps together?
Explore further
View Full Forum → | NHI Foundation Course → | Our Services →
App sprawl is becoming an identity governance problem, not only a development problem. The article describes a world where teams can build and publish internal tools quickly, but speed alone does not create control. When applications are easy to create, the primary risk is that they arrive outside the identity programme and only get noticed after they are already useful to the business. The practitioner conclusion is that app inventory, ownership, and lifecycle coverage have to be designed for build-time, not retrofitted at review time.
A question worth separating out:
Q: Should organisations treat internal apps more like identities than code projects?
A: Yes. If an app can authenticate users, hold credentials, and reach enterprise systems, it behaves like an identity-bearing asset and should be governed that way. That means lifecycle ownership, access review, and offboarding discipline need to apply to the app itself, not just to the people who wrote it.
👉 Read our full editorial: Self-hosted app governance shifts the control point for AI-built apps