← All writing

The Sanctioned Sandbox

60% of builders now ship software outside formal IT oversight — measured directly, not discovered after something broke. Blocking access doesn't make that number go to zero, it just makes the same activity invisible. Governance-as-Infrastructure applied somewhere it hasn't been written about yet: not a runtime pipeline, an org chart.

Michael Shatny··9 min read

The Sheepdog, Bred at Home

A farm doesn't need a shepherd riding constant circuits around the flock. A locally-bred sheepdog, trained once, runs the perimeter on its own — cheap to keep, always on, and it scales to a whole flock without anyone supervising every move.

AI-assisted building is the same shift inside a company. The person in finance or operations who used to file a ticket and wait no longer has to. They can breed their own sheepdog — a personal, AI-assisted tool that watches their process and mostly runs itself. The specialist isn't gone. They're just no longer the only one who can produce a working dog.

Two things follow from pushing that further, and they set up everything below. The dog still needs a farm with fences — an untrained dog running loose among the sheep isn't a helper, it's a hazard, and a hundred independently bred dogs with no shared training standard is how a farm loses track of its own flock. And someone still has to design where the fences go. That's not the dog's job, and it isn't really a builder's job either. It's the shepherd's — and that role doesn't disappear when dogs get cheap. It moves from walking the perimeter yourself to deciding where the perimeter is, and making sure every dog on the property was bred to standard.

Shadow IT Gets a Power Upgrade

“Shadow IT” is an old term — any system employees built or adopted without official sanction, because the sanctioned channel was too slow or too rigid. A finance team's forty-tab spreadsheet quietly running part of the budgeting process. A department sharing files through personal Dropbox because the official server was a hassle. The dynamic was never new. What changed is the ceiling of what one motivated, non-technical employee can produce that way. Before AI, shadow IT topped out at how good someone was with a spreadsheet. Now the same person, same incentive, can ship a real web app — real interface, real database, real workflow.

This is the sheepdog analogy in different language: shadow IT is what happens when people start breeding their own dogs because no one gave them one. And in 2026, this stopped being something IT discovers anecdotally after something breaks. It got measured directly. Retool's 2026 Build vs. Buy report, a survey of 817 builders conducted in late 2025, found that 60% had built software outside formal IT oversight in the past year — a quarter of those reporting they do it frequently. 35% had already replaced at least one official SaaS tool with something they built themselves. 78% expect to build more in the year ahead. And the builders doing this aren't who you'd assume: just over a third, 36%, identify as software engineers. The rest span operations, product, data, marketing and sales ops, business analysis, and finance.

Ask why they went around the official channel, and the answers aren't rebellion — they're logistics. Speed was the top reason. Unmet needs, second. IT's process being too slow, third. Nearly two-thirds of the builders in Retool's survey were already senior managers or above — experienced people choosing to move fast over moving officially, not junior staff going rogue.

The categories under the most replacement pressure track exactly what used to belong to spreadsheet-era shadow IT: workflow automations, internal admin tools, BI dashboards, CRMs and form builders, project management tools. Same domain. Expressed as full applications now, instead of spreadsheets.

The Lockdown Reflex

The first, most instinctive response to a number like 60% is defensive: block unsanctioned AI tools at the network level, restrict API access, disable unapproved endpoints. It's an easy lever, and it produces a visible “we did something” result for security, legal, and auditors. It's also a reflex, not a strategy.

It doesn't stop the behavior. It hides it. People work around network restrictions on personal devices, and the organization trades visible-but-ungoverned activity for invisible-and-ungoverned activity — strictly worse from a risk standpoint. That risk isn't hypothetical: a separate Retool survey of 307 CTOs, CIOs, and CISOs, conducted with Wynter in May 2026, found 93% concerned about vibe-coded tools running in production, and a scan of over five thousand publicly exposed vibe-coded apps by Escape.tech in October 2025 found more than two thousand high-impact vulnerabilities and four hundred exposed secrets — API keys and access tokens sitting in public. Shadow AI incidents, when they do surface, average $4.63 million per breach.

None of that gets fixed by blocking access — the apps that already exist stay exposed, and new ones just move somewhere IT can't see them. Lockdown also creates a competitive gap: organizations that allow sanctioned experimentation move faster, and the gap shows up in cost, speed, and output within a couple of quarters. And it drives out the most valuable people. The employees most likely to build things — motivated by genuine excitement, career leverage, portfolio-building — are also the ones with the most exit options. Blocking the sandbox blocks their best behavior along with the risky behavior.

Lockdown is a necessary, understandable first reaction. It's also typically short-lived, once its actual cost becomes visible.

The Sanctioned Sandbox

The counter-move isn't to eliminate citizen building. It's to bring it inside a governed perimeter — the fence around the farm, not a leash on every dog. A real sandbox needs five things: an isolated data layer builders work against, so nobody touches raw production data directly; a small, pre-vetted list of approved tools routed through a gateway that logs usage; automated guardrails — secrets scanning, dependency checks, lightweight security review, applied automatically rather than by a human reading every pull request; a graduation path, so a shadow tool that proves itself can become officially supported quickly instead of getting rebuilt from scratch by an engineer out of mistrust; and enough onboarding that a non-technical builder knows what's safe to touch before they touch it.

None of that is free, and the honest bottlenecks are rarely technical. Most organizations don't actually know where their sensitive data lives well enough to mask it safely — that's usually the long pole, not the tooling. Getting security, legal, and the business aligned is a political negotiation, often slower than any of the engineering work. And keeping the approved tool list current, re-reviewing access monthly, is a permanent operating cost, not a project with an end date.

What IT Becomes

The same logic that turns a SaaS vendor's roadmap into a governance product reshapes an internal IT department from the inside. Platform and governance engineers — the fence-builders, not the dog-breeders — grow in importance. Data governance and access control specialists become more critical, not less, precisely because the people building against company data are less likely to think about classification themselves. A genuinely new function emerges: proactively finding what's already been built outside official channels and deciding what gets sanctioned, hardened, or shut down, before it becomes a headline instead of a fix. And someone has to take a citizen-built tool that quietly became business-critical and make it survive its original builder leaving — proper auth, backups, monitoring, documentation. Unglamorous, and high-value precisely because it's unglamorous.

What shrinks is the traditional request-and-build model — someone files a ticket, IT builds it in six weeks. That erodes as departments increasingly self-serve, and IT's role shifts from builder to reviewer. Classic project management, the Gantt-chart and ticket-queue model, shrinks in its old form too; what replaces it is triage — deciding which shadow-built tools deserve real sponsorship and roadmap investment. And junior developers doing pure implementation are doing exactly the work AI already does well with limited oversight. Fewer get hired. The ones who do get screened for judgment — supervising and correcting AI output — rather than raw coding speed.

The department's value proposition changes shape entirely. It stops being the people who build your software. It becomes the people who make sure everyone else's software doesn't blow up the company.

The Same Move, One More Domain

This is Governance-as-Infrastructure again, applied somewhere it hasn't been written about yet — not a runtime pipeline this time, an org chart. GaI's claim was that governance can move from a review applied after an artifact exists to a constraint set that gates execution before one does. The sanctioned sandbox is the identical move, aimed at headcount instead of code: instead of reviewing shadow tools after they've already touched production data, the perimeter is designed first, and anything built inside it is accounted for by construction.

The individual builder isn't the governance layer, the same way an AI agent was never meant to be. The fence is. Someone still has to design where it goes — that job doesn't disappear when dogs get cheap to breed. It just stops being the same job it used to be.

Related

Michael Shatny is a software developer and methodology engineer and founding contributor to .netTiers (2005–2010), one of the earliest schema-driven code generation frameworks for .NET. His work spans 28 years of the same architectural pattern: structured input, generated output, auditable artifacts. Governance-as-Infrastructure is the latest expression of that instinct — applied here to the question of what an IT department is actually for, once building software is no longer the scarce skill.

ORCID: 0009-0006-2011-3258