As quoted from Shakespeare's Hamlet "Vibe-Coded Apps... to block or not to block, that is the question..."
(well close enough.. )
Every CIO has the same question on their mind right now: How do I govern and secure vibe coded apps.
Good question.
I was stalking in the CIO and CISO subreddits, and seeing this same question asked over and over, and the most common answer was “you cannot, so just ban their use”.. the second most common answer was “they are terrible quality apps, so just force the business to use your development team to build proper apps”.. and I thought these were really interesting answers.
Why?
Well, blocking/banning something never works.. it never has, and it never will. People are people, and when we want something, we find a way, and will work around whatever hurdles are put in our way. Also, banning the use of vibe coded apps is the fastest way to employee frustration. If there are employees in your enterprise that are frustrated enough by a common daily problem they face, that they will willingly go out and try to build a fix for that, you should be delighted, and actively encourage that. And if you don’t, their frustration will likely result in them fixing problems for another enterprise.
Second, forcing every business problem via a development team is something we have been doing forever, and you know what that results in? “Please write a business case for this, so we can justify the investment in people to go build the app”.. problem is this is the classic “chicken or the egg” game.. how can the business person justify the investment if they dont know whats required to solve the problem? They cannot, so they dont even bother. Isnt it better to let them solve the problem themselves, understand the gains that the solved problem has realized, and then write a business case explaining what they created, the benefits to the business, and why they would now like it handed over to engineering? That is exactly what Vibe-Coded apps allows the business to do...
So what is the right* answer ?
It seems obvious really, and brings back full circle to the question being asked. Give the business users a secure, governed way to deploy (internally) the apps they vibe code, on a platform IT controls and can observe. Now let me be crystal clear here, as the word “controls” does not mean gated; it means IT gives the users a place that the vibe-coded app can run, where you can see it, scope what it is allowed to reach, and who can reach it. It gives you the ability to scan the app (and its code) for vulnerabilities, to inspect its network traffic (to make sure no nefarious activities are occurring), but generally, do all of this in the background, without getting in the way of the business user. ie deliver this in a 100% self-service platform for your business users.
Also, its worth being pretty upfront that there is no expectation that vibe-coded apps are “forever” apps. These really should be treated as POC’s, and that after a period of time, they are either proven awesome (and therefore can justify being productionized), or rubbish (and therefore deleted). I dont think anyone, anywhere believes that vibe-coded apps are full production ready.
Should you block vibe-coded apps, or not? I argue no, and assuming you go with my argument, you then need a way to allow business users to self-serve the deployment of their vibe-coded apps, and that really really should be on a system you own and govern.
Now the sales pitch :) This is why I created Portainer-Run (portainer.ai)... so if you are one of the CIO’s faced with this exact question, give Portainer.ai a read, you may be surprised what you can do.
