← All writing

Citizen Development and the New Frontier of Technical Debt

AI app builders have made software creation elastic, but the central services every application consumes—identity, security review, deployment, support, and decommissioning—still scale one application at a time. The debt accruing in that gap belongs on the CIO's balance sheet, and it can be managed without slowing the people who create it.

One Hackathon, One Hundred Thirty-Five Applications

During a single company-wide hackathon, more than 700 employees at the ecommerce technology firm Rokt built 135 functional internal applications in twenty-four hours, many of them without a technical background, using Replit’s AI agent.1 Replit published the episode as a customer success story, and on its own terms it is one. Product managers, operations staff, and customer-facing teams solved their own problems without waiting in an engineering backlog, which is precisely the promise citizen development has made for a decade.

The more interesting question begins on the twenty-fifth hour. Each of those 135 applications needed somewhere to run, a way to authenticate users, credentials to reach whatever data it touched, and someone to call when it broke. None of those requirements were created by the hackathon, and none of them disappeared when it ended. They were simply transferred, quietly and all at once, to the teams that own identity, security, infrastructure, and support.

Multiply that pattern across the market and the scale becomes difficult to ignore. Microsoft reported in July that its Agent 365 control plane had registered nearly 40 million agents across tens of thousands of companies within two months of launch.2 Lovable, which did not exist two years ago, says its users have created more than 60 million projects since November 2024, and that the applications built on its platform now draw 900 million visits a month.3 In other words, the volume of software entering the enterprise has detached from the size of the engineering organization that historically produced it.

135
Internal apps built by Rokt employees in one 24-hour hackathon
~40M
Agents registered in Microsoft Agent 365 within two months of launch
60M+
Projects created on Lovable since November 2024 (company-reported)
30%
Software engineering teams Gartner expects to face material strain from vibe-coded apps by 2028

This article supports citizen development because the people building these applications are, in most cases, solving real problems faster and cheaper than any central team could. However, the economics of their work have shifted in a way that most IT operating models have not yet absorbed, and the resulting liability is accumulating on a balance sheet that the builders never see.

Creation Became Elastic While Operations Stayed Fixed

Technical debt has traditionally described a decision made inside an engineering team: a shortcut taken in code or architecture that would cost more to correct later than to avoid now. The concept assumed that the people creating the debt and the people servicing it worked in the same organization, often on the same team, and that the volume of new software was constrained by the number of engineers available to write it.

AI-assisted app building has broken both assumptions, since creation capacity now scales with headcount across the entire enterprise rather than with the size of the engineering function. Sacra estimates that Replit reached roughly $525 million in annualized revenue in April 2026, with users at 85% of the Fortune 500.4 Lovable, now valued at $13.3 billion, said in late September that it had passed $600 million in annualized run-rate revenue, up from $500 million in June.3 Neither figure is audited, since both companies are private, but the direction is not in dispute.

Fig. 1 — Lovable annualized revenue run rate, November 2025 to August 2026 (company-reported)

Operational capacity, by contrast, has not become elastic at all. Furthermore, the work it performs is largely invisible to the people who create demand for it. An identity team still registers applications, reviews permission grants, and rotates secrets. A security team still reviews data flows, classifies the data each application touches, and approves its egress. A platform team still owns the hosting, the network egress rules, and the patching cadence for every runtime it permits. A service desk still answers the ticket when a departmental app stops loading on Monday morning. Consequently, each of these functions scales roughly with the number of applications in production, and none of them were staffed for an enterprise in which any employee can produce a working application before lunch.

Gartner has begun to quantify where that mismatch leads. In a June 2026 report, analyst Nitish Tyagi predicted that by 2028, 60% of vibe-coded applications will be retired after failing to deliver predictable business value, and that 30% of software engineering teams will experience material capacity strain from maintaining vibe-coded applications built by citizen developers and business users.5 Additionally, a separate Gartner forecast, published in Predicts 2026, goes further, projecting that prompt-to-app approaches adopted by citizen developers will increase software defects by 2,500% by 2028.6 Both are projections, and the second in particular should be treated as a directional warning rather than a measurement. Even so, the two predictions point at the same structural fact: the cost of software has migrated from the act of writing it to the act of keeping it.

The Fixed Cost of Every New Application

The useful way to see this problem is through a central-services lens. Every application that reaches other users consumes a bundle of services from teams that did not build it. Furthermore, the bundle is roughly the same size whether the application took six months or six minutes to create, which is why a collapse in build cost produces an explosion in run cost.

Central functionWhat each new application requiresHow the load scalesWhat accumulates when it is skipped
Identity (IdP)App registration, SSO configuration, service accounts, API tokens, permission grantsPer application and per connectorOrphaned identities and standing credentials that outlive the app
SecurityData classification, review of data flows, vulnerability scanning, egress approvalPer application and per material changeUnreviewed access paths to regulated or sensitive data
Platform and DevOpsHosting, environments, deployment path, dependency patching, monitoringContinuous for the life of the appUnpatched runtimes and dependencies on platforms IT does not operate
Service deskTicket routing, triage knowledge, escalation ownerPer application multiplied by its user baseTickets with no resolver group and no documentation
Data and integrationConnector approval, API quotas, schema-change notificationPer upstream system touchedSilent breakage when an upstream system changes
Finance and procurementSubscription or consumption tracking, cost attributionPer platform and per meterExpense-card spend outside negotiated agreements
DecommissioningCredential revocation, data retention decision, connector removalPer retired applicationRetired apps whose access paths remain live

The table makes one point that the debate over code quality tends to miss. Most of the liability sits outside the code itself. A perfectly written application still requires an identity, a host, a support path, and an eventual retirement, and each of those obligations lands on a team that was never consulted about whether the application should exist. The DORA research program found in 2025 that AI adoption now correlates with higher software delivery throughput but continues to correlate with higher delivery instability, meaning more change failures and more rework.7 That finding was drawn from professional engineering teams with mature pipelines, whereas citizen-built applications typically arrive with no pipeline at all.

Identity offers the clearest illustration of the mechanics. Palo Alto Networks’ 2026 Identity Security Landscape report puts the ratio of machine identities to human identities at 109 to 1, up from 82 to 1 a year earlier, while Veza’s 2026 dataset, using a narrower definition, puts it at 17 to 1.8,9 The spread between those figures reflects differences in methodology, but both datasets point to the same signal. Every citizen-built application that connects to a data source adds service accounts, tokens, or OAuth grants to that population, and the traditional identity lifecycle was designed around human events like hiring, transfer, and termination. An application built in an afternoon has no termination event unless someone creates one.

Spend follows the same pattern in Zylo’s 2026 SaaS Management Index, which drew on more than 40 million licenses and found that large enterprises add an average of 21 applications per month and that spend on AI-native applications rose 393% year over year in organizations with more than 10,000 employees, much of it entering through expense-based purchasing.10 Interestingly, Lovable’s own numbers hint at the same channel. Employees at nearly two-thirds of the Fortune 500 use the product, yet enterprise contracts accounted for only about $20 million of its annualized revenue as of August.3 My interpretation, which the company has not confirmed, is that a large share of enterprise usage still arrives through individual and team subscriptions rather than through agreements that IT negotiated and can see.

Fig. 2 — Illustrative model: cumulative build effort versus cumulative central-service load as application count grows

What the CIO Inherits

For a CIO, the consequence is a category of debt that does not appear in the engineering backlog, the risk register, or the budget. Instead, it surfaces as diffuse operational drag: identity engineers spending sprints on application registrations, security reviewers triaging requests for tools that are already in use, and service desk agents fielding tickets for software no one in IT has ever opened. OutSystems’ 2026 survey of roughly 1,900 IT leaders found that 94% are concerned that AI sprawl is increasing complexity, technical debt, and security risk, while only 12% have implemented a centralized platform to manage it.11 OutSystems sells into this market, which bears on how much weight its survey carries, but the gap between concern and capability is consistent with what Forrester predicted for 2026: three in four technology decision-makers seeing their technical debt rise to moderate or high severity, driven in large part by the pace of AI development.12

The stakes are material even before accounting for AI’s contribution. The Consortium for Information and Software Quality estimated accumulated technical debt in the United States at roughly $1.52 trillion as of its 2022 report, a figure compiled before generative app builders reached the mainstream.13

Fig. 3 — Survey and forecast indicators of the citizen-development operating gap

The strongest counterargument, which comes from citizen development’s own advocates, holds that AI app builders surface demand that already existed. Before those tools arrived, the same business needs were met by spreadsheets with embedded macros, departmental Access databases, and unsanctioned SaaS subscriptions, all of which carried their own unmanaged debt and none of which appeared in any inventory either. On this view, a Lovable or Replit application is an improvement, since it at least runs on a platform with audit logs and a vendor accountable for the runtime. A related argument holds that much of this software is effectively disposable. If Gartner is right that 60% of vibe-coded applications will be retired within two years, the debt liquidates itself, and treating every internal tool as a permanent asset would impose enterprise overhead on work that was never meant to last.

Both points are substantially correct, and an operating model that ignores them will fail by smothering useful work. Nevertheless, neither point dissolves the problem, since the spreadsheet era was bounded by the effort required to build something nontrivial, whereas the current era is bounded by almost nothing. More importantly, disposable applications are rarely disposed of cleanly. When an application is abandoned, its OAuth grants, service accounts, stored data, and connector permissions usually remain in place until someone actively removes them. After all, retirement is itself a central-service event, which is why the same Gartner report that predicts widespread retirement also predicts widespread capacity strain. The debt therefore transfers to whichever team eventually cleans up. (For a related accounting of how AI-generated code moves cost downstream inside engineering teams, see The Second Invoice.)

Every Builder Platform Is Now Selling Governance

The vendors appear to understand this dynamic well, and their product investments are the clearest evidence of where they expect the friction to land. Lovable said in August that its new funding would go toward deeper enterprise integrations, governance, and permissions controls.3 Replit launched a self-serve enterprise tier in May 2026 and has added bulk vulnerability workflows, bulk unpublishing, and software bills of materials to its enterprise security tooling.4 Microsoft built Agent 365 explicitly as a control plane to extend existing identity, security, and management frameworks to agents.2 ServiceNow used its Knowledge 2026 conference in May to announce new governance features and to make its App Engine Management Center, which tests and scans applications before production, free to all customers regardless of license, while Salesforce shipped Agentforce Vibes 2.0 in April with a similar build-anywhere, deploy-here framing.14 The ServiceNow executive behind the decision was candid about the motivation.

“The real enterprise value comes from the actual enterprise-grade controls.”

— Jithin Bhasker, Group Vice President and General Manager, Creator Workflows and App Engine, ServiceNow, May 2026
VendorGovernance investmentRemaining gap for the buyer
Microsoft (Agent 365)Agent registry and control plane tied to existing identity, security, and management toolingRegistry inventories agents but cannot supply maintenance capacity
ServiceNow (AI Control Tower, AEMC)Governance features plus pre-production testing and scanning at no added license costLifecycle management applies to apps deployed onto the Now Platform
Salesforce (Agentforce Vibes 2.0)Build-anywhere, deploy-to-Salesforce model inside existing platform controlsControls are strongest for apps deployed to Salesforce
ReplitSecurity Center, bulk unpublishing, SBOMs, self-serve enterprise tierApps run by default on vendor infrastructure outside IT’s operational tooling
LovableAutomated security scanning; stated investment in permissions and governanceEnterprise contracts remain a small share of revenue, limiting IT visibility

Across the vendors, the pattern is consistent: every platform is investing in inventory, policy, and scanning, which are the controls a vendor can sell. None of them can supply the scarce resource the Gartner prediction actually describes, which is engineering and operations capacity to maintain what gets built. A registry that lists 40 million agents is valuable, and it is also a list of 40 million things that someone, somewhere, will eventually be asked to support. Gartner’s own research agenda reflects the shift, since its April 2026 analysis argued that the future of citizen development is software-engineering-led, and its September guidance focused on supporting and governing low-code development at scale rather than restricting it.15

Consequently, buyers should treat governance features as necessary but insufficient, since a control that makes the debt visible still leaves someone to service it.

Funding the Run Phase Before It Arrives

Therefore, the objective for a CIO is to keep the creation rate high while bringing the run cost under deliberate management. Five practices do most of the work, and none of them require slowing down the people who build.

Measure the denominator. Most organizations track how many citizen developers they have enabled and how many applications those developers have produced. Far fewer track the central-service cost per application in production. Instrument that second number by counting the identity objects, security reviews, support tickets, and platform hours attributable to citizen-built applications each quarter, and report the ratio alongside the adoption metrics. That ratio tells you whether the program is sustainable.

Tier by blast radius. A personal tool used by its creator carries almost no central burden, whereas a departmental application connected to a system of record carries nearly as much as anything engineering ships. Define three or four tiers based on user count, data sensitivity, and connected systems. Personal-tier applications should require nothing beyond platform defaults. However, movement into a higher tier should trigger the central services automatically, including a named owner, a support path, and a security review, instead of relying on the builder to ask for them.

Pave the road so fixed costs are paid once. The most efficient way to absorb per-application overhead is to move it into a shared platform. Pre-approved hosting, identity templates, managed secrets, standard connectors, and default monitoring let each new application inherit the central services rather than request them. In effect, this is platform engineering applied to the citizen population, and it converts a cost that scales with application count into one that scales with platform count.

Make expiry the default. Assign every application below the top tier a review date at creation, typically ninety or one hundred eighty days out. When the date arrives without an owner’s renewal, the platform should disable the application and revoke its credentials automatically. This single control addresses the decommissioning gap that the disposable-software argument overlooks, and it turns Gartner’s predicted 60% retirement rate from an operational burden into a scheduled, low-effort event.

Fund the run phase where the value accrues. Finally, the business unit that benefits from an application should carry its operating cost through showback or chargeback once it crosses a tier threshold. Doing so aligns incentives without forbidding anything, since a team that sees the operating cost of its fourteenth dashboard will often consolidate it with the other thirteen. Pair this with a standing engineering adoption path, so that the applications that prove essential are rebuilt or hardened by professional engineers before they become critical infrastructure by accident.

Software Anyone Can Build Still Needs Someone to Keep

The democratization of software creation ranks among the more valuable things generative AI has delivered to the enterprise, and treating citizen developers as a threat would squander it. Yet every application those developers ship draws on a pool of identity, security, platform, and support capacity that has not grown alongside the creation rate, and the difference between the two is a form of technical debt that no single builder incurs and no single team owns. CIOs who measure that difference, price it, and build platforms that absorb it once will keep the creativity and avoid the reckoning. Those who wait for the debt to appear in an incident report will find that it has been compounding the entire time.


References

  1. Replit, “How Rokt Built 135 Internal Applications in 24 Hours with Replit,” customer story, Replit, accessed October 5, 2026, https://replit.com/customers/rokt.
  2. Microsoft Corporation, “FY26 Fourth Quarter Earnings Conference Call,” transcript, Microsoft Investor Relations, July 29, 2026.
  3. Duncan Riley, “Vibe Coding Startup Lovable Doubles Valuation to $13.3B with $400M Raise,” SiliconANGLE, August 12, 2026. See also Fabian Hedin, remarks at HumanX Amsterdam, September 24, 2026, as reported in Dealroom, “Lovable Passes $600M Annual Run-Rate Revenue at HumanX Amsterdam.” Revenue and usage figures are company-reported; Lovable is privately held.
  4. Sacra, “Replit,” company research profile, Sacra, 2026. Revenue figures are Sacra estimates; Replit is privately held.
  5. Nitish Tyagi, “Govern Vibe Coding for Citizen Developers With Self-Service Platforms,” Gartner, Inc., June 29, 2026, as summarized in Tray.ai, “Gartner Report: Govern Vibe Coding for Citizen Developers With Self-Service Platforms,” September 2, 2026.
  6. Annie Hodgkins et al., “Predicts 2026: AI Potential and Risks Emerge in Software Engineering Technologies,” Gartner, Inc., as excerpted in ArmorCode, “Your GenAI Code Debt Is Coming Due: Here’s What Gartner Predicts,” 2026.
  7. DORA, 2025 State of AI-assisted Software Development (Google Cloud, September 2025); see also InfoQ, “DORA Report Finds AI Is an Amplifier in Software Development, but Trust Remains Low,” September 2025.
  8. ITWeb, “Non-Human Identities Are Outnumbering Humans. Can Your Controls Keep Up?” July 15, 2026, citing Palo Alto Networks, 2026 Identity Security Landscape.
  9. Veza, The State of Identity & Access Report 2026 (Veza, 2026).
  10. Zylo, “Zylo’s 2026 SaaS Management Index Finds AI-Native App Adoption Is Surging, with ChatGPT Now the Most Expensed App,” press release, January 29, 2026.
  11. OutSystems, “Agentic AI Goes Mainstream in the Enterprise, but 94% Raise Concern About Sprawl, OutSystems Research Finds,” press release, April 13, 2026.
  12. Forrester Research, Predictions 2025: Technology and Security (October 2024), as reported in FutureCIO, “CIOs to Triple AIOps Adoption to Fight Rising Technical Debt.”
  13. Herb Krasner, The Cost of Poor Software Quality in the US: A 2022 Report (Consortium for Information & Software Quality, December 6, 2022).
  14. Frederic Lardinois, “Developers Will Use Whatever AI Coding Tool They Want. ServiceNow Is Building for That Reality,” The New Stack, May 6, 2026.
  15. Gartner, Inc., “Analyst Take: The Future of Citizen Development Is Software-Engineering-Led,” April 27, 2026; Gartner, Inc., “How to Support and Govern Low-Code Citizen Development at Scale,” September 11, 2026.