For the CISO and the CIO

Banning it didn't work.
Fencing it in isn't governing it.

5,600 vibe-coded apps scanned in the wild. Not one had CSRF protection, security headers, or scoped access. Shadow-AI breaches are running roughly $670K over the average cost. The way out isn't a stricter rule — it's making the approved path the one people actually reach for.

Cloud Security Alliance research note, June 2026 (5,600-app scan) · IBM breach data, shadow-AI delta · Retool 2026 governance survey, n=307 CTO/CIO/CISO · Gartner, Market Guide for Enterprise Vibe Coding Platforms, April 2026

Persona · CISO

Shadow AI risk.

Every external system an app is allowed to talk to is written into the spec, approved by the person who owns that system, and then checked twice — once when the app is built, once when it tries to make the call. If it wasn't granted, it doesn't go out.

Approved by the system's owner. Enforced at build and again at send.

Persona · CIO

Governance and platform sprawl.

In Retool's 2026 survey of 307 CTOs, CIOs and CISOs, 93% said they were concerned about vibe-coded internal tools in production; 55% want governance at the platform level, and only 24% have it even at the environment level. We don't ask you to move your stack. We govern what comes out of it, wherever the app was built.

Works across whatever you already run — no migration, no new garden.

Persona · IT Operations

Apps that quietly stop being true.

Governance is usually sold as a way to stop bad things being built. The more common failure is an app that was fine at launch and isn't any more — because the data underneath it moved, or the rule it was checked against changed. Groundwork watches both after launch, names what broke, and refuses to show a number it can no longer stand behind.

Drift is a recorded event with a named owner and a stated blast radius.

Gartner's May 2026 read is that by 2027, more than 65% of engineering teams using automated AI coding will treat the IDE as optional — moving control, governance and validation onto automated platforms. That platform is the thing we are building.

Gartner press release, 20 May 2026

Questions we get

Six conversations that come up in almost every briefing.

01

"We already have Power Apps and Managed Environments."

Power Platform is very good at governing Power Platform: its own apps, its own environments, run by IT. What it can tell you is who touched what. What it can't tell you is whether the number the app is showing agrees with the source system, or whether the app is only talking to the systems it was cleared to. Those are the checks we're adding.

02

"What can your platform see of our data?"

Structure, not values. Our governance and classification surfaces are designed to read field names, types and shapes — never a value, a sample, a range, a distribution or a null rate. Not for us, not for an admin, and not for the data steward who owns the source. Values move only through the engine's granted read path, to people who hold a grant for them. Where we can't compute something without seeing values, we say “not computed” rather than showing you a blank.

A design commitment we'll walk your team through line by line.

03

"You can't trust AI output in production."

That's roughly our starting position. So we don't let the model write the code that ships. The model is only used to work out what the builder is trying to do. From there it's ordinary compiled software built from blocks that have already been reviewed.

04

"This just sounds like another AI builder."

The other tools started with speed and are trying to bolt trust on afterwards. We started with the checks and worked backward to the speed. It's a different architecture, not a different feature set.

05

"My developers and analysts will feel locked in."

The rulebook stops them from shipping things that would fail review anyway. Inside those lines, previews are instant, permissions are quoted up front, and a missing standard block lands in about a week. If it's slower than the workaround, we've already lost.

06

"This sounds like consulting dressed up as a product."

The pack has a rulebook, templates, and a defined path to production — a second customer shouldn't need the rollout the first one did. That said, we haven't proven that at scale yet. We'd rather tell you now than after the contract.

07

"Can't we just build a careful MCP server?"

Probably, and we'll likely speak the protocol ourselves. But MCP is a connection standard — it governs how a model reaches your systems. It has no spec, no versioned artifact, no verdict, no consent step and no receipt. An allowlist of tools is access control, which is the thing everyone already has. MCP standardizes the conversation's reach. We govern the conversation's consequences.

08

"We already govern our data in Unity Catalog."

Then keep it exactly where it is. Unity Catalog governs who may read which tables in your lake. We consume sources it already governs and add the layer it doesn't have: signed meaning for the fields that carry judgment, visibility when they drift, and trust in what gets built on top. Your lake governance stays put; we're the governance for what gets built on it.

Bring your security team

Every briefing comes with a governance appendix. Your CISO will want a copy.

Request a briefing