The business problem
People across the business were already building scripts, automations, and Power Platform apps with AI assistance. A blanket ban would not have stopped it, and ignoring it meant code touching company systems and data with no review, no record of what data it handled, and no owner to call when it broke.
The choice was to govern that reality or pretend it was not happening. The goal was to make the safe way the easiest way.
Four documents with four jobs
Rather than one long policy nobody finishes reading, the program separates the work:
- A policy states the requirements. An AI-assisted development policy, companion to the company-wide AI policy, covers sanctioned tools and accounts, source control in the company’s own repositories, review before anything touches company systems or data, and least-privilege access. Where it overlaps the general policy, the stricter rule wins.
- A guide teaches. A reference handbook walks the whole delivery loop: setup, working with AI-generated code, writing tests, logging and error handling, handling data and secrets safely, third-party packages, authentication, deployment, monitoring, and maintenance.
- A checklist enforces. One consolidated list defines what every application must have: a README with owner, version, and permissions, a data inventory so exposure and cleanup are never guesswork, a runbook, a changelog, and a decommission checklist. It doubles as the definition of done in code review and when ownership changes hands.
- A template removes the excuses. A starter repository contains a stub for every required file, so the fastest way to comply is to start from it.
Making the paved road physical
Rules work better with infrastructure behind them. An isolated non-production development tenant lets builders work with broad access safely because it holds no production data. Workstations are baseline-secured, and IT provisions least-privilege production access when something is ready to promote.
A set of short how-to guides gives a first-time builder an ordered ramp, including a first end-to-end script, the GitHub workflow, and how to handle secrets.
Holding IT to the same rules
The policy applies to IT’s own scripts and automations, with no self-exemption. IT’s role is framed as enabler first, with review authority and the ability to pull access when risk demands it. Documentation lives as code, maintained through pull requests, with formatted documents generated for people who do not use the repository.
The result
Builders get a clear, supported way to use AI, and the business gets code with owners, data inventories, and review history. The same pattern of requirements, teaching, checking, and scaffolding works for any organization that wants AI-assisted building without leaving it unmanaged.