Back to Case Studies

Governing AI-Assisted Development

Wrote a development policy, reference guide, documentation checklist, and repo template so people could build with AI under clear rules instead of outside them.

AI GovernancePolicyDocs-as-CodeDeveloper Enablement

The business problem

People across the business were already building scripts, automations, and Power Platform apps with AI assistance. A blanket ban would not have stopped it, and ignoring it meant code touching company systems and data with no review, no record of what data it handled, and no owner to call when it broke.

The choice was to govern that reality or pretend it was not happening. The goal was to make the safe way the easiest way.

Four documents with four jobs

Rather than one long policy nobody finishes reading, the program separates the work:

  • A policy states the requirements. An AI-assisted development policy, companion to the company-wide AI policy, covers sanctioned tools and accounts, source control in the company’s own repositories, review before anything touches company systems or data, and least-privilege access. Where it overlaps the general policy, the stricter rule wins.
  • A guide teaches. A reference handbook walks the whole delivery loop: setup, working with AI-generated code, writing tests, logging and error handling, handling data and secrets safely, third-party packages, authentication, deployment, monitoring, and maintenance.
  • A checklist enforces. One consolidated list defines what every application must have: a README with owner, version, and permissions, a data inventory so exposure and cleanup are never guesswork, a runbook, a changelog, and a decommission checklist. It doubles as the definition of done in code review and when ownership changes hands.
  • A template removes the excuses. A starter repository contains a stub for every required file, so the fastest way to comply is to start from it.

Making the paved road physical

Rules work better with infrastructure behind them. An isolated non-production development tenant lets builders work with broad access safely because it holds no production data. Workstations are baseline-secured, and IT provisions least-privilege production access when something is ready to promote.

A set of short how-to guides gives a first-time builder an ordered ramp, including a first end-to-end script, the GitHub workflow, and how to handle secrets.

Holding IT to the same rules

The policy applies to IT’s own scripts and automations, with no self-exemption. IT’s role is framed as enabler first, with review authority and the ability to pull access when risk demands it. Documentation lives as code, maintained through pull requests, with formatted documents generated for people who do not use the repository.

The result

Builders get a clear, supported way to use AI, and the business gets code with owners, data inventories, and review history. The same pattern of requirements, teaching, checking, and scaffolding works for any organization that wants AI-assisted building without leaving it unmanaged.

Explore more case studies

See how software, automation, and infrastructure address different business needs.

View Case Studies