Insights

3 ways IT can get ahead of vibe-coded apps

Your business teams are building apps with AI assistants. Here's how to get those apps running somewhere IT can see them.

Adam White

Editor-in-Chief, Tray.ai

Someone on your finance team built an app last week. They described what they wanted to Claude, and by the end of the afternoon they had a dashboard that pulls from two systems. Their team uses it every day. Now they’re asking IT to host it.

Usually the answer is no, and the app ends up on a laptop or on a personal cloud account with a production key pasted into its config. For why so many vibe-coded apps never reach production, and why the ones that do often ship without an owner, see The deployment gap.

Saying yes doesn’t work either. AI assistants let anyone build an app, but running one still takes an engineering team, and in most companies that’s one platform team.

What changesBefore AI assistantsNow
BuildEngineeringEngineering, Finance, RevOps, Ops, Support, Compliance
RunEngineeringEngineering (unchanged)
Six teams shipping apps. One team that can run them.

Every app still needs hosting, SSO, credentials, logs, cost tracking, and a named owner. Gartner’s Market Guide for Enterprise Vibe Coding Platforms (April 2026) advises engineering leaders to treat the prototype-to-production gap as “a planning constant, not a temporary limitation.”1 These three moves will close it.

1. Stop asking your platform team to host other teams’ apps

Hosting an app means patching its runtime, managing its credentials, answering its pages, and deciding what happens to it when the person who built it leaves. Agree to host five and your platform team is running a hosting service for the rest of the company, with no budget or headcount for it.

So back your platform team when they refuse. Just know that the refusal doesn’t stop the app from running.

Where the app goes when IT says no

A working app on the left with five routes out to the right. The route to proper hosting by IT is dashed and closed because the platform team says no. The other four lead to the builder's laptop, a personal cloud account, a key in a config file and one line on the AI bill.Your working appBuilt, useful, wantedHosted properly by ITPlatform team says noThe builder's laptopUp while the lid is openA personal cloud accountOn someone's card, unseen by ITA key in a config fileProduction access nobody tracksOne line on the AI billNo app, team, or owner attached
The proper route is closed, so the app goes everywhere else.

IT can’t see any of those destinations. When your platform team says no, the builder needs a governed place to deploy instead. That’s the third move.

2. Limit review to risk

The usual response is a review gate, where every app gets approved before it goes live. Review can tell you whether an app is safe to run. It can’t tell you whether the app will be useful.

Call it 1 in 5: a small share of these apps will end up carrying most of the value, and you can’t tell which from a demo.

Keep review to three questions:

  • What data does the app touch?
  • Who can use it?
  • Whose credentials does it run on?

If the answers are acceptable, let it ship and let usage show you which apps matter.

3. Make the governed path the easiest one

Builders use whatever gets their app live fastest. If the governed route means filing a ticket and waiting, they’ll use a personal cloud account. If it takes one command, they’ll use that.

The governed path

  1. BuildIn Claude Code, Codex or Cursor
  2. helix deployOne command from the assistant
  3. Live and governedSSO, an owner, an audit trail
Build where you already build, deploy with one command, and the app arrives governed.

Tray Helix is the governed runtime for AI-built apps. Builders keep using their AI assistant. When the app works, one command deploys it to a managed runtime with a live URL, SSO, role-based access, and a registry entry that names the owner and lists what the app connects to.

Credentials are the part IT should look at most closely. The app calls each connection by an alias, and the real credential stays in the Tray platform, so no key is stored in the code. When a credential changes, you update it in one place, however many apps use it.

How the app reaches your systems

  1. Your appCalls the salesforce alias
  2. Tray auth aliasResolves to the real credential, held centrally in the Tray platform
  3. SalesforceOr any system connected in Tray
The credential never lives in the app. Not in the code, the build, or the builder's laptop.

Helix runs on the Tray AI Orchestration Platform, which already runs production integrations and automations for companies like Cisco, GitHub, DocuSign, and FedEx.

Watch an app go from an AI assistant to live and governed, with an owner, scoped access, and an audit trail from the first run.

How you’ll know it’s working

Look for these signals. New apps show up in the registry with an owner attached, and stop showing up on expense reports. Tools that only ran on someone’s laptop get a URL. Your platform team gets fewer requests to host apps. And when someone asks which apps your teams have shipped, you can answer for everything deployed through the governed path.

Your teams will keep building apps. IT decides where those apps run.

Related reading: The deployment gap: what happens to the software your people build with AI

Footnotes

  1. Gartner, Market Guide for Enterprise Vibe Coding Platforms, C.A. Swan, Manjunath Bhat and Bill Blosen, 27 April 2026, G00844703. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. Back

  • vibe-coded apps
  • deployment
  • credentials

Helix is the governed runtime for AI-built apps

Deploy what your teams build, put SSO in front of it, connect it with managed credentials, and give every app a named owner.

Want to talk to someone first? Contact us