47 Apps Later: How We Empowered Non-Engineering Teams Without Sacrificing Security
What we learned enabling 47 AI-built apps across marketing, support, and customer success—without creating shadow IT
At Stan, we saw the same shift happening everywhere: teams across marketing, customer support, and customer success were using AI to generate working code. They were building real tools—prototypes, dashboards, workflow automation—to solve problems they’d previously need engineering tickets for.
We wanted to enable that. The question was how to do it without creating security blind spots six months later.
We partnered with Lovable Enterprise to close the gap between AI-generated code and safely deployed applications. Not just to let teams build faster, but to maintain visibility and control while they did.
The unlock wasn’t just enabling teams to build apps. It was maintaining security visibility while they did.
The Blind Spot Problem
Here’s what kept me up at night: every AI code generation tool promises to “democratize development,” but almost none of them address what happens after the demo. You get the productivity boost—marketing builds their landing page optimizer, support builds their ticket triage dashboard—but you also get a shadow IT problem on steroids.
Apps built outside engineering pipelines typically lack:
Authentication and access controls
Security scanning and vulnerability management
Visibility into what’s deployed and who owns it
Any path to production-grade maturity
The usual options were either lock it down completely (killing the productivity gains) or let it run wild (creating audit nightmares). We needed a third option.
Why Lovable Enterprise Worked for Us
We evaluated a few platforms, but Lovable Enterprise had features that directly addressed our security concerns:
1. Private by Default, SSO-Protected
Every app created through Lovable could be locked down to Team Lovable members via our existing SSO setup. No public deploys by accident, no access management headaches. If you’re on the team, you can access the tools. If you’re not, you can’t. Simple.
This mattered because our marketing and customer success teams were building workflow tools that touched customer data. “Just make it public for now” was never an acceptable answer.
2. Built-in Security Scanning
Lovable’s integration with Aikido meant every app got automatic security scanning. Not as a nice-to-have feature we’d enable later—it shipped with the platform. Vulnerabilities in dependencies got flagged before they became incidents.
For us as a security team, this was huge. We didn’t need to build scanning infrastructure or convince teams to adopt it. It was just there, doing its job quietly in the background.
3. The Project Dashboard as a Discovery Layer
One unexpected win: Lovable’s project dashboard became our catalog of what existed. Instead of hunting through Slack threads or tribal knowledge, we had a single place showing:
What apps existed
Who built them
What they did
When they were last updated
This sounds basic, but it solved a real problem. When you have 47 applications scattered across teams, discoverability matters. Engineering could see what was being built without being gatekeepers. Other team members could discover existing tools before building duplicates.
4. Security Center: The Single Pane of Glass
The Security Center in Lovable was exactly what we needed. One view showing the security posture of every deployed app:
Which apps had unresolved vulnerabilities
Which dependencies were outdated
Where access controls needed attention
We weren’t flying blind. We had visibility into apps deployed outside traditional engineering oversight, and we could prioritize remediation without blocking teams from shipping.
5. A Graduation Path to Engineering-Owned Infrastructure
Not every AI-built app needs to live forever in its initial form. Some experiments fail. Some become critical and need CI/CD, staging environments, and the full weight of production infrastructure.
We created a new GitHub team specifically for “graduating” Lovable apps. When an app hit a maturity threshold—sustained usage, handling sensitive data, or becoming load-bearing for operations—we could import it into our GitHub org and subject it to our standard deployment pipeline.
This gave teams permission to experiment fast, knowing there was a path forward if their tool became important.
The Results: 47 Apps and Counting
Across marketing, customer support, and customer success, teams have built 47 applications. That’s 47 workflow improvements, internal tools, and experiments that wouldn’t have happened if they required engineering tickets.
Some are small—a form that routes Creator inquiries to the right team. Others are substantial—a dashboard that tracks customer health signals and flags accounts needing outreach.
The important part: none of them are security blind spots.
Every app is access-controlled. Every app is scanned. Every app is discoverable. And the ones that matter can graduate into our core infrastructure when the time comes.
What This Unlocked
The real impact wasn’t just 47 apps. It was the shift in how teams approached problems.
Instead of writing a spec and lobbying engineering for roadmap priority, teams built prototypes. They tested ideas with real users. They iterated based on feedback. The ones that worked stuck around. The ones that didn’t got archived without ceremony.
Engineering wasn’t a bottleneck for experimentation anymore—and we didn’t sacrifice visibility or control to get there.
For security specifically, this model worked because:
We never lost track of what existed
We could assess risk across all deployed apps
We had enforcement mechanisms (SSO, scanning) baked into the platform
We could intervene when something needed to graduate or be sunset
The Takeaway
If your organization is thinking about AI-assisted development for non-engineering teams, the question isn’t just “how do we enable this?” It’s “how do we enable this without creating chaos six months from now?”
Custom-built solutions are one answer—you control every detail, and you can architect exactly the guardrails you need. But building that infrastructure is a project in itself.
Lovable Enterprise was our shortcut to the same outcome: empowered teams, maintained visibility, and a path to maturity for the tools that earned it.
We’re 47 apps in, and I’m not worried about shadow IT. I’m watching our Creator experience improve as teams build the tools they actually need—and I can see exactly what they’re building.
That’s the unlock.


