Use case scenarios / Discussion case 01 of 06
Discussion case 01
The prototype everyone now depends on
An advising coordinator vibe-coded a scheduling helper for herself. Eighteen months later, forty advisors use it every day, it reads student records through her credentials, and she leaves the university in two weeks. Nobody else understands how it works.
A hypothetical composite for discussion, not an account of a real institution.
The tension
One viewTurn it off nowIt holds student records through one person’s login, has no owner after she leaves, and was never reviewed. Every day it runs is unmanaged FERPA exposure.
Another viewKeep it running and harden itAdvisors rely on it during registration. Shutting it down pushes them back to spreadsheets and email, which carry their own risks, and punishes the person who solved a real problem.
Questions for discussion
- 01Who owns this tool the day she leaves, and who decides?
- 02Is two weeks enough to move it to a supported platform, or only enough to document it?
- 03What interim controls would make it acceptable for one more term?
- 04How did a personal tool reach forty users without anyone noticing, and what would have caught it?
- 05Should she be thanked, disciplined or both?
What the framework suggests- Audience and data have both moved: the baseline is now at least T4 Institutional.
- Data is Level 3 Confidential, so contracted tools, steward approval and scoped credentials apply.
- Proportionality cuts both ways: an abrupt shutdown has costs the framework counts too.
Where reasonable people disagree- Whether a working tool earns a grace period
- Whether the builder or her manager carries the accountability
- Whether the fix is a platform rebuild or retirement