Campus AI Development Use case scenarios

Use case scenarios Discussion case 03 of 06

Discussion case 03

The shadow tool that works better

A college office built a request-tracking app on a free no-code platform with an AI builder. It is faster and better liked than the official ticketing system. Central IT discovered it during an audit and wants it shut down because it stores student names on an unapproved service.

A hypothetical composite for discussion, not an account of a real institution.

The tension

One viewShut it downIt sits outside every contract, policy and security control. Tolerating it invites every office to do the same.
Another viewLearn from itIt exists because the official system failed its users. Shutting it down without a better alternative sends people further underground.

Questions for discussion

  1. 01Is the problem the tool, the data in it, or the platform it runs on?
  2. 02Could the same app be rebuilt on a governed platform in weeks rather than months?
  3. 03What would IT need to offer so the next office doesn’t build in the shadows?
  4. 04Who should pay for the rebuild?
  5. 05How should the audit finding be written so it improves the official system too?
What the framework suggests
  • The data, not the builder, sets the ceiling: student names make it Level 3.
  • The platform track exists for exactly this case.
  • Over-governing pushes people to personal accounts; the cost of caution is real.
Where reasonable people disagree
  • Whether shadow IT is a compliance failure or a service signal
  • How quickly IT should be expected to offer an alternative
  • Who is accountable for the office’s data