Vibe coding in production: seven institutional systems
Starting in fall 2025, Emerson's IT leadership used Claude to build operational systems that had been too specific, too small or too low-priority to buy or staff. The people building them knew the operations; none of them needed to be programmers.
PAM, a privileged access management system
It started as a few help desk forms and grew into a campus-wide platform covering Wi-Fi, inventory, SSO/MFA, DHCP and more. Security guardrails let student employees handle alumni re-enablement, group membership and name changes, requests that used to wait for senior staff.
GRID, a facilities information system
It brings together buildings, floors and rooms that were scattered across spreadsheets, legacy systems and scanned leases. It has interactive floor plans, weather-normalized utility dashboards, commercial lease tracking and role-based access. A budget system, Zero, and an institutional research data hub followed.
Their repeatable lifecycle
- 01VisionA written development plan: what the system is and isn’t, who it serves, what success looks like. It becomes the "doctrine" fed into every AI session, and major architecture decisions are recorded back into it.
- 02Data architectureSchema first: entities, relationships, authoritative sources, and what the system owns versus what it consumes, before features begin.
- 03FoundationBasic create, read, update and delete operations, authentication and roles, plus one real integration to prove the platform works with live data.
- 04ExperienceInterface and dashboards, iterated quickly on look and feel. This only works because the first three steps gave the AI enough context.
- 05OperationsThe tool goes from viewer to operational system: reminders, cross-cutting analysis, and workflows that generate new data.
Every system is built in a shared, standardized environment with authentication, logging, version control and custom instructions describing Emerson's infrastructure, so a second builder can pick up an unfamiliar project quickly.
What a vibe coder needs
Coding skill isn't on the list. What builders need instead is an IT organization behind them that provides the environment, data standards and security safeguards.
Guardrails and open problems
- Generated code is treated as flawed, then constrained and tested by someone who knows the operation.
- Code is kept in version control, development is separate from production, and review focuses on functional testing, input validation and access checks.
- Builders had to push for encrypted credential storage; the AI's default was to put credentials in the code.
- The authors acknowledge that review and governance can't yet keep up with how fast changes happen, and that AI code review shares the code's blind spots.