Campus AI Development Platforms & enterprise systems

04 — Platforms & enterprise systems · parallel track

The choice isn’t “vibe-code it or wait for IT”

Beside the five-band spectrum runs a second path: building inside platforms the institution already governs. It has different risks, skills and controls than general-purpose coding agents, and for many staff it’s the right one.

Track A

Governed low-code with AI

Platforms such as Microsoft Power Platform and Copilot Studio, ServiceNow App Engine, Salesforce and Appian, where AI now drafts apps, flows and agents from a description. This is the old citizen-developer bargain: build freely, inside a platform IT has vetted.

What it keeps
  • Campus sign-on and platform roles decide who sees what
  • An admin inventory of every app, flow and agent
  • Separate development, test and production environments
Where AI enters
  • Generating apps and flows from plain language
  • Writing formulas, expressions and test data
  • Building agents that act on platform data
Watch
  • Connectors that send data outside approved systems
  • Apps orphaned when their maker leaves
  • Per-user licensing that limits who can participate
Minimum controls
  • Data-loss policies on connectors, set per environment
  • Maker onboarding before access to shared environments
  • Ownership reassigned on departure, reviewed each term
Track B

Configuring and extending enterprise systems

Much campus “development” isn’t new code. It’s Workday, Oracle Fusion, Banner, PeopleSoft, Salesforce and the LMS: configuration, reports, integrations and, increasingly, vendor-native agents.

Where AI enters
  • Generating report queries and calculated fields
  • Drafting integration scripts and configuration
  • Vendor agent builders inside the system
Watch
  • Generated queries that run but return the wrong number
  • Vendor agents acting through broad integration accounts
  • Extensions that break at the next vendor release
  • Vendor AI terms that differ from the main contract
Minimum controls
  • Build in a non-production tenant first
  • Reconcile generated reports against a known figure, with data-steward sign-off
  • Use the vendor’s extension model, never direct database writes
  • Regression-test extensions on every release

How the tracks compare

DimensionCoding spectrum 01–05Governed low-code + AIEnterprise configuration
Who buildsAnyone with a coding toolTrained makers in departmentsFunctional analysts, system admins, vendor partners
Where it runsWherever the builder deploys itInside the platform’s environmentsInside the vendor system or its extension framework
Visible to ITOnly if someone registers itThrough the platform’s admin inventoryThrough configuration audit trails
PermissionsWhatever credentials the builder suppliesInherited from campus identity and platform rolesInherited from security roles; watch integration accounts
What gets reviewedCode, depending on bandThe solution, its connectors and its dataConfiguration changes and report results
Main riskIllegible code nobody ownsConnector sprawl and orphaned appsWrong numbers; breakage at upgrade
Exit pathHarden or rebuildTied to the platformTied to the vendor

When to take the platform track

Choose it when
  • The data already lives in that platform or system
  • The people building can’t maintain code after launch
  • A center of excellence or admin team already governs it
  • The task fits what the platform does well: forms, approvals, workflows, reports
Move to the coding spectrum when
  • The platform can’t express the requirement without workarounds
  • Per-user licensing costs more than building and running it
  • The logic needs version control, tests and code review
  • The tool must outlive a vendor or platform change

Where it meets the spectrum

Platform work still varies in structure. A maker’s quick flow in a personal environment is close to vibe coding, with guardrails. A solution moved through managed environments with review and release pipelines is closer to spec-driven work. The same rule applies: the strictest factor in the chooser sets the controls. For the operating controls both tracks need once agents spread, see governance.

Examples · as of October 2026

Assistant builders in licensed suites

The lightest kind of building: packaging instructions, files and connected apps into a reusable assistant, with no code at all. These sit beside the continuum, not on it, and the same product family can land in several places.

Google

Gemini skills

Usually T1–T2

Reusable custom instructions, with files and connected Workspace apps, invoked in any chat. Gems are being converted to skills: personal accounts from November 2026, Workspace education accounts in June 2027. Google’s transition notice

Raise the tier when a skill draws on confidential files or connected apps. The transition is also a reminder to plan for exits: platforms retire features on their own schedule.

Microsoft

Agents in Copilot Chat

Usually T1–T2

No-code agents built from a description, grounded in chosen SharePoint, Teams or web content and shared with colleagues. Agents respect users’ existing Microsoft 365 permissions. Microsoft’s Agent Builder overview

Raise the tier when grounding content is confidential, or when an agent is shared widely enough that people rely on its answers.

Microsoft

Copilot Studio

T2–T4, by data and actions

Low-code agents with connectors, actions and Power Platform flows that can read and write institutional systems. This is Track A above. Microsoft’s Copilot Studio overview

Registries, token budgets and offboarding apply most here. What the agent can do, not just what it can read, sets the tier.

Oracle

AI Agent Studio for Fusion Applications

Usually T3–T5

Agents and agentic applications built inside Fusion HCM, ERP and related systems, acting on business objects and workflows with Fusion’s security and role-based access. No-code builders sit beside pro-code tooling that works with coding agents. Oracle’s July 2026 announcement

This is enterprise system extension (Track B), not a personal assistant: agents can touch payroll, HR and finance records and take actions. Inherited permissions help, but they don’t replace data-steward sign-off, testing against real cases and a named owner.

For contrast

GitHub Copilot

On the continuum: band 02 or 03

A coding tool, not an assistant builder. Used for suggestions with every line read, it is AI pair programming; used to edit files and run commands, it is agentic coding.

Choose its controls with the chooser, not this track.

Shared assistants need owners. Instructions travel. Gemini skills can be imported from other platforms as SKILL.md files, and Copilot agents can be shared across a tenant. Keep a light inventory of shared assistants, their owners and their data sources. Microsoft 365 admins can review and approve agents in an agent registry.

Account type matters. Features, data terms and retention differ between personal and institutional accounts, and often reach education tenants last. Point builders to the campus account, under contract.

See both tracks in practice, alongside the coding spectrum, in eight scenarios from an IT development team to a student with a course API key.

Use case scenarios →