04 — Platforms & enterprise systems · parallel track
Beside the five-band spectrum runs a second path: building inside platforms the institution already governs. It has different risks, skills and controls than general-purpose coding agents, and for many staff it’s the right one.
Platforms such as Microsoft Power Platform and Copilot Studio, ServiceNow App Engine, Salesforce and Appian, where AI now drafts apps, flows and agents from a description. This is the old citizen-developer bargain: build freely, inside a platform IT has vetted.
Much campus “development” isn’t new code. It’s Workday, Oracle Fusion, Banner, PeopleSoft, Salesforce and the LMS: configuration, reports, integrations and, increasingly, vendor-native agents.
| Dimension | Coding spectrum 01–05 | Governed low-code + AI | Enterprise configuration |
|---|---|---|---|
| Who builds | Anyone with a coding tool | Trained makers in departments | Functional analysts, system admins, vendor partners |
| Where it runs | Wherever the builder deploys it | Inside the platform’s environments | Inside the vendor system or its extension framework |
| Visible to IT | Only if someone registers it | Through the platform’s admin inventory | Through configuration audit trails |
| Permissions | Whatever credentials the builder supplies | Inherited from campus identity and platform roles | Inherited from security roles; watch integration accounts |
| What gets reviewed | Code, depending on band | The solution, its connectors and its data | Configuration changes and report results |
| Main risk | Illegible code nobody owns | Connector sprawl and orphaned apps | Wrong numbers; breakage at upgrade |
| Exit path | Harden or rebuild | Tied to the platform | Tied to the vendor |
Platform work still varies in structure. A maker’s quick flow in a personal environment is close to vibe coding, with guardrails. A solution moved through managed environments with review and release pipelines is closer to spec-driven work. The same rule applies: the strictest factor in the chooser sets the controls. For the operating controls both tracks need once agents spread, see governance.
Examples · as of October 2026
The lightest kind of building: packaging instructions, files and connected apps into a reusable assistant, with no code at all. These sit beside the continuum, not on it, and the same product family can land in several places.
Reusable custom instructions, with files and connected Workspace apps, invoked in any chat. Gems are being converted to skills: personal accounts from November 2026, Workspace education accounts in June 2027. Google’s transition notice
Raise the tier when a skill draws on confidential files or connected apps. The transition is also a reminder to plan for exits: platforms retire features on their own schedule.
No-code agents built from a description, grounded in chosen SharePoint, Teams or web content and shared with colleagues. Agents respect users’ existing Microsoft 365 permissions. Microsoft’s Agent Builder overview
Raise the tier when grounding content is confidential, or when an agent is shared widely enough that people rely on its answers.
Low-code agents with connectors, actions and Power Platform flows that can read and write institutional systems. This is Track A above. Microsoft’s Copilot Studio overview
Registries, token budgets and offboarding apply most here. What the agent can do, not just what it can read, sets the tier.
Agents and agentic applications built inside Fusion HCM, ERP and related systems, acting on business objects and workflows with Fusion’s security and role-based access. No-code builders sit beside pro-code tooling that works with coding agents. Oracle’s July 2026 announcement
This is enterprise system extension (Track B), not a personal assistant: agents can touch payroll, HR and finance records and take actions. Inherited permissions help, but they don’t replace data-steward sign-off, testing against real cases and a named owner.
A coding tool, not an assistant builder. Used for suggestions with every line read, it is AI pair programming; used to edit files and run commands, it is agentic coding.
Choose its controls with the chooser, not this track.
Shared assistants need owners. Instructions travel. Gemini skills can be imported from other platforms as SKILL.md files, and Copilot agents can be shared across a tenant. Keep a light inventory of shared assistants, their owners and their data sources. Microsoft 365 admins can review and approve agents in an agent registry.
Account type matters. Features, data terms and retention differ between personal and institutional accounts, and often reach education tenants last. Point builders to the campus account, under contract.
See both tracks in practice, alongside the coding spectrum, in eight scenarios from an IT development team to a student with a course API key.
Use case scenarios →