Citizen Developers and Org Slop
Non-engineers building agents and automations produce value and sprawl in roughly equal measure; a review board kills the value without stopping the sprawl, and the only governance that scales is a paved road with ownership and retention rules the platform enforces.
A validation run. Researched position, no experiment.
Confidence
60%human-committedExpiry
4doverdue for reviewLead time
—not yet mainstream · opened 14 Apr 2026Ownership
SKSam Kowalczykmonthly cadenceWhere it is
The field came from an observation, not a paper: an inventory of one client tenant found 1,140 user-built agents and flows, 61% with zero runs in ninety days and 14% duplicating another flow. Every productivity-suite vendor now lets any licensed user build an agent from a form, and the research says the median enterprise agent has one user — its author. The first governance reflex is a review board; the one client that ran one cut agent count by 80% and cut the builds people wanted by about the same. Template guardrails — the lab's first hypothesis, now in the graveyard — reduced obvious failures and did nothing to sprawl, because sprawl is a discoverability problem, not a quality problem. What worked in a tried-tier run was boring: an owner field, a last-run time-to-live and auto-archive. Three hundred flows archived, nobody complained. APRA's CPS 230 end-user-computing expectations now reach user-built AI automations, so banks will ask for a control, and the control they reach for first will be the wrong one.
Why a Quantium decision hinges on it
Government and banking clients are arriving with hundreds of user-built agents they did not plan for and a regulator asking about operational risk. The consulting answer they will be sold is a governance framework with a board, and Quantium will be asked to build the register the board reads. The lab's position is that the register is the control: a paved road with ownership, retention and a visible catalogue, and no human gate. It is a cheaper, more defensible answer, and it is the one that keeps the value the citizen builders create. It also bears on the firm's own tenant, which has the same problem at a smaller scale.
Field attributes
Position
What is demonstrated, what is hype, what would have to be true.
The shape every position request answers. Signal-tier fields carry a draft; assessed and tested fields carry a validated one.
- 01Inventory of one government tenant: 1,140 user-built agents and flows; 61% idle for ninety days; 14% duplicates of another flow; 38% with no identifiable owner (Type 2, tried tier).
- 02Platform-enforced retention in the lab's own tenant — owner field, last-run TTL, auto-archive with a one-click restore — archived 300 flows in thirty days with zero restore requests (tried tier).
- 03Template guardrails cut obvious failures (missing error handling, hard-coded credentials) by roughly half and left the idle and duplicate rates unchanged. That thesis is in the graveyard.
- 04The one client review board we have data on reduced agent count by ~80% and reduced approved builds from business units by a comparable share; the sprawl stopped because building stopped.
- 01'Everyone is a developer now.' Everyone is a builder of things with one user, most of which stop running within a quarter.
- 02AI governance frameworks sold as the fix. A framework is a document; sprawl is a platform property.
- 03The opposite hype: 'slop' as a reason to ban citizen building. The value is real; the artefacts just need an owner and an expiry.
- 01A platform-native ownership and retention control on the productivity suites clients actually use; today it is a script the lab wrote against the admin API.
- 02Regulatory acceptance that a registry with enforced ownership satisfies CPS 230 end-user-computing expectations without a human approval gate. Not tested with APRA or an auditor.
- 03A second tenant inventory, ideally in banking, that shows the same idle and duplicate shape; we have one.
- 01Ship r-citizen-dev: paved road, owner, TTL, auto-archive, visible catalogue. No review board unless the regulator names one.
- 02Run a second inventory as a Type 2 in a banking tenant and publish the two side by side; if the shape holds, promote the retention pattern to a Type 3 with a preregistered kill condition.
- 03Ask a Big-four auditor, informally, whether enforced retention meets CPS 230 EUC expectations. Cheap, and it settles the adoption gate.
Signals · 10 in this cluster
What the cluster is made of.
Every item carries its source, tier and sightings. Detector-found signal sits beside human drops; downstream they are indistinguishable except by provenance.

Tenant inventory: 1,140 user-built agents and flows, 61% idle for ninety days, 14% duplicates
One-day Type 2 run over a government tenant's admin API with the client's permission. Counted agents and flows, last-run dates, owner fields and near-duplicate definitions. No preregistration and one tenant, so tried tier; it is the number everyone in the field quotes.
extracted claimMost citizen-built agents in a large tenant are idle within ninety days and a sizeable minority duplicate an existing one.

Logged from Claude Code: added owner, last-run TTL and auto-archive to the lab tenant's agent registry; 300 flows archived, zero restores in 30 days
Product engineer scripted the control against the admin API in an afternoon. Ninety-day idle flows archived with a one-click restore and an email to the owner. Thirty days later nobody had restored anything. One tenant, ours; tried tier.

Survey: two-thirds of large enterprises report duplicated AI agents across business units
Self-reported, 1,200 respondents, no telemetry. Consistent with the inventory but weak on its own; carried as the mainstream awareness marker.

'How our review board cut agent count by 80%' — a bank's platform lead
Case study presented as a success. Read closely: approved builds from business units fell by a similar share and the queue for approval is nine weeks. Disconfirming in that the board worked on sprawl, and confirming in that it worked by stopping building.

APRA CPS 230 FAQ: end-user-computing controls extend to user-built AI automations
FAQ update stating that operational-risk expectations for end-user computing apply to AI agents and automations built outside IT. Does not prescribe a control. Banks will read it as 'board'; we read it as 'register'.

'Slop is a governance failure, not a quality failure'
Argues that the low quality of user-built artefacts is a symptom; the disease is that nobody can find, own or retire them. Proposes catalogue plus expiry as the control. The framing the recommendation adopted.

Shadow automation: usage and lifetime of end-user-built AI agents in 30 enterprises
Telemetry study across thirty tenants. The median user-built agent has one user — its author — and a median active lifetime under seven weeks. Independent confirmation of the inventory's shape at a larger scale.

'We have 900 agents in the tenant and no one knows who owns them. Do we need a review board?'
Asked by a CIO during a data-platform review. The sector owner logged it; the same question arrived from two more agencies within two months. The demand signal that opened the field and framed it around the board reflex.


Productivity-suite vendor lets any licensed user build and share an agent from a form
Agent creation moved from a maker portal to a form in the chat surface, with organisation-wide sharing on by default. The release that turned a maker community into an entire workforce; the tenant inventory dates its sprawl to this month.
extracted claimAgent creation is now a default capability of every licensed user, not a maker-community activity.
Claims · 4 supporting, 1 refuting
The atoms.
A document cannot go stale; an assertion can. Claims are immutable and stamped with the extractor that produced them, so staleness, diffs and the graveyard operate at claim level.
In the enterprise tenants inventoried, most citizen-built agents are idle within ninety days and a sizeable minority duplicate an existing one.
Template guardrails reduce obvious failures but not sprawl, because sprawl is driven by discoverability and ownership, not quality.
Review boards reduce agent count and reduce value roughly in proportion; they gate the builds people want as hard as the ones nobody does.
Platform-enforced retention (owner, last-run TTL, auto-archive) removes the bulk of idle artefacts without a human gate and without complaints.
A human review board is the only control APRA will accept for user-built automations under CPS 230.
Position history · the diff is the product
3 validation runs against a fixed brief. Confidence 40% → 60%.
Guardrail thesis to the graveyard. Retention pattern worked in our tenant; the board case-study shows the value cost. Recommendation published at assessed tier with the second-tenant caveat.
- Template guardrails reduce obvious failures but not sprawl, because sprawl is driven by discoverability and ownership, not quality.
- Platform-enforced retention (owner, last-run TTL, auto-archive) removes the bulk of idle artefacts without a human gate and without complaints.
- Review boards reduce agent count and reduce value roughly in proportion; they gate the builds people want as hard as the ones nobody does.
- c-citizen-developers-org-slop-5 ↓ 0.42 → 0.30
Scoring · ordinal bands
Agents propose. A named human commits.
Uncommitted scores are visibly marked and never leave the building. Bands, not point estimates — false precision is the tell that a number was generated rather than derived.
Impact
committed · SKEvery large tenant has the problem; the cost is diffuse and mostly invisible until an auditor asks.
Timeline
committed · SKThe sprawl exists now; the regulatory question lands with the next CPS 230 review cycle.
Demand
committed · ABThree agencies have asked in the same words: 'do we need a board'.
Cost
agent-estimatedThe retention control is a script against an admin API; an inventory is a day. Agent-estimated.
Cost of being wrong
agent-estimatedRecommending no board to a bank that then fails an EUC finding is a credibility cost, not a catastrophe. Agent-estimated.
Workforce readiness
committed · AWDelivery teams default to a governance-framework deliverable; the platform-control answer is unfamiliar.
Relevance · per vertical
Why it matters here, or explicitly does not.
Ranking is per vertical, not global. Sector owners commit notes against agent drafts.
The inventoried tenant was an agency; the pattern is common across the APS, and records obligations make unowned artefacts a compliance issue as well as a cost.
Mechanism · Inventory, then enforced ownership and retention with an archive that satisfies records requirements.
CPS 230 end-user-computing expectations now reach user-built automations; the bank will be asked for a control and will reach for a board.
Mechanism · Registry with enforced ownership as the control; evidence pack showing idle and duplicate rates before and after.
Woolworths' own tenant has the same shape at store-support and merchandising scale; no regulator, same cost.
Mechanism · Same retention pattern; the catalogue doubles as the discoverability fix. Agent draft.
Clinician-built automations touching patient data raise a privacy question the retention pattern does not answer.
Mechanism · Depends on whether the paved road can enforce data-class restrictions, not just ownership.
Red team · the strongest case against
The strongest case against: 'no review board' is a lab preference dressed as a finding. One tenant inventory and one thirty-day retention run in our own tenant are not evidence about regulated banks. Idle flows cost nothing; the risk in citizen building is the 39% that do run, unowned, against production data, and a TTL does nothing about those. Auditors like boards because boards produce minutes, and no auditor has told us a registry is enough.
- —One tenant, one sector. The 61% idle figure may be an agency artefact; a bank's citizen builders may build fewer, longer-lived, riskier things.
- —Retention addresses the cheap half of the problem. The running, unowned, data-touching flows are the risk and the pattern does not reduce them.
- —Zero complaints in thirty days in the lab's own tenant is not zero complaints in a client's, where the archived flow may be someone's month-end.
- —The graveyard entry on guardrails is thin: one intervention, one quarter, no control group.
Source diversity
- Platform and IT practitioners30%
- Vendor15%
- Regulators15%
- Research10%
- Internal / Engel30%
A field supported by one epistemic community is a flag, not a finding.
Cross-pollination · typed joins
Connected, not merely similar.
Enabling, compounding, substituting, blocking. A satisfied dependency trigger is a far stronger signal than semantic proximity.
The paved-road pattern for engineers and for citizen builders is the same pattern at two depths.
Citizen-built agents running on personal credentials are the risk a TTL cannot fix; scoped delegation is what can.
What citizen builders learn is lost when their flows are archived; a compiled skill wiki is the retention story for knowledge.
Share graph
Provenance running forward.
Discovery, not accountability. No counts, no rankings, no rollups to managers.
Convergence · who else is here
- SKSam Kowalczyk · Research engineer · SDLC1 drop
- ABAisha Bello · Sector owner · Government1 drop
- OGOllie Grant · Product engineer1 drop
- CDClaire Dubois · Sector owner · Banking1 drop
Several people’s drops meet here. An informal working group already exists and probably does not know it.
Lineage
What this field produced, and what it killed.
Experiments, recommendations and graveyard entries stay attached. The reasoning that killed a claim is the reusable asset.
Open questions · return to the pile
Every run leaves a record. Separately, its question either closes or returns to the pile with notes — which is what the next person proposing the same thing will see.
- 01What is the shape of a banking tenant — same idle and duplicate rates, or fewer and riskier flows?
- 02Will an auditor accept enforced retention plus a registry as the CPS 230 EUC control without a board?
- 03What control addresses the running, unowned, data-touching flows that a TTL never sees?