A blueprint for securing the internal apps built by everyone on your team.
By Russell Haering and Will Bengtson
People in marketing, finance, and operations are shipping apps inside your company right now with a coding agent in one afternoon. The organizations that win will let everyone build and give every app an identity, scoped credentials, and an off switch from the moment it exists.
Drawing on a year of rebuilding how C1.ai builds and operates internal tools, VP of Engineering Russell Haering and CISO Will Bengtson lay out what the road must provide, which parts are mature, which remain unsolved, and how security reaches a builder who has never heard of authorization.

Identity, authorization, deployment, credentials, data access, and maintenance. What the road provides, what the app owes in return, and where each one stands today.
The three groups of responsibilities that disappeared when everyone started being a builder, and the different treatment each one demands.
Why spend attribution, evidence, revocation, and teardown all depend on a single identity issued the moment an app is created.
An honest accounting of the limits: model behavior that shifts without a deploy, apps already running off-road, information flow, and ownership decay.
2.6x
more likely to be low performers when changes require formal external approval
6
capabilities every new internal app needs from the road
3
groups of responsibilities: dropped, orphaned, and new, each with its own fix
1
identifier, issued at creation, that connects the whole system

Russell Haering, VP of Engineering
Russell Haering is VP of Engineering at C1.ai, where he leads the engineering behind the internal paved road the whole company ships on. He previously co-founded ScaleFT, the security infrastructure company acquired by Okta, and went on to hold an engineering leadership position at Okta.

Will Bengtson, CISO
Will Bengtson is CISO at C1.ai, where he secures the apps the whole company builds on its internal paved road. He has spent more than two decades securing cloud platforms, identity systems, and developer infrastructure, most recently at HashiCorp and before that at Netflix, Capital One, and Nuna.