Are No-Code Platforms Risky Without Enterprise Governance?

A sales manager, tired of waiting weeks for a BT ticket to be resolved, builds a customer tracking application on a free no-code platform in a fortnight. The team is productive, the manager is satisfied. But where exactly is that application storing customer data? Who has access to personal information covered by Turkey’s data protection law, KVKK? What happens when that manager leaves the company? As long as these questions go unanswered, the speed advantage that no-code tools bring to the enterprise simultaneously represents a growing accumulation of risk. By 2019, corporate interest in no-code and low-code platforms across Turkey is rising sharply — yet very little of that interest is accompanied by any serious governance conversation.

No-code platforms allow employees without technical backgrounds to build applications, automate workflows, and create data forms through visual interfaces. Microsoft Power Apps, Google AppSheet, Airtable, and similar tools are among the most visible examples in this category. Their ability to deliver in days what traditional BT queues stretch into months makes them particularly attractive in mid-sized Turkish companies. Most SMEs in Turkey operate with BT teams of two to five people managing infrastructure, software development, and support requests simultaneously. In that context, letting business units build their own solutions appears to relieve pressure on overstretched BT departments. It appears to — but the reality is more complicated than it looks at first.

The real problem is not with no-code tools themselves, but with their spread in the absence of any corporate framework. Shadow IT is not a new concept; companies have known for years that employees install unauthorized software. No-code platforms, however, take this dynamic to an entirely different level: employees are no longer just using a ready-made application — they are building one from scratch. These applications may process customer data, contract details, pricing lists, or employee records. KVKK, which entered into force in April 2018, establishes clear obligations regarding the processing and storage of personal data. Does an application built entirely on a single employee’s initiative satisfy those obligations? In most cases, no — because the question is never asked during the build process.

The second critical risk created by uncontrolled no-code proliferation is business continuity. An employee places a self-built application at the center of daily operations; the team becomes dependent on it. When that employee leaves, the application either becomes inaccessible or turns into a ‘black box’ that nobody else can maintain. In Turkey’s textile, logistics, and food sectors, mid-sized companies are increasingly encountering exactly this scenario. In one Istanbul logistics firm, a vehicle coordination process run entirely through a field coordinator’s self-built tool became inoperable for nearly two weeks after that coordinator resigned. The process was undocumented, access credentials were never handed over, and no backup existed. The result was operational disruption and an emergency BT intervention that could have been avoided entirely.

Recognizing these risks does not justify banning no-code tools. Bans rarely work in practice either; employees find ways around restrictions, and the problem becomes invisible rather than resolved. The right approach is to place democratization within a manageable framework. That framework has three core components: an approved tool catalog, usage standards, and periodic audits. The approved tool catalog is the list of no-code platforms that BT has evaluated and accepted based on corporate security requirements, data residency rules, and licensing terms. Employees choose from this list; tools outside the list cannot connect to corporate networks or data sources. This single step eliminates a large portion of shadow IT risk without blocking productivity. Usage standards define which categories of data may be processed in no-code applications, which integrations require formal approval, and how application ownership is transferred when an employee changes roles or leaves. Periodic audits inventory active no-code applications, identify unused or ownerless tools, and verify KVKK compliance across the portfolio.

For Turkish companies looking to build this framework, the practical starting point is mapping the current state. Which departments are using which tools, and how many applications are currently running? The answer almost always surprises BT teams — the number is consistently higher than expected. Once the map is complete, risk classification follows: which applications process personal data, which ones touch critical business processes, and which provide only internal convenience? This classification determines where audit energy should be concentrated. Applying equal scrutiny to every application is neither practical nor necessary; a risk-based approach allocates limited resources where they matter most.

No-code platforms can become a genuine partner to enterprise BT when placed within the right governance structure. Preserving the speed advantage while meeting data security, business continuity, and legal compliance requirements is achievable — but that balance does not establish itself. For companies to reach it, the role of the BT function must also shift: from a team managing a request queue to an internal advisor that guides business units and sets the standards they work within. That transition is not easy, particularly in resource-constrained SMEs facing real cost pressure in 2019. But no-code tools are clearly here to stay in the corporate environment. The effort required to govern them properly will always be less than the effort required to manage the risks that grow unchecked when governance is absent.

This article was originally written in Turkish by Gökhan MERCANOĞLU on June 10, 2019 and has been automatically translated into English and other languages using machine translation.


When post-erp improvement succeeds, it does not merely put more information on a screen; it gives management clearer decisions. Silos decrease, responsibility becomes visible, and measurable progress starts. Therefore, the issue is not tool selection but rebuilding operating discipline through technology.


Gökhan Mercanoğlu
ERP ve Kurumsal Yazılım