Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Low-code and no-code tools can help professional developers and business-side makers deliver applications faster, but they do not remove the organization’s responsibility for security, access control, maintenance, and oversight. Their productivity benefits are plausible and reported in surveys and modeled case studies—not guaranteed results—and the risks depend on the platform, the app, and how the organization governs its use.

What low-code/no-code development changes

Low-code and no-code platforms let people build applications through visual interfaces, configuration, and declarative tools rather than writing every part of an application by hand. The distinction is one of degree: a no-code tool may let a maker assemble an app without writing code, while a low-code platform can also give professional developers ways to extend or integrate applications with code. In practice, the boundary is not uniform across products.

The main change is that more people can participate in application delivery, not that professional development disappears. In a 2025 Forrester Consulting study commissioned by Microsoft, 66% of surveyed developers said most or all of their organization’s custom-development portfolio was still built with pro-code. The survey covered 661 IT decision-makers responsible for development-platform decisions and was fielded in October–November 2024. Read the Forrester report.

What the productivity evidence does—and does not—show

Reported adoption and use cases

In that same Forrester survey, 78% of development leaders said their organization either empowered non-IT employees through a citizen-developer strategy or planned to do so in the next 12 months. Respondents reported complete customer-facing applications as a low-code use case in 38% of cases and core business applications in 34%. Those are survey responses about use cases, not the share of all applications in the market.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reported preferences and outcomes

Among surveyed IT decision-makers, 36% initially preferred a mostly pro-code mix in their ideal development approach, while 30% preferred a mostly low-code mix. The study also records efficiency, code quality, faster development timelines, and enabling employees outside IT to deliver apps among reported drivers and outcomes. Because these are respondent reports rather than results from a controlled experiment, they do not establish that a platform caused a particular productivity gain.

A modeled business case is not a forecast

A Microsoft-commissioned Forrester Total Economic Impact study published in 2024 reported a modeled three-year net present value of USD 93.06 million and ROI of 216%, along with USD 61.4 million in development and IT cost savings, up to 25% time savings per employee, and USD 15.4 million in additional revenue. Forrester based the figures on interviews with seven experienced customers and aggregated them into a composite organization. Treat them as a case-study model, not an expected return for a typical buyer. See the study summary and methodology.

The evidence supports the possibility of faster delivery and improved efficiency, not a universal productivity estimate. The sources cited here do not provide a neutral, head-to-head comparison of platforms or a general calculation of net productivity after training, governance, integration, and ongoing maintenance.

Why faster app creation can raise security risk

Making application creation easier can increase the number of apps and data connections an organization must govern. In its survey, Forrester Consulting recorded security and governance challenges associated with low-code development. These are respondent-reported challenges, not verified incidents across every platform:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Insecure authentication: weak or unsuitable authentication can leave business systems open to unauthorized access.
  • Excessive data exposure: an app may share or surface more data than its maker intended.
  • Unseen component risk: makers may use insecure or outdated components without knowing their status.
  • App sprawl: a high volume of apps can make it difficult to identify what exists, who owns it, and how it is used.

These issues are not unique to low-code. The concern is that a broader pool of makers and a faster release pace can expose gaps in existing identity, data-access, review, and inventory practices. Forrester’s 2020 report summary put the distinction succinctly: “The low-code movement can turn anyone into a developer, but it can’t turn anyone into a security-aware developer.” The line appears in the report summary and is not attributed to a particular speaker. Forrester, “Low-Code Development Requires A Security Rethink”.

How prepared organizations say they are

The October–November 2024 Forrester survey offers a useful counterpoint to adoption enthusiasm: 30% of surveyed IT decision-makers were concerned about a lack of security controls for applications built outside traditional development processes, while only one in three IT leaders felt highly prepared to address the security issues described. These are reported concerns and self-assessed readiness, not audited measures of breach frequency or control effectiveness.

Data governance emerged as one practical priority: 56% of those surveyed considered improving data curation an important way to manage security gaps in data access and management. The report also points to controlling which users can access which data and training citizen developers. Microsoft Learn similarly describes low-code security as requiring both platform-specific features and organizational processes; low-code alone does not eliminate security risk. Microsoft Learn: Assess security posture.

What to evaluate in a platform and governance program

Compare the controls a platform actually offers, how they are licensed, and how your organization will configure and operate them. The categories below are decision criteria, not a claim that every vendor implements them in the same way.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Control area Questions to answer
Data boundaries Can administrators restrict connectors and data flows? Can policies reflect data classification and prevent inappropriate movement between services?
Identity and sharing How are authentication, roles, least-privilege access, and application sharing controlled? Can access be reviewed and revoked?
Visibility Can the organization inventory apps, makers, data connections, owners, and usage? Can it identify unowned or unused assets?
Lifecycle Are there workable processes for review, testing, deployment, change management, support, and retirement?
Operations Are audit trails, monitoring, backup and recovery, and incident-response workflows available and usable?
Adoption model Can makers be onboarded and trained, supported by professional developers, and routed through stronger review when an app has higher impact?

Microsoft describes Power Platform capabilities in areas including data-loss prevention, identity and access management, application lifecycle management, solution checking, telemetry and monitoring, asset inventory, and administration. That is a vendor description of its own control categories; it does not establish comparative superiority or prove that a particular deployment is configured effectively. Check current product documentation, licensing boundaries, and the organization’s configuration before relying on any feature. Microsoft Power Platform security and governance overview.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to scale citizen development without losing control

  1. Set ownership before launch. Assign responsibility for each app, its data connections, access decisions, support, and eventual retirement. An app without a clear owner is difficult to review or maintain.
  2. Classify data and set access boundaries. Decide which data makers may use, which users may see it, and what sharing or connector rules apply. Apply least privilege rather than granting broad access for convenience.
  3. Match review to impact. A small internal workflow and an application that handles sensitive information or serves customers should not automatically follow the same approval path. Define when security, privacy, or professional-development review is required.
  4. Train and support makers. Cover secure handling of data, authentication, sharing, testing, and escalation. Give makers a clear route to ask for help instead of leaving them to infer policy from platform defaults.
  5. Inventory and monitor the portfolio. Track apps, owners, connections, changes, and usage. Use that visibility to find stale, duplicated, exposed, or unowned apps and respond to unusual activity.
  6. Maintain and retire apps deliberately. Include testing and change management in the release process, review components and access over time, and remove apps and permissions when they are no longer needed.

Governance works best when it makes the approved path understandable and proportionate to risk. Controls that are too weak leave data and applications unmanaged; processes that are unnecessarily difficult can discourage makers from using supported channels.

When low-code is a good fit—and when to pause

Low-code/no-code can be a sensible route when the platform fits the application, data access can be bounded, ownership is clear, and the organization can support the app through its lifecycle. It is not a shortcut around architecture, security review, or maintenance. Before choosing the approach, check whether the application’s sensitivity, integrations, reliability needs, and expected audience fit the platform’s real capabilities and your team’s operating model.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.