Skip to main content

By Errin O'Connor, Founder & Chief AI Architect, EPC Group

Microsoft reports over 33 million monthly active Power Platform users as of early 2026. Most enterprise tenants contain 2,000–8,000 citizen-built apps — the majority untracked and connecting to sensitive data without IT oversight. EPC Group delivers a governance framework that balances enablement with control across Power Apps, Power Automate, and Copilot Studio. Last updated: 2026. Read time: 8 min.

Key Facts

  • Typical Fortune 500 tenant: 2,000–8,000 citizen-developed assets, most ungoverned.
  • EPC Group standard governance engagement runs 6–10 weeks end to end.
  • CoE Starter Kit deployment typically reveals 3–5× more assets than IT expected.
  • EPC Group has completed 10,000+ implementations across Power BI, SharePoint, Azure, and Copilot.
  • Managed Environments are required for all production workloads in regulated industries.

Power Platform Governance for Citizen Developers: The Enterprise Guide

By Errin O'Connor, Founder & Chief AI Architect, EPC Group | Updated April 2026

Citizen development on Microsoft Power Platform is expanding quickly in every Fortune 500 company we support. The main question is not whether we should enable it, but how to govern it effectively. We must also ensure that we maintain the innovation that brings value.

This guide outlines:

  • Environment strategy
  • DLP policies
  • Approval workflows
  • ALM practices

EPC Group uses these strategies for enterprises running Power Platform at scale.

The Citizen Developer Governance Challenge

As of early 2026, Microsoft reports over 33 million monthly active Power Platform users worldwide. In our enterprise clients, we frequently discover that there are 5-10 times more Power Apps and Power Automate flows than IT leaders expected during initial governance audits.

The average Fortune 500 tenant has:

  • 2,000-8,000 citizen-developed assets
  • Most of these assets are untracked
  • Many are ungoverned
  • They connect to sensitive data sources without IT oversight

This is a real risk. We have seen healthcare organizations where Power Automate flows transferred PHI between SharePoint and personal OneDrive accounts. In financial services, Power Apps have exposed customer PII through shared canvas apps. Government agencies have also experienced citizen-built bots connecting to external AI services without a security review. Each of these situations can be avoided with proper governance.

The solution is not to lock down Power Platform — that drives citizen developers to shadow IT tools with zero governance. The solution is a governance framework that balances enablement with control, and that is exactly what EPC Group delivers through our AI Governance practice.

Environment Strategy: The Foundation of Governance

Every Power Platform governance framework begins with environment architecture. Environments are crucial for security, compliance, and lifecycle management. EPC Group suggests a four-tier environment model for enterprise clients:

  • Development
  • Test
  • Staging
  • Production

EPC Group Four-Tier Environment Model

  • Default Environment (locked down): Renamed from the original default. No production workloads. Sharing restricted. Used only for personal productivity exploration with Business connectors only.
  • Sandbox Environments: Per-department or per-project sandboxes for citizen developers to build and test. DLP policies permit broader connector access. Auto-cleanup policies remove inactive resources after 90 days.
  • Shared Development Environment: Managed Environment with solution checker enforcement. Citizen developers promote validated apps here for peer review before production deployment. ALM pipelines configured.
  • Production Environments: Managed Environments with full governance controls. Deployment only via ALM pipelines. Sharing limits enforced. Usage analytics enabled. Quarterly access reviews mandated.

This architecture allows citizen developers to innovate in a sandbox environment. At the same time, it maintains enterprise controls on anything that interacts with production data or supports business-critical processes.

The promotion path includes:

  • Sandbox
  • Shared development
  • Production

This structure creates natural governance checkpoints without causing bureaucratic delays.

Data Loss Prevention (DLP) Policy Architecture

DLP policies are essential for effective governance in the Power Platform. They control which connectors can interact, stopping data leakage where corporate information might reach unauthorized external services. EPC Group creates DLP policies using a layered approach:

  • Identify critical data and services.
  • Define connector communication rules.
  • Implement monitoring and enforcement strategies.

Tenant-Level Base Policy

The tenant-wide policy is designed to be restrictive. It classifies all Microsoft first-party connectors as follows:

  • Business: SharePoint, Outlook, Teams, Dataverse, OneDrive
  • Blocked: Known high-risk connectors like anonymous HTTP and SMTP
  • Non-Business: All other connectors

This approach prevents citizen developers in ungoverned environments from unintentionally connecting corporate data to external services.

Environment-Specific Override Policies

For approved use cases, environment-specific policies take precedence over the tenant policy. This allows for additional connectors.

For example:

  • A marketing department sandbox may allow the LinkedIn and Mailchimp connectors in the Business group.
  • A finance environment may permit the SAP and Workday connectors.

Each override needs a documented business justification and must be reviewed annually.

Connector Action Control

Beyond connector-level classification, DLP policies can now control individual actions within a connector. EPC Group uses this to allow read access to external services while blocking write operations — for example, permitting Power BI data pulls from Salesforce while blocking automated record creation. This granular control is essential for Microsoft Fabric and Power BI integration scenarios where data should flow in one direction only.

Power Apps Approval Workflows

Not every Power App needs IT approval. EPC Group implements a risk-tiered approval framework that matches governance overhead to actual risk:

Risk TierCriteriaApproval RequiredGovernance Controls
Tier 1 — PersonalUsed by maker only, no shared dataNoneDLP policy enforcement only
Tier 2 — TeamShared with <25 users, non-sensitive dataDepartment leadSolution checker, usage tracking
Tier 3 — Department25-500 users or sensitive data connectorsIT governance boardFull ALM, security review, Managed Environment
Tier 4 — Enterprise500+ users, regulated data, external-facingIT + Compliance + SecurityFull ALM, penetration testing, compliance audit

This tiered approach maintains lightweight governance for low-risk scenarios. This applies to 80% of citizen-developed apps. It also ensures strict controls for the 20% that involve sensitive data or critical business processes.

The approval workflows are created in Power Automate. This design fosters a self-governing ecosystem.

Connector Governance Beyond DLP

DLP policies are important, but they are not enough for effective connector governance. EPC Group adds extra controls, including:

  • Custom connector registration policies: All custom connectors need IT review and registration.
  • Connector certification workflows: Internal connectors must pass security testing before they can be used across the tenant.
  • Premium connector budget controls: Power Platform premium licenses are allocated through department chargebacks to avoid uncontrolled cost growth.

We set up restrictions on the HTTP connector to prevent citizen developers from making untracked API integrations. The HTTP with Azure AD connector is permitted only for approved API endpoints. Meanwhile, the generic HTTP connector is blocked at the tenant level.

This setup ensures that all external integrations go through the custom connector registration process, where a security review takes place.

ALM for Citizen Developers

Application Lifecycle Management (ALM) is a critical area where many citizen developer governance programs face challenges. Traditional ALM processes, designed for professional developers, often create barriers. These include:

  • Git branching
  • CI/CD pipelines
  • Code reviews

Such techniques can drive citizen developers back to ungoverned shadow IT.

EPC Group has created a citizen-friendly ALM approach. This method ensures quality controls while honoring the low-code development model:

  • Maintains quality standards
  • Supports low-code development
  • Reduces friction for citizen developers
  • Solution-based development: All citizen-developed assets must exist within solutions from day one. Unmanaged solutions in sandbox, managed exports for promotion. This is enforced through environment settings, not training alone.
  • Pipeline-based deployment: Power Platform Pipelines provide a citizen-friendly deployment experience — select the solution, choose the target environment, click deploy. No Azure DevOps expertise required, but the same traceability and approval gates are enforced.
  • Solution checker gates: Managed Environments enforce solution checker validation before deployment. Critical issues (accessibility violations, deprecated API usage, security anti-patterns) block promotion automatically.
  • Environment variables for configuration: Connection references and environment variables separate configuration from logic, ensuring solutions deploy cleanly across environments without manual reconfiguration.

CoE Starter Kit: Your Governance Foundation

The Microsoft Center of Excellence (CoE) Starter Kit is a free, open-source solution that EPC Group deploys as the foundation of every Power Platform governance engagement. It provides three critical capabilities:

  • Inventory and telemetry: Automated discovery of every app, flow, bot, and custom connector in the tenant. Usage metrics, maker details, and last-modified dates. Most clients are shocked by what the initial inventory reveals.
  • Compliance and governance flows: Automated compliance processes including developer welcome emails, app quarantine for policy violations, inactive app cleanup, and environment request workflows. These flows replace manual governance with automated enforcement.
  • Nurture and adoption: Maker engagement tools including training module assignments, community feeds, and innovation challenges. The governance stick works better when paired with the enablement carrot.

EPC Group enhances the baseline CoE Starter Kit with custom dashboards in Power BI that provide executive-level governance metrics: app growth trends, connector usage patterns, compliance violation rates, and citizen developer adoption curves. These dashboards transform governance from a cost center conversation into a value creation narrative.

Managed Environments Configuration

Managed Environments are Microsoft's solution for the governance gap in Power Platform. They provide advanced governance controls on top of standard environments. These environments are crucial for organizations in regulated industries.

  • EPC Group configures key Managed Environment capabilities for enterprise clients.
  • Sharing limits: Restrict canvas app sharing to security groups rather than the entire organization. Prevents accidental broad exposure of sensitive applications.
  • Solution checker enforcement: Block deployment of solutions containing critical or high-severity issues. Non-negotiable for production environments.
  • Maker welcome content: Custom onboarding that links to governance policies, training resources, and support channels. First-touch governance sets the right expectations.
  • Usage insights: Enhanced analytics showing which apps are actually used, by whom, and how often. Essential for quarterly governance reviews and license optimization.
  • IP firewall: Restrict Dataverse access to approved IP ranges. Critical for healthcare, financial services, and government clients subject to data residency and access control requirements.

Governance Metrics That Matter

EPC Group tracks governance health through a standard set of KPIs that we report to IT leadership quarterly:

  • Governed asset ratio: Percentage of Power Platform assets in governed environments vs. default/ungoverned. Target: 95%+.
  • DLP violation rate: Monthly DLP policy violations per 100 active makers. Target: <5.
  • Citizen developer adoption: Monthly active citizen developers as a percentage of licensed users. Healthy range: 15-30%.
  • App promotion rate: Percentage of sandbox apps that graduate to production through ALM pipelines. Healthy range: 10-20%.
  • Time to production: Average days from app creation to production deployment. Target: <30 days for Tier 2, <60 days for Tier 3.

Frequently Asked Questions

What is Power Platform governance and why does it matter for enterprises?

Power Platform governance is the set of policies, controls, and processes that ensure citizen-developed apps, flows, and bots meet enterprise security, compliance, and quality standards. Without governance, organizations face shadow IT proliferation, data leakage through uncontrolled connectors, and compliance violations that can result in regulatory fines. EPC Group has helped Fortune 500 clients implement governance frameworks that enable innovation while maintaining IT control.

How do DLP policies work in Power Platform?

Data Loss Prevention (DLP) policies in Power Platform classify connectors into Business, Non-Business, and Blocked categories. When a connector is in the Business group, it can only share data with other Business connectors — preventing scenarios where corporate SharePoint data flows to a personal Twitter account. Policies are scoped at the tenant or environment level, and EPC Group recommends a layered approach: a restrictive tenant-wide policy plus permissive environment-specific policies for approved use cases.

What is the CoE Starter Kit and should we deploy it?

The Center of Excellence (CoE) Starter Kit is a free Microsoft solution that provides inventory dashboards, compliance flows, app quarantine capabilities, and maker engagement tools. Yes, every enterprise running Power Platform should deploy it. EPC Group typically deploys the CoE Starter Kit in Phase 1 of any governance engagement because it gives immediate visibility into the apps, flows, and makers already operating in your tenant — often revealing 3-5x more citizen-developed assets than IT expected.

How do Managed Environments differ from standard Power Platform environments?

Managed Environments add enterprise-grade controls on top of standard environments: sharing limits (restrict who canvas apps can be shared with), solution checker enforcement (block solutions with critical issues), maker welcome content, usage insights, and data policies. They require Power Platform premium licensing but are essential for production workloads in regulated industries. EPC Group configures Managed Environments as the default for all client production and shared development environments.

How long does a Power Platform governance implementation take?

EPC Group's standard governance engagement runs 6-10 weeks: 2 weeks for discovery and tenant audit, 2-3 weeks for policy design and environment architecture, 2-3 weeks for CoE Starter Kit deployment and Managed Environments configuration, and 1-2 weeks for maker training and documentation. Clients with existing ungoverned Power Platform estates (1,000+ apps) may need an additional 4 weeks for app remediation and migration into governed environments.

Related Resources

Get Your Power Platform Governance Assessment

EPC Group offers a 2-week Power Platform Governance Assessment. This includes:

  • Tenant audit
  • Policy gap analysis
  • Environment architecture design
  • Prioritized remediation roadmap

Call (888) 381-9725 or schedule online.

Schedule Your Assessment

Ready to get started?

EPC Group has completed over 10,000 implementations across Power BI, Microsoft Fabric, SharePoint, Azure, Microsoft 365, and Copilot. Let's talk about your project.

contact@epcgroup.net(888) 381-9725www.epcgroup.net
Schedule a Free Consultation

Power Platform Governance for Citizen Developers

As of early 2026, Microsoft has more than 33 million monthly active Power Platform users. Most enterprise tenants have between 2,000 and 8,000 citizen-built apps.

Many of these apps are untracked. They connect to sensitive data without IT oversight.

EPC Group provides a governance framework that balances enablement with control across:

  • Power Apps
  • Power Automate
  • Copilot Studio

Last updated: 2026. Read time: 8 min.

Key facts

  • Typical Fortune 500 tenant: 2,000–8,000 citizen-developed assets, most ungoverned.
  • EPC Group standard governance engagement runs 6–10 weeks end to end.
  • CoE Starter Kit deployment typically reveals 3–5× more assets than IT expected.
  • EPC Group has completed 10,000+ implementations across Power BI, SharePoint, Azure, and Copilot.
  • Managed Environments are required for all production workloads in regulated industries.

Why ungoverned Power Platform is a risk

Without proper governance, citizen developers can create security risks. They may transfer PHI between SharePoint and personal OneDrive accounts. They might also expose customer PII through shared canvas apps. Additionally, government agencies have connected citizen-built bots to external AI services without any security review. Each of these situations can be avoided.

Locking down Power Platform is not the answer. This method drives users to shadow IT tools that lack proper governance. We need a framework that makes secure and compliant development easier.

EPC Group four-tier environment model

Every governance framework starts with environment architecture. Environments are the primary boundary for security, compliance, and lifecycle management.

  • Default Environment (restricted) — Renamed from the original default. No production workloads. Business connectors only. Sharing restricted.
  • Sandbox Environments — Per-department or per-project spaces for citizen developers. Broader connector access. Auto-cleanup removes inactive resources after 90 days.
  • Shared Development Environment — Managed Environment with solution checker enforcement. Apps go here for peer review before production.
  • Production Environments — Managed Environments with full governance controls. Deployment via ALM pipelines only. Quarterly access reviews mandated.

DLP policy architecture

DLP policies are the most critical technical control in Power Platform governance. They determine which connectors can share data with each other. EPC Group uses a layered approach.

Tenant-level base policy

The tenant-wide policy classifies all Microsoft first-party connectors as Business. This includes:

  • SharePoint
  • Outlook
  • Teams
  • Dataverse
  • OneDrive

The policy also blocks high-risk connectors, including anonymous HTTP and SMTP.

All other connectors are classified as Non-Business. This policy helps prevent citizen developers from linking corporate data to external services in ungoverned environments.

Environment-specific override policies

For approved use cases, environment-specific policies enable extra connectors. For example:

  • A marketing sandbox might allow LinkedIn and Mailchimp.
  • A finance environment might allow SAP and Workday.

Each override needs a documented business justification and an annual review.

Connector action control

DLP policies can now control specific actions within a connector. EPC Group uses this feature to allow read access to external services while blocking write operations.

  • For example, Power BI can retrieve data from Salesforce.
  • However, it cannot create records automatically.

This control is essential for Microsoft Fabric and Power BI integration scenarios.

Power Apps approval workflows

Not every Power App requires IT approval. EPC Group employs a risk-tiered framework that aligns governance with actual risk. This approach simplifies governance for most low-risk citizen apps.

For the 20% of apps that handle sensitive data or support critical business processes, we apply more rigorous controls. This ensures proper oversight where it is most needed.

Connector governance beyond DLP

DLP alone is not enough. EPC Group adds three layers on top of DLP policies.

  • Custom connector registration — All custom connectors require IT review before use.
  • Connector certification workflows — Internal connectors must pass security testing before tenant-wide availability.
  • Premium connector budget controls — Power Platform premium licenses are allocated through department chargebacks to prevent uncontrolled cost growth.

The generic HTTP connector is blocked at the tenant level. Only approved API endpoints can use the HTTP with Azure AD connector. This process ensures that all external integrations undergo a security review.

ALM for citizen developers

Application Lifecycle Management (ALM) is a key area where governance programs often face challenges. Traditional ALM tools are designed for professional developers, which can create obstacles for others. As a result, citizen developers may turn to shadow IT. To address this, EPC Group uses a citizen-friendly approach to ALM.

  • Solution-based development — All assets must exist within solutions from day one. Enforced through environment settings, not training alone.
  • Pipeline-based deployment — Power Platform Pipelines give a simple deployment experience. No Azure DevOps expertise required — but the same traceability and approval gates apply.
  • Solution checker gates — Managed Environments enforce validation before deployment. Critical issues block promotion automatically.
  • Environment variables — Connection references and environment variables separate configuration from logic so solutions deploy cleanly across environments.

CoE Starter Kit: your governance foundation

The Microsoft Center of Excellence (CoE) Starter Kit is a free, open-source solution. EPC Group deploys it in Phase 1 of every governance engagement. This kit offers three essential capabilities:

  • Improved governance
  • Enhanced insights
  • Streamlined processes
  • Inventory and telemetry — Automated discovery of every app, flow, bot, and custom connector in the tenant. Most clients are surprised by what the first inventory reveals.
  • Compliance and governance flows — Automated processes for developer welcome emails, app quarantine, inactive app cleanup, and environment request workflows. These flows replace manual governance with automated enforcement.
  • Nurture and adoption — Maker engagement tools including training modules, community feeds, and innovation challenges. Governance works better when paired with enablement.

Managed Environments configuration

Managed Environments are Microsoft's answer to the enterprise governance gap in Power Platform. They add premium governance controls to standard environments and are essential for regulated industries.

  • Sharing limits — Restrict canvas app sharing to security groups rather than the entire organization.
  • Solution checker enforcement — Block deployment of solutions with critical or high-severity issues.
  • Maker welcome content — Custom onboarding that links to governance policies and support channels.
  • Usage insights — Enhanced analytics showing which apps are used, by whom, and how often.
  • IP firewall — Restrict Dataverse access to approved IP ranges. Critical for healthcare, financial services, and government.

Governance metrics that matter

EPC Group tracks governance health through a standard set of KPIs reported to IT leadership quarterly.

  • Governed asset ratio — Target: 95%+ of Power Platform assets in governed environments.
  • DLP violation rate — Target: fewer than 5 violations per 100 active makers per month.
  • Citizen developer adoption — Healthy range: 15–30% of licensed users active monthly.
  • App promotion rate — Healthy range: 10–20% of sandbox apps graduate to production.
  • Time to production — Target: under 30 days for Tier 2 apps, under 60 for Tier 3.

Frequently asked questions

What is Power Platform governance?

Power Platform governance is the set of policies, controls, and processes that manage how Power Apps, Power Automate, Power BI, and Power Pages are used across an enterprise.

Without proper governance, organizations risk shadow IT, data leakage from uncontrolled connectors, and regulatory fines. EPC Group has assisted Fortune 500 clients in implementing governance frameworks. These frameworks protect data while allowing creators the freedom to innovate.

How do DLP policies work in Power Platform?

DLP policies classify connectors into Business, Non-Business, and Blocked groups. Business connectors can only share data with other Business connectors.

This prevents the flow of SharePoint data to personal Twitter accounts. EPC Group employs a layered approach to security:

  • A restrictive tenant-wide policy
  • Permissive environment-specific policies for approved use cases

Should we deploy the CoE Starter Kit?

Every enterprise using Power Platform should implement it. EPC Group deploys the CoE Starter Kit in Phase 1 of all governance engagements. This kit offers:

  • Quick visibility into apps
  • Insights into flows
  • Information about makers across the tenant

It often uncovers 3–5 times more citizen-developed assets than IT anticipated.

How do Managed Environments differ from standard environments?

Managed Environments provide enterprise-grade controls. These include:

  • Sharing limits
  • Solution checker enforcement
  • Maker welcome content
  • Usage insights
  • Data policies

They require Power Platform premium licensing. EPC Group sets Managed Environments as the default for all client production and shared development environments.

How long does a governance implementation take?

EPC Group's standard engagement lasts 6–10 weeks. This includes:

  • 2 weeks for discovery and tenant audit
  • 2–3 weeks for policy design and environment architecture
  • 2–3 weeks for CoE Starter Kit and Managed Environments configuration
  • 1–2 weeks for maker training and documentation

Clients with over 1,000 ungoverned apps may require an additional 4 weeks for remediation.

Start your governance assessment

EPC Group offers a 2-week Power Platform Governance Assessment. This assessment includes:

  • Tenant audit
  • Policy gap analysis
  • Environment architecture design
  • Prioritized remediation roadmap

For more information, call (888) 381-9725 or schedule online.

AI assistant — not human