← All posts Perspective

Purpose-Built Beats Half-Built

Purpose-Built Beats Half-Built

At a previous job, somewhere around 2021, our vacation approvals ran through a Power Automate flow that a colleague in controlling had built on a quiet Friday afternoon. It worked for two years. Then she left the company, IT disabled her account, and approvals quietly stopped. The flow had been running under her login the whole time. We found out when three people came back from holiday and their requests were still sitting in a queue that no longer existed.

Everyone has a version of this story. The Retool app only one developer dares to touch. The Airtable base that quietly became the real CRM. The SharePoint list with fourteen calculated columns that somehow runs onboarding.

This is what "business users building their own tools" turned out to mean in practice: software with all the responsibilities of software and none of the foundation.

The pitch was right, to be fair

The diagnosis behind low-code was correct, and I want to say that clearly before criticizing it. IT backlogs are measured in quarters. The people who understand a process best are the ones living inside it. Waiting six months for a developer to build a form is absurd.

The market certainly believed it. Gartner put low-code at 26.9 billion dollars in 2023, growing almost 20% a year. Power Apps, Retool, Mendix, OutSystems, and a few hundred more. By that logic, internal software should be a solved problem by now.

I believed it too. I recommended Power Apps to more than one team, with some confidence. What I got wrong was where the work actually sits.

The work doesn't disappear, it moves

Buy a low-code platform and what you own is a canvas. The data model is still your job. Permissions are still your job, per app, in each tool's own dialect. What happens when a record gets deleted, also your job. Low-code moved that work away from developers and handed it to whoever had a free Friday, without version control, without review, and without anyone knowing about it until something breaks.

Then there is the pricing. Read Microsoft's own page on Power Automate licensing once: user licenses, capacity licenses, Process licenses stackable up to ten per flow, premium connectors gated by tier. I have sat in a meeting where working out whether a flow was worth building took longer than building it, because nobody could figure out what it would cost. (The connector we needed was premium. Of course it was.)

One honest exception: if you have developers and your data lives in databases you run, Retool is genuinely good, and we say so in our comparison. But then developers are building the internal tools again, which is the exact situation low-code promised to end.

Now the same promise, with AI writing the code

The new version of the pitch is Lovable, Bolt, v0. Describe your app, watch real code appear, click deploy. As a demo it is spectacular, and for a prototype or a landing page I would use these tools without thinking twice.

Enterprise software fails somewhere the demo never goes. The visible part of an internal tool, the form and the table and the button, is maybe a tenth of it. The other nine tenths never make it into a screenshot: who may see which records, what gets logged, what happens to the data of someone who leaves, where it is hosted and under which law.

Last year this stopped being theoretical. A security researcher found over 170 production apps built with Lovable leaking user data, names, emails, API keys, even payment records, because the generated backends shipped without row-level security. It became CVE-2025-48757, severity 9.3 out of 10.

I'm not bringing that up to dunk on Lovable. The problem sits in the build principle. When every app is a freshly generated codebase, security is also freshly generated, every time, by a model whose goal is to make your demo work. Sometimes it gets it right. "Sometimes" is not a security model for the system holding your customer data, and I'll defend that opinion precisely because I sell AI-built software myself.

What purpose-built means now

Purpose-built used to mean an agency, a six-figure quote and a maintenance contract. For a vacation approval app that was never going to happen, and that gap is exactly where low-code grew.

Cordango starts from the other end. The foundation, identity, roles and permissions, audit log, EU hosting, exists before the first app and is shared by every app that follows. You describe the tool you need, answer a few questions, and the app is generated onto that foundation. The generator cannot forget the security layer because the generator never touches it. And when something is genuinely too complex to generate, our team builds it custom on the same core, as part of the product, not as a consulting detour.

My colleague from controlling was the right person to create that approvals app, by the way. She knew the process better than IT ever would. She just should never have ended up responsible for its authentication.

A small test

Find the one flow or app in your company that only one person understands. Ask what happens on the day that person's account is disabled. If the answer takes more than a sentence, that is the app to bring along. Book a demo and we'll rebuild it in front of you, foundation included.

See Cordango in your own company

The fastest way to understand it is to watch it stand up a company and add an app live.

Book a demo →