Companies used to buy their software. Now the people who work there are composing it themselves.

With AI, people in every function are building real software shaped to the exact job in front of them. But it is landing on personal accounts and laptops, invisible to the company that now depends on it. Every company is deciding who owns and controls all of it, whether it means to or not.

Contact sales →
Maestra
Security
Deal deskSales · 12 users
Month-end closeFinance · 8 users
Supplier queueProcurement · 5
New-hire checklistHR · 21 users
Metrics boardData · 44 users
Escalation boardSupport · 17
Contract intakeLegal · 6 users
Data flow diagram
AI models
MaestraEvery app your people build, in one governed estate.

A short tour of Maestra’s estate management.

Employees are now building the company’s software.

For most of its history, a company’s software came from outside: packaged products and subscriptions, around fifty of them for a typical mid-sized firm, each one somebody else’s product, licensed and administered by IT. That is what “the company’s software” meant. Things it bought.

That is changing quickly. The people who do the work are building the tools they need themselves, by describing them to an AI agent and getting a working application back. The software a company runs on is shifting from what it buys to what its people make.

This software lives outside the company’s control.

Look at where the built software actually lives today. A weekend project nobody quite finished. A database whose schema was designed by someone learning SQL as they went. A script that only runs on one laptop, on the day the report is due. Each piece tied to whoever happened to build it.

And none of the usual controls apply. The tools built to rein in unsanctioned software assume a vendor on the other end. Here there is no domain to block, no licence to revoke, no vendor to call. It stays invisible until it breaks, and then nobody knows where it runs or what it touches.

Running software is harder than building it.

There is a reason so much of it is half-finished. Building the tool is the easy part now. Everything after it is not.

Once a tool exists it needs somewhere to run, and running it takes a different kind of work: unrelated to the problem the person set out to solve, and often unfamiliar to them entirely. That gap is where things stall, get abandoned, or end up on a personal account held together with tape. Someone still has to do that work. Increasingly it falls to people who never signed up for it, which is how a whole workforce has quietly been drafted into IT.

All this software needs a foundation the company owns.

Software a company depends on has to run on something the company controls. That was always true. It is just that the something used to come from a vendor, or from an engineering team building on infrastructure IT already ran. Workforce-built software has neither. It needs a layer of its own, the same way vendor and engineering software already have one.

The shape of that layer is simple to describe: one foundation every built application runs on, owned and governed from its first line of code. Not a review gate someone has to pass before shipping, since those get skipped or slow everything down. A floor that everything stands on by default.

A shared foundation removes setup work and adds visibility.

For the person building

Sign-in, databases, vector search, hosting, domains, storage, email, and the services other tools need to talk to are already handled. The work is describing the app. The foundation runs it.

For the organization

That same setup is what makes every app arrive already accounted for: identity and access, audit and compliance, isolation and backups, in place from the first line of code. None of it configured by hand, and none of it depending on whoever built the app to have thought about any of it.

Setup, handled
for the person building
  • Sign-in
  • Databases
  • Hosting & CDN
  • Domains & TLS
  • File storage
  • Email delivery
  • A large integration catalog
Everything accounted for
for the organization
Identity & Access
  • Directory SSO / SAMLSAML 2.0
  • Scoped API keys
  • Role-based access
  • Per-person model access
  • Monthly spend limits
Isolation & Data
  • Per-tenant isolation
  • Encryption at rest
  • Data residencyUS · EU · CA · AU
  • Encrypted backups
Audit & Compliance
  • Append-only audit trailOCSF
  • Security assessment
  • Pre-filled questionnaire
  • Evidence packet
  • GDPR terms
Observability
  • Live logs
  • Error tracking
  • Performance metrics
  • Instant rollback
One foundation · owned from the first line of code

The result is a software estate the company owns.

Put every app on one foundation, each with a score describing what it does and why, and the scatter becomes something the company can hold. A landfill of half-known projects turns into an estate it can see across at a glance, with every app accounted for and every owner named.

It applies to what already exists, too. An app exported from a coding agent, a site built on a hosted playground, a folder of files running off one laptop: none of it needs a migration project to join the estate. It just needs a real place to run, a sign-in through the company directory, an audit trail, and a score describing what it does.

Available to your security team

  • Security review packet
  • DPA GDPR
  • Pen-test summary on request
See how we handle security →
Contact sales →