The first Power App in an organisation is a good news story. Someone close to a painful process builds a fix in a fortnight, the process improves, and IT gets to say yes for once. Nothing about that story needs governance, which is exactly why governance never starts there.
The fortieth app is a different story. By then there are apps nobody remembers building, flows moving data to places the security team has never reviewed, licences accumulating in ways nobody models, and at least one business-critical process running on an app owned by someone who resigned in March. None of it happened through bad intent. It happened because forty reasonable decisions were made with no framework around them.
We get called in at both ends of this curve, and the difference in cost is stark. Setting up governance before the estate grows is a few weeks of work. Retrofitting it across an estate of unowned apps is a project with an archaeology phase.
What actually needs deciding, and when
Environment strategy comes first. The default, where everything lands in one environment, is how sprawl starts. A working structure separates personal productivity, team development and production, with promotion between them as a deliberate step. The moment an app matters to more than its maker, it graduates into managed application lifecycle, with source control and deployment rather than edits in production.
Data loss prevention policies come second, and early, because they are dramatically harder to tighten than to loosen. Deciding which connectors can be used together, and which are blocked outright, is a one-hour conversation before the app count grows. After it grows, every tightening breaks something someone depends on.
Ownership rules come third. Every app has a named owner and a named backup, recorded somewhere that survives the maker leaving. When the answer to "who owns this" is a departed employee's name, the app is already a risk; the rule exists so the question never has that answer.
The centre of excellence, minus the ceremony
Centre of excellence sounds like a committee. In practice, at mid-size, it is two or three people with a clear remit: keep the environment strategy current, review what citizen developers are building, run the graduation path for apps that start to matter, and coach makers so quality rises without IT becoming a bottleneck.
That last point is the one worth defending. The purpose of governance is not to slow makers down. It is to make it safe for them to keep going. The estates that get this right have more citizen development than the ungoverned ones, not less, because IT is no longer afraid of what it cannot see.
Licensing belongs in the same conversation
The other surprise at the fortieth app is the bill. Premium connectors and Dataverse capacity turn apps that were free at pilot into apps with real per-user costs at scale. Modelling licensing against the actual user base is part of governance, not procurement, because the cheapest fix is usually an architectural one made before the app ships.
If your Power Platform estate is somewhere between the first app and the fortieth, this is the moment the discipline is cheap. Our Power Platform practice sets up the environment strategy, the policies and the centre of excellence, and then gets out of the way.
Marcel Rizzolo is Director of Coder Trove.