Citizen Development
What Shell’s Citizen Development Program Teaches Enterprises in 2026

TL;DR
- Citizen development helps organizations reduce IT backlogs and modernize workflows by empowering employees to build low-code applications, automations, and AI-enabled solutions.
- Shell’s DIY program shows that success requires more than technology—it depends on strong governance, executive support, practical training, and collaboration with IT.
- Organizations should start with low-risk, measurable use cases, apply risk-based controls, and scale solutions based on security, adoption, and demonstrated business value.
Citizen development has changed dramatically.
What began as a way for business users to build simple applications with low-code and no-code platforms has expanded into a broader enterprise development model. In 2026, employees can use visual development platforms, intelligent automation, generative AI, and AI agents to create increasingly sophisticated solutions without relying exclusively on professional developers.
That opportunity comes with an important warning: making development easier does not automatically make it secure, scalable, or strategically valuable.
Without the right governance, citizen development can produce disconnected applications, duplicated data, uncontrolled AI agents, security vulnerabilities, and a new generation of shadow IT. With the right operating model, however, it can help organizations reduce IT backlogs, improve productivity, modernize workflows, and turn frontline expertise into scalable digital solutions.
Shell’s Do IT Yourself—or DIY—citizen development program remains one of the most valuable enterprise examples. The program demonstrates that successful citizen development is not primarily about purchasing low-code technology. It requires a clear mission, executive sponsorship, structured training, risk-based governance, community support, and continuous measurement.
Here are the most important lessons enterprise leaders can apply in 2026.
What Is Citizen Development?
Citizen development is the practice of enabling employees outside traditional software development roles to create business applications, workflows, automations, dashboards, and AI-enabled solutions using approved low-code or no-code tools.
Citizen developers are typically the people closest to the operational problem. They may work in finance, healthcare operations, construction, logistics, human resources, customer service, procurement, or another business function. They understand where work slows down, where information gets lost, and which repetitive tasks consume employee time.
Low-code platforms allow these employees to help solve those problems through visual interfaces, reusable components, integrations, business rules, and workflow automation.
Citizen development does not eliminate the need for IT. It creates a governed partnership between business teams and technology professionals. Business users contribute process knowledge and rapid experimentation, while IT provides architecture, security, integration, data governance, and lifecycle oversight.
The Project Management Institute describes citizen development as a way for employees to create applications without complete reliance on IT. It also emphasizes that governance and collaboration are necessary to prevent shadow IT.
Why Citizen Development Matters in 2026
Organizations are under pressure to modernize faster, but most IT departments have limited capacity. Technology teams must simultaneously maintain existing systems, secure sensitive data, modernize legacy applications, support integrations, manage AI adoption, and deliver new digital capabilities.
Citizen development expands the organization’s ability to solve operational problems without sending every request into the same development backlog. The business case is especially strong when employees need to:
- Replace spreadsheets, email chains, and paper-based workflows
- Automate repetitive administrative tasks
- Connect information across approved business systems
- Build dashboards that provide real-time operational visibility
- Create mobile applications for field teams
- Standardize approvals, inspections, onboarding, and reporting
- Add governed AI assistance to document-heavy processes
- Test new ideas before investing in enterprise-scale development
The goal is not to turn every employee into a software engineer. The goal is to give qualified business users a safe, supported way to improve the work they understand best.
How Shell Built Its DIY Citizen Development Program
Shell introduced a citizen development initiative called DIY, short for “Do IT Yourself,” using Microsoft Power Platform. The program empowered employees without traditional coding backgrounds to create applications and automations for real business problems.
According to a published Microsoft customer story about Shell, the program grew beyond its initial goal of training 500 citizen developers and reached more than 4,000 active DIY developers by 2023. Shell used several methods to develop and support its citizen development community:
- A dedicated center of excellence
- Embedded coaches and internal champions
- Persona-based learning paths
- Boot camps and hackathons
- Centralized resources and success stories
- Risk-based development guidelines
- Collaboration between business users and professional technology teams
Citizen developers created solutions that improved customer and employee experiences, supported data visualization, automated manual processes, and increased operational efficiency.
One application digitized a lifting and hoisting approval process at Shell’s Monaca facility. The solution reduced approval time by approximately 40%, taking the process from as long as 2.5 hours to about one hour.
Shell’s experience illustrates an important distinction: citizen development becomes valuable at scale only when the organization treats it as an enterprise capability rather than a collection of isolated experiments.
1. Citizen Development Does Not Happen Overnight
A sustainable citizen development program requires planning, testing, refinement, and organizational change. Shell’s program developed over several years. The company did not simply provide employees with a low-code platform and wait for innovation to happen. It established training, support communities, governance practices, leadership alignment, and a center of excellence.
Organizations beginning a program in 2026 should expect to move through several stages:
- Identify suitable business problems and initial participants.
- Establish approved platforms, environments, and data policies.
- Launch a controlled pilot with measurable objectives.
- Train citizen developers and business sponsors.
- Review the pilot for security, usability, adoption, and value.
- Expand successful practices across additional teams.
- Introduce automated monitoring and mature lifecycle controls.
Starting with a pilot gives the organization room to learn without exposing critical systems or sensitive data to unnecessary risk.
2. Begin With a Clear Business Mission
Shell defined the mission of its DIY program as empowering employees to digitize work processes, improve productivity, increase agility, and create more value for customers. A clear mission helps teams understand what citizen development is—and what it is not.
Citizen development should not become an open invitation to build any application with any tool. Every proposed solution should connect to a defined operational goal, such as reducing processing time, improving data accuracy, strengthening compliance, increasing capacity, or delivering a better customer experience.
A useful citizen development mission for 2026 revolves around empowering employees to safely improve business processes using approved low-code, automation, data, and AI capabilities while maintaining enterprise security, governance, and architectural standards. That statement gives innovation and control equal importance.
3. Standardize the Process Before Scaling the Program
A successful application built by one employee does not automatically create a successful enterprise program. Without shared standards, citizen developers may create redundant applications, inconsistent data structures, insecure integrations, and workflows that become difficult to maintain when their original creators change roles.
Organizations need a repeatable development lifecycle that covers:
- Use-case submission and evaluation
- Business ownership
- Data classification
- Security and compliance review
- Architecture and integration requirements
- Testing and user acceptance
- Documentation
- Production deployment
- Performance monitoring
- Maintenance and support
- Application retirement
Standardization does not need to eliminate speed. The review process should be proportional to the risk, complexity, and reach of the solution.
A basic internal workflow tracker should not face the same approval process as an application that uses protected health information, initiates financial transactions, or allows an AI agent to take action across multiple enterprise systems.
4. Use Risk-Based Development Zones
One of the strongest lessons from Shell’s program is the use of development zones based on risk and complexity. A modern version of this model can classify projects into three categories:
Green Zone: Citizen-Led Development
Business users can build and maintain the solution using approved platforms, connectors, templates, and data sources. Green-zone projects may include:
- Departmental task trackers
- Internal request forms
- Basic notifications and approvals
- Non-sensitive dashboards
- Simple workflow automation
- Low-risk AI assistance that does not take autonomous action
Amber Zone: Collaborative Development
Citizen developers can lead the project but must work with IT, security, data, compliance, or professional developers. Amber-zone projects may include:
- Applications used across multiple departments
- Integrations with core business platforms
- Sensitive or regulated business data
- Customer-facing workflows
- AI-generated recommendations
- Automations that update important business records
- Processes that require auditability or human approval
Red Zone: Professional Development
The solution must be designed and controlled by professional technology teams. Red-zone projects may include:
- Safety-critical applications
- High-volume transactional systems
- Financial disbursements
- Clinical decision support
- Infrastructure or identity management
- AI agents with broad access or autonomous authority
- Applications handling highly regulated data
- Processes in which failure could create significant legal, financial, or operational consequences
This approach allows organizations to encourage innovation without treating every application as equally safe.
5. Expand Governance to Include AI Agents
The biggest difference between citizen development then and now is the arrival of generative AI and agentic automation. In 2026, business users may be able to describe an application in natural language, generate workflows, summarize documents, build copilots, or create agents that retrieve information and take actions across connected systems.
This accelerates development, but it also increases the potential impact of mistakes. AI-enabled citizen development governance should address:
- What data an AI model can access
- Whether prompts or data leave the organization’s environment
- Which models and AI services are approved
- What actions an agent is authorized to perform
- When human review is mandatory
- How generated outputs are tested for accuracy
- How hallucinations, bias, and unreliable responses are handled
- Whether agent actions are logged and auditable
- How permissions are revoked when employees change roles
- Who owns, monitors, and maintains each agent
The NIST Generative AI Profile provides a useful foundation for identifying and managing risks throughout the AI lifecycle.
Microsoft’s 2026 Power Platform roadmap similarly emphasizes secure innovation zones, real-time risk assessment, application lifecycle management, audit trails, agent monitoring, and granular controls for data access and external permissions. These capabilities reflect an industry-wide shift from governing applications alone to governing applications, automations, copilots, and agents together.
6. Make Upskilling a Core Part of the Program
Access to a low-code platform does not automatically make someone a capable citizen developer. Employees need more than basic platform training. They must understand how to design reliable processes, work with organizational data, test solutions, document changes, and recognize when a project has exceeded the boundaries of citizen development.
A 2026 training program should cover:
- Process mapping and problem definition
- Low-code application fundamentals
- Workflow and automation design
- Data quality and data modeling
- Integration basics
- Security and privacy requirements
- Responsible AI use
- Prompt and output testing
- Human-in-the-loop controls
- Documentation and change management
- Application lifecycle management
- Accessibility and user experience
- ROI measurement
- Escalation criteria for higher-risk projects
Training should also be role-based. Citizen developers, coaches, business sponsors, IT administrators, security teams, and executive leaders each need different levels of knowledge.
Shell supported its community through formal learning, boot camps, hackathons, embedded coaches, and shared resources. That combination helped employees move beyond theory and apply new skills to operational problems.
7. Build a Community, Not Just a Training Course
One-time training rarely produces a sustainable citizen development program. Citizen developers need somewhere to ask questions, find approved components, receive feedback, share solutions, and learn from other teams. Internal communities also help prevent departments from unknowingly building duplicate applications.
A strong community of practice can include:
- Citizen development coaches
- Office hours with IT and security
- Reusable templates and approved connectors
- Internal discussion channels
- Solution showcases
- Hackathons and innovation events
- Development standards and checklists
- Peer reviews
- A searchable application catalog
- Recognition for high-value solutions
The community should connect business users with professional developers instead of creating two competing groups.
8. Keep IT at the Center of the Operating Model
Citizen development is most effective when it expands IT’s reach rather than bypassing IT. Technology teams should establish the foundation that enables business users to build safely. This includes identity and access management, integration architecture, development environments, deployment pipelines, data policies, monitoring, reusable services, and incident response.
Professional developers can also help citizen developers recognize when a prototype should become an enterprise application. This partnership gives IT more capacity to focus on complex, strategic initiatives while enabling business teams to address lower-risk operational needs faster.
9. Select Tools Based on Enterprise Requirements
The low-code market now includes application development platforms, integration and automation tools, AI assistants, workflow products, process orchestration systems, and specialized agent-building platforms. The best tool is not necessarily the one with the easiest interface. Organizations should evaluate whether the platform can operate safely and reliably within the broader technology environment.
Important evaluation criteria include:
- Integration with existing systems
- API and connector capabilities
- Identity and role-based access controls
- Data residency and privacy controls
- Environment separation
- Audit logging
- Application lifecycle management
- Version control and rollback capabilities
- AI model governance
- Agent permissions and action controls
- Human approval support
- Monitoring and usage analytics
- Scalability and performance
- Vendor stability
- Licensing and consumption costs
- Portability and vendor lock-in
- Accessibility
- Administrative visibility
Approved tools should fit into the organization’s architecture and governance model. Otherwise, citizen development may create more technical debt than it eliminates.
10. Start Small, Measure Results, and Scale What Works
Shell began with a relatively small citizen development initiative before expanding the program across the organization.
A focused pilot remains the best way to begin in 2026. Choose a process that is valuable enough to matter but controlled enough to manage. It should have a clear business owner, measurable baseline, limited integration risk, and employees who are motivated to improve it.
Good pilot use cases include:
- Employee onboarding requests
- Equipment inspections
- Document routing
- Project status reporting
- Internal approvals
- Field service updates
- Compliance evidence collection
- Customer inquiry triage
- Invoice exception management
Once the solution has demonstrated value, the organization can reuse its architecture, governance controls, training materials, and implementation lessons across other teams.
11. Measure Business Value, Not Application Volume
The number of applications created is not a reliable measure of citizen development success. A program that produces hundreds of unused or redundant applications may be less valuable than one that delivers ten well-governed solutions tied to important business outcomes.
Organizations should track metrics such as:
- Hours of manual work eliminated
- Cycle-time reduction
- Cost savings or cost avoidance
- Error-rate reduction
- Increased employee capacity
- Application adoption
- User satisfaction
- Customer experience improvements
- Compliance exceptions
- Automation success and failure rates
- Number of redundant systems retired
- Percentage of applications with active owners
- Security incidents
- AI output accuracy
- Frequency of human intervention
- Ongoing licensing and support costs
Every solution should have a baseline, an expected outcome, and a method for measuring results after deployment. ROI should include more than labor savings. Faster decisions, cleaner data, improved safety, reduced compliance exposure, and better customer experiences can create significant value.
12. Plan for Long-Term Ownership
Citizen-developed applications can become business-critical faster than organizations expect. Employees change positions. Business rules evolve. APIs are updated. Platforms change licensing models. Data grows. AI models and prompts behave differently as surrounding processes change.
Every production solution should therefore have:
- A named business owner
- A technical owner or support path
- Current documentation
- A backup owner
- A review schedule
- Usage and performance monitoring
- A process for managing changes
- A retirement or replacement plan
Lifecycle management prevents useful innovations from becoming unsupported operational risks.
What Are the Biggest Lessons From Shell’s Citizen Development Program?
Shell’s experience shows that enterprise citizen development works when it is treated as a structured organizational capability.
The most important lessons are:
- Establish a clear business mission.
- Begin with controlled, measurable use cases.
- Create risk-based development zones.
- Keep IT, security, legal, and compliance involved.
- Invest in training, coaches, and communities.
- Standardize development and deployment practices.
- Govern AI agents as carefully as applications.
- Measure business outcomes instead of application counts.
- Maintain clear ownership throughout the solution lifecycle.
- Scale proven patterns rather than isolated experiments.
Citizen Development Is Becoming Governed Enterprise Innovation
Citizen development is no longer limited to basic forms and departmental applications. Low-code platforms, enterprise integrations, generative AI, and intelligent agents now allow business users to build solutions with much greater reach.
That makes governance more important—not less.
Shell’s DIY program provides a valuable blueprint for 2026; you need to start with a clear mission, build organizational support, create practical guardrails, train employees, and scale based on demonstrated value.
In 2026, citizen development should not be viewed as a substitute for professional technology teams. It should be part of a connected delivery model in which business users, developers, automation specialists, data teams, security professionals, and AI leaders work together to modernize operations.
How Quandary Helps Organizations Scale Citizen Development
Quandary Consulting Group helps organizations create governed foundations for low-code development, intelligent automation, enterprise integration, and AI-enabled operations.
We work with business and technology leaders to identify high-value use cases, connect fragmented systems, establish governance frameworks, modernize manual workflows, and create secure solutions that can scale beyond an initial pilot.
Whether an organization is launching its first citizen development program or trying to regain control of an existing low-code environment, the objective is the same: empower employees to innovate without sacrificing security, reliability, data integrity, or enterprise visibility.
Additional Resources:
- Citizen developers find creative ways to help Shell run safer, smarter and more efficiently with Power Platform (Microsoft)
- Microsoft Power Platform 2026 release wave 1 plan
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST)
Top FAQs about Citizen Development in 2026
What is a citizen development program?
A citizen development program is a governed enterprise initiative that enables qualified employees outside traditional software development roles to create applications, workflows, automations, dashboards, and AI-assisted solutions using approved low-code or no-code platforms.
What is the difference between citizen development and low-code development?
Low-code development refers to the technology used to create applications with visual components and limited manual coding. Citizen development refers to the organizational practice of enabling business users to use that technology. A citizen development program also includes governance, training, security, ownership, and lifecycle management.
Is citizen development the same as shadow IT?
No. Properly governed citizen development is designed to reduce shadow IT. Shadow IT occurs when employees adopt or build technology without appropriate organizational visibility or approval. Citizen development gives employees an authorized path for innovation within defined security and architectural standards.
Does citizen development replace professional developers?
No. Citizen developers typically focus on lower-risk operational applications and automations. Professional developers remain essential for complex integrations, enterprise architecture, cybersecurity, high-volume systems, regulated workloads, and business-critical applications.
What are the benefits of citizen development?
Citizen development can reduce IT backlogs, accelerate process improvement, automate manual work, increase employee capacity, improve data visibility, and help organizations respond faster to changing business requirements.
What are the risks of citizen development?
Common risks include shadow IT, weak security, poor data quality, duplicated applications, inadequate testing, unsupported solutions, excessive licensing costs, and unclear ownership. AI-enabled solutions can introduce additional risks related to inaccurate outputs, excessive permissions, sensitive data exposure, and autonomous actions.
How should an organization govern citizen developers?
Organizations should use approved platforms, role-based access, risk-based project classifications, data policies, development environments, testing requirements, deployment controls, monitoring, documentation standards, and clearly assigned ownership. Higher-risk solutions should require collaboration with IT, security, legal, or compliance teams.
How does generative AI affect citizen development?
Generative AI makes it easier for employees to create applications, workflows, content, and AI agents through natural-language instructions. It can accelerate development, but it also requires additional controls for data access, output accuracy, agent permissions, human review, auditability, and responsible AI use.
What projects are best for citizen developers?
The best projects are clearly defined, lower-risk processes with measurable outcomes. Examples include internal request forms, approvals, task tracking, inspections, document routing, notifications, reporting dashboards, and repetitive administrative workflows.
How should citizen development ROI be measured?
Citizen development ROI should be measured through business outcomes such as time saved, cycle-time reduction, fewer errors, increased capacity, improved adoption, reduced risk, cost avoidance, and better customer or employee experiences. Organizations should also account for licensing, support, governance, and maintenance costs.











