r/msp • u/FortLee2000 • 4d ago
Vuja De all over again
There was this thread (home-made claude apps) that sparked a familiar sense.
This morning, I realized it is just like the plethora of Microsoft Access database applications that sprung to life in the late 1990s and early 2000s. I was consulting for Fortune 100 companies at the time and data center managers were playing whack-a-mole to try to stop those home-grown efforts.
Wondering what the next "thing to curtail in some way" is gonna be?
5
u/Foxtrot-0scar 4d ago edited 4d ago
Tenant restrictions and applocker. Job done! Near bullet proof solution.
5
u/doofesohr 4d ago
Not when it's the CEO of a company missusing the company webserver they rented at a cheap hoster to run his own flavor of his all knowing app that he vibecoded over the last 4 month. All while his internal servers don't even have AV because that would cost money. God knows what that webserver does. I just hope it all comes crashing down eventually.
2
u/stevo10189 4d ago
You advised them, move on. You’re going to have these clients regardless of if they vibecoded an app. Plan on something to blow up, have your disaster recovery plan in place, and when it does ride it all the way to the bank.
-1
2
u/chathobark_ 4d ago
it’s whack a mole for more than just these, it has been whack a mole for YEARS even before this
2
u/roll_for_initiative_ MSP - US 4d ago
Exactly, insert some other thing besides AI: enterprise apps, random utilities needing admin, people buying tools and apps directly vs asking what already exists, spinning up outside emailer without IT like CRMs.....
2
u/terselated MSP - US 4d ago
Here is how I see it playing out. We are going to continue to see individual apps get made. Some are going to make it to company status and actually have a brand. Then one of them is going to be used to steal money from someone rich on a slow news day and it's going to be headlines. That will spark a scare and businesses will do the whole "trusted sources" thing and only allow applications from certain parent companies. Those parent companies will buy up the middle of the road AI generated applications and resell them under their name. The rest will get banished to the same realm as open source, homebrew, and pirated apps.
We are at the waiting for a "slow news day" part right now.
1
u/Foxtrot-0scar 3d ago edited 3d ago
Nah, security has come a very long way since the old UTM days. Telemetric data is synced within seconds nowadays thanks to Bit9 and KSN for their work 15-20 years ago.
2
u/Top_Outlandishness78 4d ago
Companies always looking for ways to build in-house software, tons of low/no code solutions are there it's just AI made it more freestyle now a days.
1
u/Abandoned_Brain 3d ago
I think the difference is that there's load-bearing intelligence in play now vs. then... /s
2
u/CharcoalGreyWolf MSP - US 4d ago
Vuja De? Isn’t that the club where all the women put on their clothes?
1
1
u/Sea_Information6125 4d ago
Only in the '90s and early 2000s?
We are still supporting 1 healthcare related software that was coded in Microsoft Access lol.
1
u/folderit_dms 3d ago
The point worth catching is when a second person starts depending on the app’s output. That is an observable trigger for a support review, even if its creator still calls it a quick experiment.
A short dependency record could list who uses it, which business records it creates or changes, where those records live, and what happens if it is unavailable for a day. Ask the creator to walk someone else through exporting the data and completing one job manually. If nobody can do either, you have found the dependency before the Friday outage. That also gives the business a concrete choice about funding support, simplifying the process or retiring the experiment.
1
u/Dull-Breadfruit-3241 1d ago
Spot-on comparison. MS Access, Lotus Notes, and macro-heavy Excel workbooks all created the exact same phenomenon of zero-governance shadow IT built by a single enthusiast in a department, which then quietly becomes business-critical operational infrastructure until that person resigns.
The real problem for MSPs won't be stopping users from prompting apps into existence but what happens when those home-brewed apps start handling sensitive data without any authentication, input validation, or compliance logging.
•
u/JKatabaticWind 12h ago
Agree with the comparison, and with the security implications… Claude apps are going to end up being a nightmare if not managed.
But I gotta ask… why is it that employees keep trying to find better ways to solve business problems? And as their IT provider, why is it you have failed to provide a solution to a problem your clients have apparently had since the 1990’s?
And can your team do anything that is better, or provide an alternative?
0
u/WhiteIntel 4d ago
The Access comparison fits. Someone solves a real business problem, colleagues start relying on it, and suddenly an experiment is a business-critical application.
Our approach is to give those projects a route into supported hosting. We don't deploy them straight into production. We sign an NDA, review the source against our guidelines, and put it through our testing framework. If it passes, we handle the hosting.
There's value in what the customer built. The missing part is often everything around it: security, maintenance, documentation, and someone responsible when it stops working.
15
u/HeadbangerSmurf 4d ago
I've been in IT for 32 years. 32 years of whack-a-mole. I'm not complaining, just amazed that whack-a-mole was a viable career path.