Secure Vibe Coding: Why Retool Is Betting Governance Is the Next Enterprise Battleground

The company recently announced new capabilities that allow teams to build applications using any AI coding tool.
AI has dramatically lowered the barrier for software development. Today, employees can generate working applications in minutes using AI coding assistants such as Cursor, Replit, Claude Code, Codex, Lovable, and other emerging “vibe-coding” tools.
But while AI has accelerated software creation, it has also exposed a growing challenge for enterprises: how to govern, secure, and monitor AI-generated applications once they move into production.
“AI is transforming how software gets built, but it hasn't solved how software gets governed and shipped, and that gap is exactly where enterprises get exposed. Retool secures vibe coding,"” David Hsu, CEO and founder of Retool, said.
The company serves more than 10,000 organisations globally and is positioning itself as a governance layer for enterprise AI development.
Retool recently announced new capabilities that allow teams to build applications using any AI coding tool while automatically enforcing enterprise security, compliance, and governance controls when those applications are deployed.
The Rise of Vibe Coding—and the Governance Problem
The promise of AI coding tools is simple: anyone can build software. Product managers, operations teams, analysts, and non-engineers can now generate internal tools, dashboards, and workflows without writing large amounts of code.
However, most AI-generated applications are built without enterprise-grade safeguards. They often lack single sign-on (SSO), role-based access controls (RBAC), audit logs, permission management, and alignment with enterprise data governance policies.
As AI-generated software proliferates across organisations, IT and security leaders are increasingly worried about what they cannot see.
According to a survey commissioned by Retool and conducted among 307 CIOs, CTOs, and CISOs, 93% of enterprise technology leaders are concerned about AI-generated applications running in production environments. More notably, 38% described it as a top operational risk.
The survey also found that nearly 60% of respondents could not confirm whether their organisations had already experienced AI-related production incidents, highlighting a significant lack of visibility into AI-created software.
Visibility Is Becoming the Biggest Enterprise AI Challenge
As employees experiment with AI coding tools, enterprises are facing a new wave of shadow AI—applications and workflows created outside approved governance processes.
Only 5% of respondents in Retool’s survey said they were “very confident” they had complete visibility into all internal tools running in production. Nearly all respondents acknowledged some level of governance blind spot.
One survey participant summarised the concern bluntly, stating, “When anyone can ship a tool in an afternoon, nobody signs up to maintain it. AI failures are silent—confident output that's quietly wrong—so rot stays invisible until something breaks.”
Another respondent compared the current AI landscape to an unregulated frontier:
“I think we are in the Wild West of AI—as a CISO I am worried about moving fast and secure and govern later.”
For enterprise leaders, the challenge is no longer whether employees will use AI coding tools. The challenge is ensuring those applications remain secure, auditable, and compliant once they begin interacting with production data.
“We see firsthand how fast enterprises are building AI-powered apps, and how quickly the governance question follows,” said Unmesh Jagtap, Director of Product at Snowflake.
What ‘Prompt-to-Production’ Actually Means
The idea of moving from a simple prompt to a production-ready application has become a central promise of generative AI. Yet, in enterprise environments, building the application is only a small part of the journey.
Production systems require governance.
This means ensuring applications inherit enterprise permissions, follow security policies, generate audit trails, and comply with internal controls before they can interact with business-critical data.
Retool’s approach is to place governance underneath the application layer. Instead of securing individual apps, permissions are attached directly to enterprise resources such as Snowflake, databases, APIs, and other data systems.
As a result, any application that lands within Retool—regardless of whether it was created using Cursor, Replit, Claude Code, Codex, Lovable, React, or imported from a Figma design—automatically inherits existing enterprise controls.
Any application deployed through Retool automatically inherits an organisation’s existing governance framework, including single sign-on (SSO), role-based access controls (RBAC), audit trails, resource-level permissions, and enterprise data governance policies. Its governance architecture is designed to extend across the entire application lifecycle, from the moment a vibe-coded app is imported through every deployment, update, and user interaction that follows, so that data-layer permissions and application-layer behavior stay in sync rather than existing as two separate systems an IT team has to reconcile by hand.
This ensures that AI-generated applications comply with the same security and compliance standards as every other application running within the organisation, regardless of how or where they were built. It also lets business teams and engineers co-build without friction.
The company argues that this approach allows organisations to maintain governance consistency regardless of how software is created.
Why Enterprises Like Colgate-Palmolive Are Paying Attention
Large enterprises like those that make up Retool’s 10,000 customers are increasingly recognising that AI adoption cannot come at the expense of governance.
“We want teams to be able to build responsibly without creating new risk,” Iraklis Pappas, Global Head of AI at Colgate-Palmolive, stated.
“The challenge is not just speed; it is making sure the right governance, permissions, and auditability are built into how AI-enabled applications move into production. Platforms that make governed building easier are important for enterprises like ours,” Pappas explained.
The statement reflects a broader shift among enterprise AI leaders. The discussion is moving beyond productivity gains and toward operational accountability.
For organisations handling sensitive customer data, financial information, healthcare records, or intellectual property, governance is increasingly becoming the deciding factor in AI deployment strategies.
Don’t Slow Down AI—Centralise It
Retool’s message to enterprises is not to restrict AI experimentation but to centralise it.
The company argues that enterprises should allow teams to build applications and AI agents using whichever coding tools they prefer, while ensuring deployment happens within a governed environment.
This approach enables rapid experimentation without sacrificing control.
The strategy is particularly relevant as enterprises expand their use of data platforms such as Snowflake and cloud environments like AWS. Retool recently deepened partnerships with both Snowflake and Amazon Web Services to support this model of governed AI application.
The economics of software development have changed dramatically. AI has made software creation cheaper, faster, and more accessible than ever before.
The new challenge is governance.
As AI-generated applications become commonplace across organisations, enterprises will need platforms that provide visibility, permissions, auditability, and compliance without slowing innovation.
The debate is no longer whether AI can build software. It clearly can.
The question enterprises are now asking is: how do you govern what AI builds once it reaches production? Retool’s answer is that governance should not be an afterthought. It should be embedded into the platform from the start. For a closer look at what that looks like in practice, Retool has published a production checklist for securing vibe-coded apps.
[This article is part of the Brand Content initiative at AIM.]
Key Takeaways
- Retool leverages AI tools to simplify application development for enterprises.
- Focus on governance is essential as AI-generated applications present security challenges.
- CEO David Hsu emphasizes the need for strong governance in software production.
- Retool aims to position itself as a crucial governance layer in enterprise AI development.
- Over 10,000 organizations globally utilize Retool's services for application building.