Three weeks after engaging GTH Cloud 365 this Power Platform governance manufacturing engagement had delivered a fundamentally different environment.
Power Platform governance for manufacturing SMBs is the difference between productive citizen development and ungoverned shadow IT — and this case study shows exactly what that looks like in practice.
Service: Power Platform Governance and ALM
Industry: Manufacturing
Company Size: 180 employees — Mid-Market SMB
Location: United States
Technologies: Microsoft 365, Power Apps, Power Automate, Azure DevOps, Microsoft Teams, SharePoint Online
The Business Challenge
The manufacturing firm had embraced citizen development with real enthusiasm. Within two years the company had accumulated over 60 Power Apps and more than 120 Power Automate flows built by employees across three facilities.
On the surface this looked like a success. Teams were automating processes, reducing manual data entry, and building tools that genuinely helped their day-to-day operations.
But underneath the productivity gains a set of serious problems had been quietly building.
The IT manager — a team of one supporting 180 users across three sites — had no visibility into what had been built, who owned it, or what data it was accessing. When a production floor supervisor called to report that a critical quality inspection app had stopped working on a Monday morning — affecting 40 production staff — nobody could identify the cause, find the person who built it, or roll back to a working version. The app had been built directly in the production environment with no development or test environment, no version history, and no documentation.
The IT manager spent three days trying to recover the app from memory. Production quality recording fell back to paper forms for the entire week.
When the company began exploring Microsoft Copilot adoption their external IT advisor told them plainly — their Power Platform environment was not in a state where Copilot could be safely enabled. Too many flows had access to sensitive production and HR data. Too many connectors had never been reviewed for appropriateness. There was no DLP policy in place anywhere in the tenant.
They reached out to GTH Cloud 365 through a search for Power Platform governance consulting after reading our blog post on what happens when Power Platform has no rules.
Why They Chose GTH Cloud 365
The company had spoken to two larger Microsoft partners before contacting GTH Cloud 365. Both proposed multi-month enterprise governance programs with price tags that did not fit a 180-person manufacturing business.
GTH Cloud 365 proposed something different — a focused three-week engagement scoped specifically to their environment, their team size, and their most pressing risks. No enterprise framework applied to an SMB. No six-month roadmap before anything was actually fixed.
The IT manager later told us the decision came down to one thing — in the first conversation GTH Cloud 365 asked about the quality inspection app incident before proposing anything. We already understood the problem.
What GTH Cloud 365 Found
We started with a full Power Platform governance assessment across the entire tenant. What we found was consistent with what we see in most manufacturing SMBs that have embraced citizen development without governance controls.
Environment and deployment:
- All 60 Power Apps and 120 Power Automate flows were built and running in a single default environment — Development, Test, and Production were all the same place
- No environment strategy existed — changes made by citizen developers went live instantly with no testing and no approval process
- No version history was available for any app or flow — when something broke there was no way to identify what changed or roll back
Ownership and documentation:
- 23 of the 60 Power Apps had no identifiable owner — the original builder had either left the company or moved to a different role
- 41 of the 120 flows had not been modified or reviewed in over 18 months — it was unclear whether they were still needed or still working
- No documentation existed for any solution — what each app did, what data it accessed, who used it, and what happened if it stopped working was entirely undocumented
Data access and connectors:
- 18 flows were connecting to external services including personal email accounts, file sharing platforms, and third-party services that had never been approved by IT
- Sensitive production data including quality inspection records, supplier contracts, and employee performance metrics was being accessed and processed by flows with no access controls
- No DLP policies existed anywhere in the tenant — any connector could connect to any data source
- The environment was not ready for Copilot under any circumstances — the combination of ungoverned connectors, overpermissioned flows, and absent DLP policies meant enabling Copilot would have created immediate data exposure risk
What We Did
Our Power Platform governance manufacturing engagement was structured across three focused weeks. We structured the engagement across three focused weeks — moving quickly because the business had already experienced a production impact from the ungoverned environment and could not afford a long drawn-out process.
Week 1 — Assessment, risk mapping, and environment strategy
We completed the full governance assessment and delivered a prioritized risk report within the first three days. The report identified the 12 highest-risk flows for immediate action, the 23 orphaned apps requiring ownership assignment, and the connector and DLP gaps requiring urgent remediation.
We then designed and built a three-environment strategy — Development, Test, and Production — within the existing Microsoft 365 tenant. We configured Azure DevOps to manage solution promotion between environments so that no change could move from Development to Production without a documented review and approval step.
Week 2 — DLP implementation, connector governance, and ownership remediation
We implemented a comprehensive DLP policy framework across the tenant. Personal email connectors, personal file sharing services, and unapproved third-party connectors were blocked from accessing business data sources. A tiered connector classification was established — Business connectors, Non-business connectors, and Blocked connectors — with clear rules for each category.
We worked with the IT manager and department heads to assign ownership to all 60 Power Apps. The 23 orphaned apps were reviewed — 14 were reassigned to new owners, 9 were retired as no longer needed. Each remaining app received a one-page solution document covering its business purpose, data sources, owner, and contingency plan if it went offline.
The 41 inactive flows were reviewed — 28 were retired, 13 were reactivated and documented under new owners.
Week 3 — ALM pipeline configuration, training, and governance playbook
We configured Azure DevOps ALM pipelines for the 20 most business-critical Power Apps — enabling automated deployment between Development, Test, and Production with full version history and rollback capability. This meant the quality inspection app incident that originally prompted the engagement could never happen in the same way again — any change to the app would be tested, reviewed, and deployed through a controlled pipeline with a one-click rollback option.
We delivered a Power Platform governance playbook covering maker policies, environment usage rules, connector approval process, DLP policy reference, solution documentation standards, and the ALM deployment process. We ran a two-hour governance training session with the IT manager and the eight most active citizen developers across the three facilities.
The Results
Three weeks after engaging GTH Cloud 365 the manufacturing company had a fundamentally different Power Platform environment.
- 60 Power Apps assessed and properly documented under named owners
- 120 Power Automate flows reviewed — 28 retired, 13 reactivated and documented, 79 maintained with full ownership and documentation
- 18 unauthorized external connector connections blocked through DLP policies
- 3 environments established — Development, Test, and Production with Azure DevOps ALM pipelines
- 20 critical apps enabled with full version history and one-click rollback
- 23 orphaned apps resolved — 14 reassigned, 9 retired
- Zero production incidents from ungoverned Power Platform changes in the 60 days following the engagement
- Copilot-ready — the environment met Microsoft’s governance prerequisites for safe Copilot enablement at the end of Week 3
The quality inspection app — the one whose failure had triggered the original call — was rebuilt in the Development environment, tested in Test, and deployed to Production through the new ALM pipeline. It has been running without incident since.
The IT manager reported that the governance playbook alone reduced the volume of Power Platform-related support tickets by approximately 30 percent in the first month — because citizen developers now had clear rules and documentation to follow instead of guessing.
What the Client Said
“We thought we were doing the right thing by letting our teams build their own tools. And in a lot of ways we were — the apps genuinely helped. But we had no idea how exposed we were until GTH Cloud 365 mapped it all out. Three weeks later everything was documented, governed, and under control. The quality inspection app running reliably on the production floor again tells the whole story.”
— IT Manager, Manufacturing SMB, United States
Could This Be Your Environment?
If your organization has been using Power Platform for more than 12 months without a governance review the situation we found at this manufacturing client is likely more similar to your environment than you expect.
The apps your teams have built are probably genuinely useful. The governance gaps that have accumulated alongside them are probably invisible — until something breaks or Copilot surfaces them.
GTH Cloud 365 offers a free Power Platform Governance Assessment for SMB and mid-market organizations. In one session we identify your top governance gaps, DLP risks, and orphaned solutions — and provide a clear roadmap to get your environment under control. Power Platform governance for manufacturing organizations does not have to be a long or expensive process.
No obligation. No sales pressure. Just specific, actionable guidance for your Power Platform environment.
Request Your Free Power Platform Assessment →