Citizen App Registry & Handover
Is it still healthy, and who owns it now?
This keeps approved and discovered apps healthy and owned. How they get discovered and approved is handled upstream.
Live demo · Source on GitHub · Framework doc

Problem
Employees build their own AI tools and automations without engineering support, and most organizations have no answer for who maintains them once the builder moves on or leaves.
What it does
A registry for employee-built apps. Each app moves through defined stages, from idea to prototype to MVP to production, and carries a named maintenance owner at every stage. Health signals come from the app’s actual repository, pulled live from the GitHub API, and a written framework spells out what each stage requires.
Built today
- A stage board (idea, prototype, MVP, production) with a named maintenance owner on every app
- Live repo health on each card: last commit and contributor count from the GitHub API
- A framework document with the entry and exit criteria for each stage
- A seeded catalog of employee-built tools, all synthetic
Next
- The owner as a gate: an app can’t reach production in the registry without a named maintenance owner
- Flag apps with no owner: the owner has left or the repo has gone quiet
- A handover checklist for reassigning an app with no owner
- An adoption panel: an idea-to-production funnel, share of approved apps over time, apps with no owner, and time to decision, all on synthetic data
What it demonstrates
A maintenance owner is a gate, not a field. Almost nobody plans for what happens to an employee-built app after the person who built it moves on, so the idea carries most of the weight here. The build just needs to be credible.
Rejected alternative
I considered a model that required engineering sign-off before anyone could build anything internally. I rejected it because that’s exactly the kind of bottleneck that pushes people toward unapproved tools in the first place. This model assumes employees will keep building, and makes what they build visible and owned instead of trying to stop it.
Honest limitation
Repo signals cover only apps that have a repo; low-code and no-code tools need other health signals. And today the tracker records ownership without enforcing it. The owner gate is the next piece being built.
Integration map
| System | This demo | In production |
|---|---|---|
| GitHub | Live (real API, real repos) | Same |
| App registry | Simulated (seeded synthetic catalog) | Real CMDB or SaaS inventory |
| Ownership and HR data (who owns what after a departure) | Documented only, out of scope | Real HRIS integration |
Tech stack
- Frontend
- Astro
- TypeScript
- Vanilla DOM
A board you read and click through needs no UI framework, so it ships as static pages.
- Backend / data
- Seeded catalog (TypeScript module)
No database until the registry needs to write anything back.
- Integrations
- GitHub REST API (live)
Public repo data needs no credentials, so the health check runs in the browser.
- Infra
- GitHub Pages
- GitHub Actions
Every push builds and deploys a static site, with no servers to run.
Where it connects
- Receives from · Stage 2, DecideInnovation & PRD MarketplaceStatus: LiveOwner named. Once a marketplace PRD is assigned and built, the app moves to the registry, and it can’t reach production there without a named maintenance owner.
- Hands off to · Stage 2, DecideInnovation & PRD MarketplaceStatus: LiveNo owner. An app with no owner triggers a handover, a retirement, or a new marketplace submission.

