Build1 distinct publisher3 min readPublished
Liran Baba's dev.to argument runs through JFrog's own prompt-to-production path, which wires Okta, DNS and a security scan at launch, and still leaves unwritten the one field that decides who gets paged in eighteen months.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Each step in that path binds something, and only once.
Okta binds authentication to a directory at creation time. DNS binds a name to a service, once. The automatic security review binds a verdict to the state of the code on the day it shipped [7]. That is real work and it removes real toil; Baba, who describes the internal path at JFrog, says it replaced what used to cost three tickets and a fortnight [6]. None of the three steps writes a field whose value is a team, and none of them is scheduled to run again.
The offboarding checklist has the same single-shot shape from the other end. It operates on the human principal: accounts deprovisioned, laptop returned, SSO revoked, HR ticket closed [10]. In Baba's scenario the app holds a live database credential of its own [9]. A credential issued to a service has no opinion about whether the person who requested it still badges in. So the checklist completes correctly, every box ticked, and the tool keeps serving four people who depend on it [9][10]. The credential does not know the person who requested it is gone.
What actually fails six weeks later is the routing of the ticket. There is no repo anyone recognises, no runbook, and no team name attached anywhere in the systems [9]. Baba's framing is that Day 1 is close to solved because deployment is a product now, while Day 2 has nobody's name on it, since every other class of software in the company arrived with a support team already attached [12]. He is explicit that none of this is an argument for slowing the building down [13].
The two numbers here are carrying more weight than they can. Gartner's figure is that 41% of employees are business technologists, building technology capability while reporting outside IT, measured in 2022 [1]; Baba tells you to read it as a floor because it predates AI making the building part trivial [5]. For that share to describe your org, you would need a comparable proportion of non-IT staff with an actual sanctioned path to production, not just a spreadsheet habit. If you have no such path, the same people are still building, and the artifacts are somewhere you cannot enumerate.
The second number is a CISO self-report: 75% say they have already found unsanctioned AI tools running in production, and 16% are not sure [2][3]. Add them and 91% of respondents cannot say their production estate is free of unsanctioned AI tooling [4]. That is a claim about a wider category than the one in the scenario. Shadow SaaS signed up on a corporate card and an internal app wired into your own Okta tenant with a database credential are different exposures with different fixes, and the survey as reported does not separate them.
The mechanism for the fix already exists in the same path. It fails a deploy on a scanner finding [7]. Pointing that gate at a required owning-team field, with an expiry, is the same interlock aimed at a different column.
Ranked by verification strength, evidence, and original report placement.
Gartner found that 41% of employees are business technologists, building technology capability while reporting outside of IT (Gartner, 2022).
75% of CISOs say they have already found unsanctioned AI tools running in production (Saviynt / Cybersecurity Insiders, 2026).
A further 16% of CISOs are not sure whether unsanctioned AI tools are running in production (Saviynt / Cybersecurity Insiders, 2026).
At JFrog an internal path was built that takes someone from a prompt to a running production service with no engineer in the loop, handling parts that used to cost three tickets and a fortnight.
The JFrog path wires the app into Okta so authentication is real, provisions DNS so the service has a proper address, and runs an automatic security review before anything goes live.
Nitzan Gotlib, in JFrog's CISO organization, drove the prompt-to-production work.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
security
An ASD-endorsed assessor ran the entire JFrog platform against the ISM at Protected level1 distinct publisher
leadership
Naming an AI agent moves the blame from its owner to the technology1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One insider account, two borrowed numbers
The sturdiest thing in this reporting is the part Baba can speak to directly: JFrog's prompt-to-production path, named components and all, credited internally to Nitzan Gotlib's group. Everything that widens it out is thinner. The Gartner 41% is four years old and arrives without a link; the Saviynt and Cybersecurity Insiders survey arrives without a sample size or question wording; and the consequence the whole essay turns on — the orphaned reconciliation tool that wrecks a quarterly close — is explicitly a story Baba invents to make the gap visible.
One platform disclosed, a survey's shrug behind it
Prompt-to-production is running somewhere real — JFrog says so about itself — but the essay never says how many tools that path has shipped or how many are still alive. The wider signal is the CISO survey, where three in four respondents report finding unsanctioned AI tools in production. That establishes the phenomenon exists at scale; it establishes nothing about the specific pattern Baba describes, in which sanctioned self-service platforms mint services with no owner.
Diagnosis outruns the data, slightly
Slightly overstated, and mostly by construction. 'Nobody is on call' is a company-wide verdict built from one company's launch path, one 2022 headcount figure and one CISO survey; the failure that makes it stick never happened. Against that, the piece declines the usual moves — no product to sell, no solution announced, no claim that the gap has been measured — and it says out loud that a scan at launch tells you nothing eighteen months later. Confident framing, honest scaffolding.
Employer sits next to the problem
Baba works at JFrog, a company whose business is software lifecycle and supply-chain tooling, and his argument is that self-service production builds leave a lifecycle-shaped hole. That adjacency is worth naming. What tempers it: he discloses the affiliation in the same breath as the claim, criticises the design his own security organisation shipped, credits a colleague by name, and never mentions a product. The pull here is toward a worldview his employer benefits from, not toward a purchase order.
Believable, unverified
We can be fairly sure what was said and by whom; we cannot check any of it. A single publisher, a single author, no second voice, no primary documents behind either statistic, and a hypothetical standing in for the incident. Our read holds if you accept an insider's description of his own platform — which is reasonable — and stops there.