ما يُبنى بهWhat may be built
حدّد الفئات المسموحة: نماذج، تقارير، وأتمتة بسيطة. الحدود الواضحة تمنع بناء أنظمة حرجة بلا ضوابط.Define permitted categories: forms, reports and light automation. Clear boundaries prevent building critical systems without controls.
ما لا يُبنىWhat may not
التعامل مع بيانات حساسة، أو العمليات المالية، أو التكاملات الحرجة. هذه تُبنى في الأنظمة المعتمدة.Handling sensitive data, financial operations, or critical integrations. These are built in approved systems.
الصلاحياتAccess
كل تطبيق يجب أن يمر بمراجعة صلاحيات، وإلا صار متاحاً لمن لا يجب. الأداة السهلة تُنسى فيها الصلاحيات.Every application should pass an access review, otherwise it becomes available to the wrong people. Ease of use makes permissions get forgotten.
الملكيةOwnership
لكل تطبيق مالك باسمه، وبديل عند غيابه. التطبيق الذي يملكه من بناه فقط يتوقف عند انتقاله.Each application needs a named owner and a backup. An application owned only by its builder stops when they move.
البياناتData
أين تُخزَّن بيانات التطبيق؟ هل في الأداة أم في نظام معتمد؟ التخزين في الأداة يُنتج بيانات بلا نسخ احتياطي.Where does the application's data live: in the tool or an approved system? Storing in the tool produces data without backup.
المراجعةReview
جرد دوري للتطبيقات المبنية: ما زال مستخدماً؟ من يملكه؟ هل البيانات حساسة؟ التطبيق المهجور يبقى خطراً.A periodic inventory of built applications: still used, who owns it, is the data sensitive? An abandoned application remains a risk.

