
Architecting Power Platform for Complex Enterprise Solutions with Ian Tweedie [MVP]
About this episode
M365.FM - Modern work, security, and productivity with Microsoft 365 is made possible by:
LOW-CODE DOESN’T MEAN LOW ARCHITECTURE
Power Platform can deliver a large percentage of business value quickly, but enterprise solutions almost always contain requirements that go beyond standard low-code capabilities.Ian explains why low-code should never be confused with no-code — and why traditional software architecture principles still matter when building with Power Apps, Power Automate, Dataverse, custom connectors, APIs, and Azure services.
WHEN POWER PLATFORM BECOMES ENTERPRISE SOFTWARE
There isn’t necessarily a clean line between “low-code” and “enterprise.”Complexity starts increasing when applications involve multiple user journeys, development teams, integrations, security requirements, business-critical processes, and interconnected services.At that point, architecture becomes essential.Ian explains why solutions should be divided into clearly defined features and modules with clean interfaces instead of becoming one large interconnected application.
ESCAPING THE WHACK-A-MOLE DEVELOPMENT PROBLEM
Fix one bug and another appears somewhere else.That familiar development problem is often a symptom of tightly coupled architecture.Ian discusses how modular design can isolate functionality and reduce unintended dependencies. Using email delivery as an example, he explains how separating business processes from delivery mechanisms can make applications easier to test, maintain, replace, and scale.
LOW-CODE + PRO-CODE = HYBRID ARCHITECTURE
Power Platform doesn’t have to compete with traditional software development.A Power Apps frontend might represent only a small part of a much larger application using Azure, AWS, GCP, APIs, or custom services.The important architectural question isn’t whether something is “low-code” or “pro-code.”It’s which technology is best suited to each feature.
CITIZEN DEVELOPERS, MAKERS AND ARCHITECTURE
Citizen developers bring something extremely valuable: deep knowledge of the business processes they work with every day.But business expertise doesn’t automatically translate into good application architecture.Ian discusses the balance between empowering makers and introducing enough architecture, governance, normalization, and technical review to prevent solutions from becoming difficult to maintain.
GOVERNANCE WITHOUT KILLING INNOVATION
Too little governance creates chaos.Too much governance creates friction — and can drive employees toward unsupported workarounds, spreadsheets, VBA, and shadow IT.The challenge is finding the right level of governance based on organizational risk, application criticality, users, and business impact.
POWER PLATFORM, APIs AND AZURE
Where should business logic live?Should secrets be stored inside Power Platform? When should Azure Key Vault, Azure Functions, or API Management become part of the architecture?Ian explains why architecture should always begin with the problem being solved rather than adding Azure services simply because they are available.
GIT, SOURCE CONTROL AND CI/CD
As Power Platform development becomes more collaborative, traditional development practices become increasingly relevant.The conversation explores Git, repositories, development environments, pipelines, source control, feature isolation, cross-dependencies, and CI/CD.There may not always be a perfect approach to source control in Power Platform — sometimes the goal is choosing the “least worst option” for the project.
IAN’S POWER PLATFORM ARCHITECTURE PLAYBOOK
Ian’s core principle is straightforward:Break solutions into features and modules.Each feature should have a clear reason to exist and ideally perform one specific responsibility.Then determine how those features communicate, where logic should execute, how they should be tested, and which technology is best suited to implementing them.
THE RAPID-FIRE ROUND
Mirko puts Ian through a series of quick questions:Should every enterprise application use Dataverse?Can Power Platform build mission-critical applications?Can Power Automate replace Logic Apps?Does low-code automatically reduce technical debt?Can Power Platform replace traditional application development?And perhaps most importantly: what should you order when visiting Newcastle?
KEY TAKEAWAY
Low-code does not mean low architecture.As Power Platform solutions become larger, more connected, and more important to the business, the fundamentals of software engineering remain relevant.Architecture matters.Data modeling matters.Governance matters.Security matters.API design matters.DevOps matters.And successful enterprise Power Platform development is increasingly about understanding how low-code, pro-code, Azure, APIs, automation, and traditional software engineering practices work together.
Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-a-microsoft-mvp-podcast-by-mirko-peters--6704921/support.
Get every episode summarized
Each time M365.FM - Modern work, security, and productivity with Microsoft 365 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
695 searchable segments. Every word is indexed and playable.
Full transcript
M365.FM - Modern work, security, and productivity with Microsoft 365 — Architecting Power Platform for Complex Enterprise Solutions with Ian Tweedie [MVP]. Machine-transcribed; use the interactive transcript above to jump the player to any line.
This is Dave Roberts. If you're heading into summer without a medical emergency kit, you're taking a risk most people don't think about until it's too late. Summer colds linger and can turn into sinus infections at last for weeks. Getting sick right before vacation can derail everything and we are traveling, finding a doctor and pharmacy is stressful. That's why I ordered medical emergency kit. It's like having an emergency care and a pharmacy right at home. It includes essential prescriptions like a moxasillin and generic z-pack to treat a wide range of common and serious illnesses. So if you wake up sick at home or on the road, you already have what you need. No waiting for your doctor, no hours at urgent care, no pharmacy lines, no co-pays, just match your symptoms to the right prescription in your guidebook or call their telemedicine doctor standing by. Start on your med sooner and feel better faster. Every home needs at least one medical emergency kit. 40 years online in minutes and it's shipped to your door and say $45 with promo code blue at urgentcairedkit.com slash blue. That's promo code blue at urgentcairedkit.com slash blue. Hi, this is Dave
Roberts. Heading into summer without a medical emergency kit, that's a risk. Summer colds can linger and getting sick on vacation can derail everything. That's why everyone needs a medical emergency kit. It includes doctor prescribed medications to treat common and serious illnesses. So if you wake up sick at home or on the road, you already have what you need. It's like having an urgent care and pharmacy at home. Say $45 with code blue at urgentcairedkit.com slash blue urgentcairedkit.com slash blue. Welcome everybody to the M 365FM podcast where we explore the people ideas and technology shaping the M Microsoft 365 power platform Azure AI security governance and modern workplace. Today we are going behind one of the most common descriptions of Microsoft power platform. Low code. Low code has opened application development to much broader group of people. But what happened when the application becomes business critical when you need to integrate APIs, Azure services, complex data
model security automated deployments, monitoring performance and multiple development teams working on it. At this point, power platform isn't simple a low code tool anymore. It's become an enterprise application platform and architecture starts to matter. My guest today is I'm treaty solution architect and senior technical consul and specialized in power platform, Azure and technical delivery. Ian helps organizations designing practical, secure and efficient solutions that solves real business problems with particular focus on architecture automation, deliver leadership and making technology work for the people. Today we are going to explore what happens when power platform goes beyond the low code architecture complex solutions and so on to pro code and data was and so on. So yeah, Ian, welcome to the M 365FM podcast. Cheers. Thank you very much. I have a me. Yeah, yeah, I do spend a lot of time looking at
when we want to build something with the power platform and it is a fantastic tool for getting 80% of that business value. But nearly always when we come across an enterprise solution, there is that 20% that is unique to that particular organization. But that particular organization needs where you have to go beyond that kind of no code into the low code nest of the system. And it's an important thing to recognize is the fact that it is a low code platform and what we mean by that is there's not 50,000 lines of code but you may have 100, 200, 300 lines of code. And it's important to recognize that and if you if you treat it as a form, you hear as much from you out of it. That's interesting, but before we deep dive into the topic, Ian, before you we make it really technical, I hope we get deep in it. How did you end up
working with the power platform? Well, so I did a bit of a data role and then I've done a number of different roles over the last 20 years. I'm starting off with Service Desk and running my own freelancing consultancy to building websites to then get in a job doing data in a government agency, analysing data and looking at how that data was moving around. Then I touched the dynamics, as it was known then, for the first time, I've always still known as dynamics, but we all know it's just the first, but it's just a power act. But I don't tell that too much, they've done it for the people in my get upset. But when we were looking at dynamics, building custom tables, then I moved off that and I moved into the world of Office 365 migrations and Azure migrations, which was quite a little journey I took about 2015 and I became an IT manager
and looked at moving largest sites to the Cloud. I then did consultancy off the back of that for a little bit. Certainly during COVID, I moved a large number of organisations to the Clouds, because people were contacting us and saying, look, we're closing down our office in two weeks time. We've got a server, it's sat there in the room. What do I do? How do I get it into the Cloud? I don't really want to, I can't really bring it home. It's not going to run on my internet these kind of quite interesting migration jobs. Then I went back towards the power platform in a way, looking more or more around how data was moving and this side of things. I've been all over the place a little bit. I even touched something called Asterix and built telephone systems for a little bit of time. Quite an interesting dimension. But I've settled really on the power platform and really I sent her around how business uses technology. So more business using
technology and the power platform is just one of the current thing that enables that. It's not going to take either things, but I think it's the current thing that enables that. You have a broader response to question. You'll say, thumbs like interesting, you'll say, Power Apps, or it's normally, I don't know, it's really under the line of codes, whether you do it. You also say Dynamics is also built a bit as power Apps. I think it's as a little bit more code. Is there any limitation? How many code we can write in one application? Before we get trolled by all the people who do Dynamics, it's a remember what part of Dynamics we're talking about because in true Microsoft style, there is more than one product Dynamics, although branding is quite well done. But if we think about sales and customer service as there now, at the time when I was playing with them, it was Dynamics. Dynamics, see, all right.
When we're looking at on top of power to the power platform and opened up, it's kind of self underneath and said, look, you know, you can build stuff that isn't just sales or customer service, so really just to be some marketing. In terms of limiting code, that there are, you're operating inside of a sandbox, you operate in the inside of a safe space. So you can't just write what you want, but you can push quite far. So with PCFs, you can do an awful lot. With PowerPage, you can do more. And we're seeing that really come to life now. Up until recently, you can only do client side logic, now we're starting to server side logic creeping. With things like plug-ins and custom connectors, you can reach out and do a bit more things. It's more about looking at the right solution for the right situation. And the other thing, I tend to find a lot is when we're building automations or we're building the right solution,
we need to be exactly executed because if we just plummeload a JavaScript in, and we are going to make some critical business decisions based on that JavaScript, we need to remember that that's going to run client side and someone could manipulate it. And if they do manipulate it, what's the impact for that going to be? You know, if it's something that has to be right and always must be accurate, then we need to execute that server side and then do we need to execute it synchronously? So the question can be vastly different as to where you got it. But when you see or when there was power platform, solutions stopped to being a local application and become an enterprise software. So I don't think there's a difference between low code and enterprise. I say there's there's where they become more complex is really when you're when you've got multiple
multiple different user flows or you use the journeys running through them. And you're doing more than just something as simple as looking at desk. We've got multiple people interacting with it, multiple different teams and you've got all these streams coming together. You have to start thinking about your architecture and you need to break it down into modules or features and you need to decide how are those modules or features going to interact with each other. And you need to start just seeing the principles of clean architecture. You know, if you if you're Uncle Bob and some of the stuff he's written over the years, it's been quite quite good and you may look at it with that only applies to a pro code world. It doesn't it applies in the low code world and it is a low code world not a no code world. And when we're applying it in that low code world, we have to think about, you know, how are we going to make this not? But it's nest. How are we going to make it so that when support get hold of it, they can understand where the problem is. How are we going to make it to reach feature or
reach module we build? Cleanly interacts with other features of modules, you know, other parts of the classification, but also has only one single purpose. It doesn't try and do everything. As soon as we try to make a module or a feature do everything, it becomes really difficult to build, really difficult to develop a really difficult test. Yeah, what I see I have developed a long time on on my own for the podcast for my own solution since I think seven or seven months or so. And I have started with this low code and oh, oh, I can use co-pilot in it. It's really cool. And it's become yeah, critical to handle. I say one back there. I say fix it. Next back there. Fix it. Then the next back is there. It's really, it's a little bit depression. So
so for me, it's the change. I know I use the I as co-pilot studio, no, I'm a visual studio and now I have downloaded two visual studio and you use it there. I also use a clawed inside. So I'm a burp burp burp burp burp. That's lazy, lazy guy. So did you think there is a line between the low code and pre-row code or is that distinction becoming meaningless? I I don't think I think there is a distinction in terms of skill set. I don't look at a business problem. You know, look at an assistant we are building and say, oh, that's a low code, a no code or a pro code solution. I look at it and say, well, what what features,
what modules do we need to develop to deliver this and can that feature or module be developed? You know, what's the best way of delivering that feature or module? And you know, you talk there about, you know, you had a bug over here and then you had a bug over there and then a bug over here. And what we what we tend to find is when we if we don't split up our architectures into separate parts, separate features or modules, and we end up with this whack-a-mo problem where we fix a problem over here, but then a problem pops up over here. So we fix that one and then something else breaks over here. And this is why it's really important to break down your architecture. Because if you break it down and you practice those principles of clean architecture, which aren't my principles, you know, they're they're coming from from Uncle Bob and various other, you know, architect of years for a far more experience than me. What what they what they tell you is you when you break things down and you give them clean interfaces between them, that's take sending an email is
a really simple one. Okay, we're going to send an email. Are we going to use a connector to send emails in every single flow that we have where we need to send an email? We could do that, but then we're quite closely coupling our flows to our sending of emails. Well, what happens if we need to send emails in a different way? What happens if we need to use sends grid instead of outlook? Or what happens if we need to use a different method? So then we say, well, could we call a child flow? Every time we want to send an email, could we call a child flow? Yes, we could, but what happens if it errors? How do we test it effectively? How can we break apart those tests and almost conduct unit type tests? Well, let's say, well, instead of sending an email directly from our flow, let's dump a record into a table and we'll call that our emails amp bound table, just like outlook does. And if we do that, we then can have something else that comes along and
says, right, how many emails are in this outbound? Top 50. And I'm going to do that every five minutes. And the reason I'm going to do that is because my current API limits limit me to sending 50 a minute or whatever. And what you've done there is you've separated out your features so that if one thing breaks, it doesn't break something else. And also, if you need to change something, you're only changing that one feature, you don't have to change everything else. So you don't end up with this whack-a-mo effect and this ripple impact affecting your whole, a whole environment. This is Dave Roberts. If you're heading into summer without a medical emergency kit, you're taking a risk most people don't think about until it's too late. Summer coldslinger and can turn into sinus infections at last for weeks. Getting sick right before vacation can derail everything. And we are traveling, finding a doctor and pharmacy is stressful. That's why I ordered medical emergency kit. It's like having an emergency care and a pharmacy right at home. It includes essential prescriptions like a moxasillin and generic z-pack to treat a wide range of
common and serious illnesses. So if you wake up sick at home or on the road, you already have what you need. No waiting for your doctor, no hours at urgent care, no pharmacy lines, no co-pays, just match your symptoms to the right prescription in your guidebook or call their telemedicine doctor standing by. Start on your med sooner and feel better faster. Every home needs at least one medical emergency kit. 40 years online in minutes and it's shipped to your door and say 45 dollars with promo code blue at urgencaredkit.com slash blue. That's promo code blue at urgencaredkit.com slash blue. Hi, this is Dave Roberts. Heading into summer without a medical emergency kit, that's a risk. Summer colds can linger and getting sick on vacation can derail everything. That's why everyone needs a medical emergency kit. It includes doctor prescribed medications to treat common and serious illnesses. So if you wake up sick at home or on the road, you already have what you need. It's like having an urgent care and pharmacy at home. Say 45 dollars with code blue at urgencaredkit.com slash blue.
Urgentcarekit.com slash blue. This is Dave Roberts. If you're heading into summer without a medical emergency kit, you're taking a risk most people don't think about until it's too late. Summer colds linger and can turn into sinus infections at last for weeks. Getting sick right before vacation can derail everything. And we're traveling, finding a doctor and pharmacy is stressful. That's why I ordered medical emergency kit. It's like having an emergency care and a pharmacy right at home. It includes essential prescriptions like a moxasillin and generic z-pack to treat a wide range of common and serious illnesses. So if you wake up sick at home or on the road, you already have what you need. No waiting for your doctor, no hours at urgencared, no pharmacy lines, no co-pays, just match your symptoms to the right prescription in your guidebook or call their telemedicine doctor standing by. Starting your med sooner and feel better faster. Every home needs at least one medical emergency kit. 40 years online in minutes and it's shipped to your door and say $45 with promo code blue at urgencaredkit.com slash blue. That's promo code blue at urgencaredkit.com slash blue.
So it's not, I know it's not a really good description but I try when, when, so the difference is we have the power platform and it tests is framework and then I have another architecture, a different one or a complex one. Is this the different from from from low code to to pro code? I think you should, you should break them, you should break them down into sensible chunks, you should break them down to to usable components. And I don't want to say components, I'm not talking about the individual components you find inside the solution, yeah, I'm talking about these modules. So you could have something where you've got a front end that is using canvas app and you know, well then calling a power to make flow, power to make flow is then
calling a connector, that custom connectors then calling a whole load of stuff going on. But you you'd set out those separate parts. So, code is you could just be 20% if your whole application. In fact, I've seen systems been involved with systems where the low code element is looked after by one team and that really represents 20% of the state and then you pull pro code type stuff going on, AWS and Amazon, so AWS and as you're and bit of GCP. So you got these other components sitting out there that are then doing other bits of work and really the power platform is used as a front end interfacing with a very small part of the system. Now, why does that work? Well, power platform is very easy to change and edit. So if you've got your small 20% front end, if it's receiving four bits of information and it's outputting six bits of information to another system, then that's all that you need to worry about.
Your business process will change far quicker. So if you've got, if you imagine you've got your inside of a company and you've got a power platform application which your team are using, but it's receiving four pieces of information and transmitting six. But it's chatting to some kind of pro code solution that's been built by some other teams. Your low code solution or no code solution, you can move forwards as your team needs change. Let's say you just are going to change your team's business processes. You can change your business processes within side of your team and you can update your power platform solution, your little part of the jigsaw puzzle. So long as you're receiving those four bits of information still in your transmitting those six, it doesn't matter. You can iterate your part of the jigsaw puzzle. And I think, you know, I go back to the question of, you know, you've got this pro code world in the low code world. I don't see it as pro code and
local. I always see hybrid model as possible. And as soon as you start making that decision, oh, that's a low code system, that's a pro code system. You go and do out this situation where you're trying to make, you know, you're trying to fit a square peg in a round hole. Awesome. I think also, that's also a bird book, bad words, but I think the local stuff, it's really cool to build an MVP, I mean, minimal viable product, the Microsoft data. And I think it's also nature over the time. So I think more, first we have all builders and we have only one one solution and then came the data, the data driven data model apps are the renamed it's often. It's like something like when we look at a data worse, they implement data worse. I think also,
as I started, it's called common data service. I don't know, or it was something wrong. I really wrote with the names. I don't know. I'm so overwhelmed with the renaming. So it's not the hard line, we say, it's more liquid to get there. Okay. But I think that's a little bit battle to low code developer and pro code developer. And I also think, okay, you say the 80% can develop in low code. But the, I think you, or what what what a lot of people misunderstanding, it's coding, it's not only to write good code, it's also to understand the architecture. And how will you say, yeah, we have these other tools and this is more, more implemented.
Let's say, I think a little bit about Azure and all these, I don't know, 100, 600 services. And so what did you think when we need a real architect and what should we start every time with architecture, when that's what what the best solution and yeah, how we can this this figure out the liquid line. I do think it's not an easy question to answer because you know, you have to think about why do we want citizen developers in the power platform, why do we want them building these business applications? Well, the reason is because of translation. Often these people live and breed these processes. So they know how to make the application fit
their needs better than anybody else because you've got less people involved. If you go back to school and you think Chinese whispers, you think about how something can change when it goes through 10 different sets of years. We have the same problem when we're building solutions. The more people involved from user requirement to building the solution, the less reliable that's going to be. However, as you've pointed out, we have another problem, whilst the less used to building a business application, the person is the more likely they are to architect it in a way that isn't necessarily efficient. So if we think about normalization, I came across a project where someone had created more than 450 fields on a dataverse table and applied 40 business rules. And they are
should work, but it's a bird's nest, a bit like that. And actually would be far better off looking at normalization. So you have these two forces at play. And that's where you've got to think about, when is the right time to have just enough architecture at play? And I think that that role of reviewing what is going on is important and looking at the number of users what is being built is going to impact and what the criticality of that service. If it's something that's critical and is needed to deploy something that's life-saving or is going to impact the finances around the business, then you need far more governance and architecture involved. If it's something that is if it doesn't work, it's nice to have, then you probably don't need to involve the architects and you can let them get on with building 400 fields on the table and applying 30 business rules and crying when it doesn't work. But you have these two forces at play and the reason why we love
we love the power platform is not only can you get an awful lot of business value very quickly in a very safe place, but also you can hand the platform over to people who are not, you know, not hardcore developers, not not as experienced in that development world, but are extremely experienced in what they do day to day. But the problem is you do need to meet somewhere in the middle. You know, we've all seen really horrific Excel spreadsheets and that's in Excel. We've all seen horrific access databases, you know, they still exist out there. So you do have to draw a line and it is a weekly line and it comes down to organizational risk, you know, what's the risk profile about organization, how willing are they for things to go wrong and what's the business criticality and you can't strangle an organization because if you strangle an organization you say why every single app that someone wants to build must go for this rigorous process, what happens is
you end up with a little cottage industry growing up and you get this cottage IT industry that springs up where, you know, someone over there in the corner has decided to make this Excel spreadsheet and there's put some VBA in some horrendous stuff like that that isn't supported properly or isn't really accepted anymore and there's built this thing and before you know it's used business, it's become business critical. So if you're too strict in your architecture governance, all you do is drop ever cottage industry. This is Dave Roberts. If you're heading into summer without a medical emergency kit, you're taking a risk most people don't think about until it's too late. Summer coldslinger and can turn into sinus infections at last for weeks. Getting sick right before vacation can derail everything and we are traveling, finding a doctor and pharmacy is stressful. That's why I ordered medical emergency kit. It's like having an emergency care and a pharmacy right at home. It includes essential prescriptions like a moxasillin and generic z-pack to treat a wide range of common and serious illnesses. So if you wake up sick at home or on the road, you already have what
you need. No waiting for your doctor, no hours at urgent care, no pharmacy lines, no copays, just match your symptoms to the right prescription in your guidebook or call their telemedicine doctor standing by. Start on your med sooner and feel better faster. Every home needs at least one medical emergency kit. 40 years online in minutes and it's shipped to your door and say 45 dollars with promo code blue at urgentcaredkit.com slash blue. That's promo code blue at urgentcaredkit.com slash blue. Hi, I'm Math and Evelyn and I'm Presley Hossbock. We're the co-host of Serving Smiles. A podcast where we try and make health and wellness way less overwhelming. In partnership with Colgate Palm Olive, we're breaking down topics like oral health, skin health and more with the help of expert guests. Check out Serving Smiles, wherever you get your podcasts. This is Dave Roberts. If you're heading into summer without a medical emergency kit, you're taking a risk most people don't think about until it's too late. Summer colds linger and can turn into sinus infections at last for weeks. Getting sick right before vacation can
derail everything and we're traveling, finding a doctor and pharmacy is stressful. That's why I ordered medical emergency kit. It's like having an emergency care and a pharmacy right at home. It includes essential prescriptions like a moxasillin and generic z-pack to treat a wide range of common and serious illnesses. So if you wake up sick at home or on the road, you already have what you need. No waiting for your doctor, no hours at urgent care, no pharmacy lines, no co-pays, just match your symptoms to the right prescription in your guidebook or call their telemedicine doctor standing by. Start on your med sooner and feel better faster. Every home needs at least one medical emergency kit. Order yours online in minutes and it's shipped to your door and say $45 with promo code blue at urgentcaredkit.com slash blue. That's promo code blue at urgentcaredkit.com slash blue. And it happens. You see people you work around with human beings. Human beings will always find a way around the problem. You know, we wouldn't be here today if we weren't really good at that. I think the question you have asked is really interesting. I think why we have citizen developers.
I think it's has two reasons. The first reason is so for me or for my department, I can make things simpler. But the other thing is we have external and implement knowledge in a company. So and when I don't know, I say I'm a flat manager in the company with 10 cars. Then I can build this simple solution and everyone can book with some rules behind the management level or something else. I don't know. And I think that's really cool. And also we don't want to use this knowledge from this guy because I don't know why he knows. It's worse. I work on Fawi company and all they have the the expenses Blackberry dudes that's worse. The people there are first drafts in this time. It's a long time ago. There were people don't know Blackberry anymore. But I think then but when you have you lot the fleet manager,
you have a what's the word like six and six and so on these big car companies. Then you need different kind of handling. You need I don't know. You have I don't know thousands of stations and it's a more complex system. I think yeah, that's the citizen I want to put out. And that's for me than then enterprise. You can it's built like in yeah, like these MVP example. How does this process work at my station? I show it to you and can you implement it to I don't know to the the world system. It's yeah, it's the blueprint I say for I don't know. It's good. I'm loved. I don't have a driver license or I'm not an expert. That example. But I think okay, I living in in Germany and on on we need this in the contracts for cars, but it's could be completely different in the US or in Spain or UK or Berlin. I don't know. And I think it this is also be
a thing where I need a fast really good working solution because when everyone builds their own thing and give it to a big system that could be I don't know. It could be a lot of data that are that's similar but that only one field and I build it every time and it's better to have a concept that are an architecture could this be the sometimes of difference. Is it dead? So if we think about common situation is where business has a couple of common things they need to communicate amongst the whole organization. But they they also have a couple of things where everyone does their own thing. And this is where using the right architecture and the right system and power platform can be really helpful. So if I think to when I used to work with
government funding. So quite many many moons ago we would have national requirements for government funding and what needed to be recorded. But also we had much more local requirements as to what we needed to know for the funding in our particular area. Now the national items existed inside of a national database. But we couldn't add our local items to that database. They weren't interested in that setting. You know we want five fields here and you can understand why because if everybody that was giving out you know every single you know sub body or sub organization that was giving out this funding added their own you know 20 fields to it. It would be a mess. And it would be a nightmare to manage. So what does that mean? Well right then that meant ended up with two systems in double entry. And one of the challenges I had at the time was how do we
make that one system with single entry? I can't dig too many mean extremely details as to how I achieved that but you can achieve that with something like the power platform where you can extend. You can't predict the future but you can prepare for it. Arizona State University is building degrees for what's ahead. Programs designed around emerging fields taught by faculty whose research is shaping our future. Not just teaching about it. It's why we've been ranked number one in innovation for more than a decade. Your future is worth preparing for and you don't have to prepare alone. Become future ready. Explore more than 400 programs at ASUOnline.asu.edu. That's a degree better. Right now it's subway. Try the 499 sub of the day. Get a different six inch sub every day for just 499 each like Meatball Marinera on Mondays, Tuna on Tuesdays and the BMT on Saturdays. It's a different six inch sub every day packed with protein and your choice of chopped veggies for
just 499 each or make it a meal with chips and a drink for just $2 more. But hurry it's only for a limited time and only its subway. After participating restaurants prices higher in Washington, Alaska and Hawaii and on third party delivery add-ons taxes and fees for delivery additional. Rubric is the security and AI operations company. Build for what happens after an attack hits. Not just the moments before. AI has turned the threat landscape into quicksand. Moving too fast for any human to fully predict. That's why an agentic cyber resilience platform matters. Automated recovery. Clean data. A business that keeps moving no matter what hits. One platform. Not a patchwork of stitched together tools and gaps. Don't wait for the next attack. Secure and accelerate your business at rubric.com. Again, rubric.com. If you can get an API interface up to that central system, then everyone can do their own things their own way and just report back or communicate almost those 5 or 6 fields where they have to be recorded in central system or
5 or 6 entities would have got to be in the central system. I think that's a real option in the power platform because you can develop in that way but you have to think about your architecture in the right way. You've got to consider what it is you're going to do, how it is you're going to allow communication and you have to be open to democratize your environment. Now I can see this really coming into life with things like AI because not only have we got more capability to develop those solutions more locally but also you're starting to see organizations create internal MCP servers. You know we look at say time shooting for instance something which in the consultant world we all have to deal with and whether we like it or not. We we we're starting to the MCP servers
being created on the back of those time sheet systems which then means that we can write something to winterface with that MCP server which means we don't have to use the time shooting software that maybe we're not a big fan of. Or you're starting to see this this almost democratization take place and I think with the right architecture you can see that happen but you almost have to build a system so it's open to that. The central idea has to be well we're open to time shooting systems being interface with people with that other applications and we're going to put these governance around it but ultimately you know as long as you've got the right to spoken to communicate with that you can update whatever you want. This is a really interesting part what I often see it's now a lot of a lot of developer also pro quality other parts start with tokens and develop and I think it's it's a good idea but then we have processes I say what process can we take. Let's let's take the MCP
I say share point I can do it with MCP I pay for for tokens or I use the graph API for doing I know no governance stuff it's really free when I see the price difference so it's I think the I don't know the wipe coating could be also getting more expensive in the world time when I doing simple processing with an MCP or AI and use all the tokens every time in every process I think that's it's for me an interesting architecture question because I don't know a lot of people especially at LinkedIn they post oh I have spent this week 80,000 dollars in tokens yeah I'm the best guy and I'm the expert and I think okay you're not expert because if you
have used this or that you have paying nearly three dollars for computing. Yeah this this this I think a good example for architecture but I will look a little bit into the Azure platform and I think Power Platform has has really good integrations to the most of the tools but there are also tools like I don't know sphere or a foundry but when I look into Foundry you can do so much more than you're doing in Power Apps can power apps first can power apps be a pro code tool or did I need like Brazil to do your or something else to make really pro code and I think yeah
that's my thoughts question then ask my second question so you if you need your preferred IDE really so if you want use Visual Studio use Visual Studio you want to use VS Code use VS Code if you want to use a terribly different IDE you want to use NotePad and you feel confident enough to use NotePad you can the advantage of course with with your IDE is they provide help you know they provide little tools to help you debug what it is you're trying to do they will tell you when you've got something wrong so you can use a lot of different tools but it just comes down to what's what's your preferred IDE what's your preferred method of editing those text files but there's no need to necessarily buy something particularly expensive but like with anything you know people are paying money for these tools for a reason and that's usually because these tools help them and if we go back to say thinking about some of your points there around people
burning 80,000 tokens building a solution in a week or 80,000 pounds worth of tokens building a solution in a week and not just tokens are pound by the way that would be extreme because you imagine it none of us would be touching this stuff the the question I would be asking is are we splitting down the solution that with the system that they're trying to build to a stage where we've got lots of features or modules each doing a single purpose and then communicating in the right way you know communicating in the facing with each other or are we just whacking everything in a one prompt and you know it's spewing out this big blob of code and we're going oh it's a magic box and it does that thing but we don't know how well it does that thing we're just crossing off fingers and hoping for the best and if we go and look at it it's all spaghetti you know is that what
we've built and I think the follow-up question is do we care now I think we should care I think we need to care because at some point something in that he's going to become deprecated something's going to need replacing his son is going to need to communicate with it all we're going to need to extend it and if we need to extend it or change it or alter it we want to be able to just alter that one piece not rebuild the whole application and you may say it's a small application it doesn't matter we can just rebuild it every time well if it's a small enough application to rebuild it every time I'd argue it's probably a single feature in which case you're doing exactly what I want you to do and what I think you should be doing is building things a small enough so they're modularised or featureised so they're building blocks that can then slot together and you know if we go back to the platform and if we think about Nissan Nissan so Nissan just up the road from me here in the northeast of England and you know Nissan get assembled parts of cars to put together
they don't build the whole car in that Nissan factory they don't produce tires in that factory now someone somewhere making sure me down but I'm fairly sure that they don't get all the various materials arrive at the factory in trucks they get you know glass from somewhere they'll get tires from somewhere they get these components and they put them together and I think sometimes with the power platform and sometimes with some of these solutions we go around them go well we've got these tiny little pieces of Lego and we're going to try and build a solution with them and I'm like hang on a minute that's bad what we need to do is we need to make our tiny pieces of Lego in steering wheels we need to make our tiny pieces of Lego into wheels we need to make our tiny pieces of Lego into gearboxes into engines and then once we've worked out what we're going to make our engine look like we then go drop our engine into every single car that needs that engine
we don't try and build entirely from just the little building blocks because if you do that and you do that on scale you know let's say you're running an app factory and you build every single app in its own individual way there's going to be someone downstream from you in support who's looking after 400 applications that all have a slightly different case management system they're all running this slightly different way that don't follow any kind of patterns or practices and they're going to cost a fortune to maintain developing upkeep so it is important to try and feature as one moduleize our solutions you can't just you know put your fingers in your ears and try and build this spaghetti and hope for the rest whether you're building whether you're wide coding or whether you're building something on power platform or whether you're building something you know as a developer you know just right in C sharp and you've got 50 developers on hand you have to still break these things down into their their their features their modules you can't
just expect to try and build the whole thing in one go it doesn't matter what it is you're building I think those core principles there's core architectural principles don't change and haven't changed for years yeah right now it's subway try the 499 sub of the day get a different six inch sub every day for just 499 each like meatball marinara on Mondays tuna on Tuesdays and the BMT on Saturdays it's a different six inch sub every day packed with protein and your choice of chopped veggies for just 499 each or make it a meal with chips and a drink for just $2 more but hurry it's only for a limited time and only it's subway participating restaurants prices higher in Washington, Alaska and Hawaii and on third party delivery add on taxes and fees for delivery additional rubric is the security and AI operations company built for what happens after an attack hits not just the moments before AI has turned the threat landscape into quicksand moving too fast for any human to fully predict that's why an agentic cyber resilience platform matters automated recovery clean data a business that keeps moving
no matter what hits one platform not a patchwork of stitch together tools and gaps don't wait for the next attack secure and accelerate your business at rubric.com again rubric.com kitchen and bathroom professionals know what goes behind the tile matters that's why trade pros trust fiber cement party backer board to keep tile firmly in place resist cracking and held block moisture chosen over 40 million kitchens and bathrooms party backer board what the best build on shop now at participating home depot lows and floor into core stores for more information visit jameshardy.com slash hardy backer the first thing i i have think more in England and mini and roise roise but this one is also a good example okay it's both no bwm but yeah um what i see or i sometimes feel a little bit uncomfortable it's it's that so many logics to live in power apps and not i say in
as a function or so or what actually stopped to work it's it's too hard code something into then they say oh you you cannot hard code it and i use the keyboard now i have to use the keyboard of course it's not working when i use a ipi so i don't think i think that's also an interesting part what did you think where do is the or i say the upie management fit in is upie management something more power platform architect should understand and should they use error or it's fine to have it in i don't know in power platform it's an interesting question so and we're thinking about where we should store secrets and keys the the question i would always ask is is where we're storing
it reversible if we're storing it in a place that's reversible then we potentially shouldn't be storing it there unless it's somewhere like key vault where it's got the right governance around it so i've unfortunately over my career seen people store secrets as environment variables that's always a bit rusty because anyone is an administrator on the system can look at it the environment to take environments variable is ultimately a table under the hood and i could accidentally be exposed we could not execute in a way another is a way to store secrets as an environment variable because you essentially store them as they're address inside of the is your subscription which is like subscription slash resource group slash key vault i can't remember it off the top of my head i left it out but there's a right way of doing it but the other question in my mind is what what's the governance around it what's going to be the need to
understand the usage of that do you need now each time it was accessed and when it was accessed or do you not and if you need that tighter governance around it then yeah spinning it up as you know you're climbing it by and as your function and exposing that as your function using api m into your power platform is probably the right way to do it but if you're doing something that's that that complex and that you know that secretive you are going to want all that logging around it and you're going to want to expose that as you know an internal API that then that internal API is going to have a secret so even if you expose it from api m you're still going to want to expose it with the secret you're not going to just expose it onto public input and let in hope for the best idea because you know you haven't really achieved anything there and when you do expose it you're all you've potentially done is you've just moved you've just doubled your problems so if you're going to have it exposed as a function and you're going to have you know you're going to
access key vault from your function then you have to ask yourself why you're doing that what is what is the business need for doing it what's the need from from an info site point of you because are you just going to have two sets of keys now one of the answers could be that you're going to publish this as a service you know that say you've got a service to access a certain type of information and you're running an out of factory and you want to build this once and the direct access to this particular system you're going to keep in the key vault and you're going to have and as your function go and fetch it from that system and then you're going to expose it to the power platform through api m and then you're going to limit how much usage all your environments can have against that and that gives you obviously things like mocking as well so it's about doing it in the right situation for the right problem don't just do it because you can
because if you just do it because you can oh we've spun up a function because we you know we want to store in a key vault yeah but how are you going to access your function all you've done is proxy proxy your connections to your key vault you're still going to ultimately store you know that secret somewhere and if you have to store that secret inside of your power platform inside of a connector which is you know you can't necessarily reverse it out of that then why why are you unhappy with storing it just there directly so it always comes down to like what why is it you're doing this can you think through what your logic is and you could have some good logic or you could have some not super logical it's it's always fascinating to ask that question but what is it what's the problem you try yourself by doing this um i think we have the citizen Ebola pass or i think better word it's the power platform makers i think Microsoft use it um what did you think about show day understand using GIP so they understand CICD or um it's okay to do it the i did it my way
i frankly not as to i it depends if they're using if they're they're working with any other youth really and what it is they're developing on if you're developing something like power pages it can be really handily to do that using GIP because your conflict it's very easy to accidentally conflict with someone else unfortunately when you're working with power pages you're really just editing lines in the table because power pages is still stored as lines in their table um i don't think it's a difficult thing to understand i do my architecture on most projects using a Git repository and usually with less than half a day of workshop you know people who are non-technical like bays who are usually quite non-technical i can get into a comfortable position using markdown files and pull requests and they seem quite happy
with it so i don't think gets a particularly complex thing to understand i think you've got to use it in the right situation i think one of the issues with power platform is how do you how do you use that with Git because you're all editing the same source so are you going to just have one person inside of that developer or build environment and then are you going to you know ask them to commit you know do you know run a pipeline and say ado to pull those changes into a Git repository and then you can mark those changes being part of that particular ticket well yeah could but what's the benefit of that? whilst an approach i if i can take i do tend to try and push towards is that we we keep our features separate in separate developer environments and we bring those in to a Git repository and then we deploy them into the other repositories but you have to be
really careful if you're going to do that because you'll need to watch out for cross dependencies and so you have to i go back quite carefully and you have to think how are you going to be sure you don't encounter cross dependencies but if you can split up your solution and you can get it independently deployable then your fabrata give one developer one environment and one Git repository and that way you know that person's responsible for everything in that but it's not always possible to do you have to look at the size of the solution you're trying to solve and there's there's i always say there's at least worst option there's never a best option with rest you know this one's really be worth and you know i a common a common pattern i tend to use for doing this is we'll have two or three developers inside of a build environment and we'll have run two pipelines off that build environment so every time they finish a sprint or they're happy
to do a release you know we've reached the end of a piece of work we'll do we'll run a your DevOps pipeline that will take the latest version of that and that will be that that sprints build and we'll put that into the test environment from where that is you know you can get to all three different things in there which can upset you know a lot of the you know it does go against that kind of a poor request you don't need to contain one one particular thing so you can go back the other thing i tend to do if we're using a shared build shared development environment is i will take i will run a separate pipeline which will take a copy of the build environment and run it on a schedule into a Git repository every six hours so at 12 o'clock and at six o'clock every day and what that means is we've got a copy of what happened in that environment unpacked in source control and should we need to know oh this power automate flow changed will it go find that
flowing source control and it's see when it changed within six hours you can go to get but like I say it's a least worse option there is no perfect way of doing a proper source control with our platform you have to really take your least worst option and someone somewhere and I know that will shout at me and tell me oh no there is and yeah there is you know you you you can build your objects separately but I think that's probably quite complicated for a lot of users. Rubric is the security and AI operations company built for what happens after an attack hits not just the moments before AI has turned the threat landscape into quick sand moving too fast for any human to fully predict that's why an agentic cyber resilience platform matters automated recovery clean data a business that keeps moving no matter what hits one platform not a patchwork of stitched together tools and gaps don't wait for the next attack secure and accelerate your business at rubric.com again rubric.com kitchen and bathroom professionals know what goes behind
the tile matters that's why trade pros trust fiber cement party backer board to keep tile firmly in place resist cracking and help block moisture chosen in over 40 million kitchens and bathrooms party backer board what the best build on shop now at participating home depot lows and floor into core stores for more information visit jameshardy.com slash hardy backer. ready for 10 days of Microsoft 365 copilot AI azure and the people shaping the future of work this January m 365 con is back and we're going bigger join us for live sessions real world demos and practical knowledge from MVPs and industry experts worldwide no generic slides no endless buzz we're tackling the real challenges copilot studio AI agents fabric security governance and automation whether you're an it pro developer or business leader there are sessions designed for you
with ten full days you can explore multiple technologies and connect with a global community watch live and take practical insights back to your organization January 2027 10 days one Microsoft community registration is open now go to m365con.net and secure your place today that's m365con.net join now at m365con.net and we'll see you live in January yeah i think when we think about this we have to to set godrails and also we have to talk about governance and i think the power platform governance often create tensions the the business one to or they are freedom it wants the control how do you balance those both religions sites i always think about it is in terms of friction and you know how can we allow people to do
what they need to do with least friction possible now governance is a funny thing because some people see governance as being you know we're gonna spell out every single thing you must do and if we haven't told you to breathe in that way then you're doing it wrong i'm not a big fan of that because i think you create yourself a big headache and you you get to a situation where people stop thinking for themselves and you have to ask yourself you know why are you employing developers if they're going to paint by numbers i think for me governance has to be around intent and giving the power to the makers and the developers to tell you how they're going to reach that
intent how they're going to you know make it as safe as possible in their way or to you know build a parallel to make flow that you know isn't you know eight levels of nesting and 450 actions and you have to review what it is they're doing and how they're doing it it's i'd say it's more of an art than a science now i don't particularly tend to get involved with governance in terms of the LP policies and that sign of things my my tend to center around you know the governance self of architecture in terms of how we how are we going to how are we going to build this are we building it the right way are we using the right type of automation tool and i think we've all come across those builders those developers that see power to make as the answer to every single
solution and showing them that it's not the right answer to every single solution and why it's not the right answer to every single solution is always an interesting exercise i've seen some pretty interesting environments i have one a couple of years ago where someone had built 450 parallel to make flows and they asked me if i could help debug it and i was like yeah to be fun i think i'll have a long if you got how much budget do you have because it's going to cost a lot so you know we've got a priming sample of where if governance has gone wrong there and we haven't broken things down properly and we haven't thought about things to services and things as features and what things are doing to other things because everything is you know something is serving something else this is the way you got to think about it when we talk about Ian's really his architecture playbook how does it look like
the bible the novel or more than a commission so for me my architecture playbook is very much great things down into modules and features and with power platform they very much have to be kind of integrated layers so what do i mean by that is you you don't end up with a separate feature as much doing the front end and a separate feature as much doing the back end you feature tends to be molded together so you've got a piece of functionality in your feature so we're going to have a functionality that's responsible for i don't know pushing stuff to a queue that sits on as your and all it's going to do is it's going to look for look for objects in this table and push them to a queue in a queue or we've got a function you know a feature that's going to look for emails
that are in you outbound email table and it's going to send them based on the schedule that we've already set or it's going to have text messages in that way so my playbook very much is around splitting up the desired solution into features and once we split up into features ask us what's the reason for that feature to exist is there more than one reason for that feature to exist if there is we need to question you know is it decoupled enough or is it one big blob of mess and if we can get one read down to one reason we can decouple it so that's that's ultimately what it what it looks like i think there's other things that sit in that playbook around you know practices if you think about practices think about you know what type of automation should be used to solve problem now often people will go well let's use some JavaScript to make sure all these fields are
populated that's awesome what happens if someone breaks that JavaScript or someone edits that JavaScript in the web browser because users can be pretty cheeky at times what happens if we're building power pages and we've got some very important business logic that relies on JavaScript but ultimately we can just write stuff straight to the database you know ultimately we can we can edit that and we can then put in whatever we want you know that's that's a problem so there's another part of it is to are we doing the right thing in the right place but that comes after the featureisation but the first thing for me is always how do we break this thing down into features how do we give these features one purpose to exist and then how do we test these features so when we put Humpty Dumpty together Humpty dot the slots together nice and neatly we don't end up with big fat cracks because we got cracks in Humpty Dumpty we've got a problem okay yeah cool yeah we're running a little bit out of time I have every part I have a rapid
fire around so I give you a statement and you tell me whatever you agree disagree or say it's depends or give a short answer every enterprise all our actual use data was what enterprise apps should use data verse and it depends I don't know it depends it comes down to down to what what it is we're trying to do but it depends so yeah I'm not very good to quick fire because my house is probably depends yeah it's a typical answer when every heat comes up um it's a little bit like can the mission critical applications no power automate can replace logic apps no because you have to have stuff like using a logic app yeah when I get in the old castle in you castle what is your your track holder you're sorry what what what
should you order a new castle um see I'd go I'd go mediums bear and order order a parmo because parmo is the greatest food in the world new castle will be a curry um definitely Are you for Nick? I'm sorry. I'm sorry. Are you for Nick? I'm sorry. Are you for Nick? I'm sorry. Did you say, I think local reviews taking full debt? No. No. Doesn't automatically reduce technical debt. Papa came for a replay of traditional application development. No, because I believe that those principles still that the principles that you have at the end of the day are still in the day. I don't know. I don't know. I don't know. I don't know. That's something interesting. I would want probably a feature to make forms and it's not a feature.
I would want to make a feature to make forms and it's not a feature. I would want probably a feature to make forms and it's not a feature. If I could have any feature in Power Platform would be something that would render a Jason definition as a form so I can have dynamic forms and then store data dynamically. Like almost like it's your table storage where I can just chuck any Jason out of it and I'll go thanks. I'll store that. Okay. And who shall I invite next to the platform to power the MC65 podcast and what questions shall I ask? Paavez, an ask the same question about ALM. I'd love to know his answer to that. I would be interested because I firmly believe that although application development is different in Power Platform, those core principles still play. He is definitely a far more than expert in ALM than I am.
Yeah. Then, thank you for joining me. I think one of the important things from this session is that the local doesn't mean low architecture. Power Platform makes it possible to build application automation incredibly quickly. But as those solutions become larger, more connected, more important to the business of the animals of software engineering, don't disappear. Data architect, charmeters, governance, metters, API integration, monitoring, and dev ops and so on and all this matters. And perhaps most importantly delivery, so yeah, I think it's it's power platform. This is a real power full platform and yeah, and yeah, choosing between local and pro-court is more to understanding when to use each concept and how to combine power platform,
Azure Automations and so on. So yeah, for all the listeners, I think thank you for listening today and you find all the applications from each really in show notes. And yeah, thank you for staying here and yeah, thank you Ian for spent nearly over an hour would be. Well, thank you very much for having me. It's been a pleasure to be on the show. So thank you.
More episodes
More from M365.FM - Modern work, security, and productivity with Microsoft 365

How AI Changed Software Development Forever — Building the Agentic Future with A...
M365.FM - Modern work, security, and productivity with Microsoft 365

Copilot Inherits Your Mess: Modernizing Microsoft 365 for AI with Richard Harbri...
M365.FM - Modern work, security, and productivity with Microsoft 365

Microsoft 365 Copilot: What Actually Makes People More Productive with Adrian Es...
M365.FM - Modern work, security, and productivity with Microsoft 365

How Microsoft 365 & Copilot Are Redesigning the Way We Work with Tracy van der S...
M365.FM - Modern work, security, and productivity with Microsoft 365