We are using NoCoBase to build our ISMS/GRC tooling, and the feedback from accountants and auditors has been very positive. No wonder NoCoBase is a great tool and, in our experience, much more powerful and useful than many other NoCode platforms.
However, there is one potential weakness that could become a serious concern for organisations using NoCoBase for critical business systems: continuity .
Although NoCoBase is very intuitive, designing and maintaining a system with a NoCode platform is still often seen as a form of programming. This can create a continuity risk.
For example, I have designed most of our application myself using NoCoBase. But what happens if I leave the company or move to another job? Who will be able to take over the system and continue developing and maintaining it?
There is also a second question related to the continuity of NoCoBase itself. NoCoBase is a relatively small company. What happens if, for whatever reason, the company decides to change direction, discontinue the product, or move to another technology? Who would be able to continue the development of an application that is heavily dependent on NoCoBase?
Of course, the fact that NoCoBase is open source and can be self-hosted is a major advantage. This provides much more control and reduces some of the vendor-lock-in risk. However, for a critical ISMS/GRC system, this may not be enough by itself. An organisation also needs confidence that the system can be maintained and developed over the long term.
So I am interested in how other organisations are dealing with this issue.
What continuity scenarios or strategies are possible when using NoCoBase for critical business applications?
For example:
- How can the knowledge of the application be transferred to another developer or administrator?
- Are there recommended ways to document a NoCoBase application so that someone else can take over?
- Is it realistic for an external developer or service provider to take over a NoCoBase implementation?
- Does the open-source nature of NoCoBase provide sufficient protection against the company itself discontinuing the product?
- Are there any recommended approaches for reducing the long-term dependency on a single person or on NoCoBase itself?
I would be very interested to hear how other users — especially organisations using NoCoBase for business-critical systems — look at this continuity risk and what measures they have taken to address it.