Home AI Development AI App Builder Audits Budibase

AI App Builder Audits · AI Development Series

Budibase App Audit

Budibase is built so that non-developers can make internal tools. That is the point of it, and it is also why nobody technical has usually looked at the result.

Rob Sherwood, co-founder of Dev Partners
Straight answer: we do not build in Budibase and we are not Budibase consultants. A Budibase app is a data layer, a permission scheme and a set of queries — which is what we work on. We audit what it does with your data, not the tool.

What Budibase actually hands you

Budibase is an open-source internal tool platform aimed particularly at IT and operations teams rather than developers. It can sit over an existing database or provide its own, and it can be self-hosted.

What a Budibase application is made of

  • Interface Visually assembled screens and forms
  • Data sources Your Postgres, MySQL, MongoDB, REST, or Budibase's internal DB
  • Queries Generated CRUD, plus custom queries
  • Logic Automations and bindings
  • Access Role-based access per screen and data source
  • Hosting Self-hosted via Docker or Kubernetes, or Budibase cloud

Budibase deliberately makes the common cases easy, generating standard create, read, update and delete screens over a table with very little configuration. That speed is genuinely useful and it has a predictable consequence: the generated screens expose the whole table by default, and narrowing that afterwards is a job that has to be remembered.

Where it uses its own internal database rather than yours, the usual data-modelling caveats apply too — it is convenient rather than relational, and it will not enforce relationships for you.

What we consistently find

These recur in Budibase deployments.

1

Generated screens exposing whole tables

The fastest route to a working tool is to point Budibase at a table and take the screens it offers. Those screens show every column and every row unless told otherwise.

Internal notes, cost prices and personal details come along with everything else, and the person building it may not have realised those columns existed.

What it costs you: staff seeing far more of a table than their role requires.
2

Roles configured once and never revisited

Access is set per screen and data source, and it tends to be configured at the start and then left as new screens are added.

The result is a tool where most things are properly restricted and a handful of newer screens are not, with nothing to draw attention to the difference.

What it costs you: gaps that widen quietly as the tool grows.
3

A privileged connection and no audit trail

As with every tool of this kind, the platform connects to your database with one broad set of credentials, so the database cannot tell who is asking.

Combined with write access and no record of who changed what, a mistaken bulk update becomes very difficult to unpick.

What it costs you: changes to live data that cannot be attributed or reversed.

Where Budibase is genuinely good

Budibase does something worthwhile: it lets an operations or IT team solve their own tooling problems without waiting for developer time they were never going to get. For forms, approvals and simple operational apps it is a sensible, economical choice.

Genuinely well suited to

  • Internal forms, approvals and simple operational apps
  • IT and operations teams without developer support
  • Organisations needing to keep data inside their own network
  • Replacing shared spreadsheets and manual processes
  • Quick tools where the alternative is nothing at all

Where it needs engineering behind it

  • Anything customer-facing or reachable from outside the organisation
  • Tools performing bulk or irreversible actions on live data
  • Regulated processes needing a defensible audit trail
  • Screens generated over tables holding sensitive columns
  • Anything the business genuinely could not operate without

The honest summary: Budibase is a good answer to a real problem, and its strength is also the thing to watch: it is designed for people who are not developers, so the decisions a developer would have questioned tend not to get questioned.

Meet the team

Prefer to watch? The short version of who we are and how we work

Do you need an audit?

Get it looked at if

  • It can write to, or delete from, your production database
  • It touches personal data, payroll, pricing or payments
  • Screens were generated over tables and never trimmed
  • The instance is reachable from outside your network
  • The person who built it has left, or is about to

You are probably fine if

  • It is read-only over data nobody would mind seeing
  • A couple of trusted people use it on an internal network
  • It is a dashboard rather than a tool that changes things
  • Everything it touches is easy to reconstruct

The AI Code Audit, applied to your Budibase build

Fixed price, £495. A written report within five working days of getting access. We look at what each generated screen actually exposes, whether roles are enforced consistently across newer screens, what the tool can do to live data, and how your instance is deployed. If you go on to have us fix it or rebuild it, the £495 comes off the cost in full.

Questions about auditing a Budibase build

Not at all — that is what the tool is for, and them solving their own problem is usually better than a request sitting in a developer queue for six months. The gap is simply that nobody asked the questions a developer would have asked: which columns should this screen expose, what happens if someone runs this without a filter, who can reach this. That is what the audit adds, without taking the tool away from them.

Read access to the applications so we can see the screens, data sources, queries and role configuration, plus the database schema and the credentials the platform connects with. If you self-host, how it is deployed and who can reach it matters too.

No, and we would rather say so plainly than pretend otherwise. We build with Claude Code and Cursor, with senior developers designing the system, reviewing every change and testing it. What makes us useful here is not Budibase expertise, it is that the thing being audited is a data layer, a permission scheme and a production database.

Find out what you are sitting on

The AI Code Audit is £495, fixed.

Tell us roughly what you built and how many people use it. If an audit is not the right thing for you, we will say so.

What the report covers:

  • What each screen actually exposes, column by column
  • Whether roles are enforced consistently as the tool has grown
  • What the tool can do to live data, and what is recorded
  • How your instance is deployed and who can reach it

We reply within one working day.

Book the audit