Great International Developer Summit (GIDS)

Enterprise Vibe Coding: Building Secure, AI-Powered Apps in 30 Minutes - Parth Sharma

27:33 · 21 Apr 2026 – 24 Apr 2026 · YouTube

About this talk

This talk discusses the concept of enterprise wipe coding and its evolution into agentic systems engineering, which allows developers to move from idea to production in under 30 minutes. The speaker presents OutSystems as a pioneer in low-code development, detailing how their platform enables rapid app development and integration with existing systems. They introduce the innovative data fabric technology as a key enabler for connecting various data sources in a standardized way, facilitating seamless development processes. The session emphasizes the importance of security, maintainability, and enterprise-level integration in application development while showcasing a live demo where an application is built using their AI tool, Mentor.

Full transcript

Today, I think obviously most of you are here because of enterprise wipe coding. And that's what we're going to talk about, right? How do you um you know, go from uh an idea to production in less than 30 minutes? And um I was uh I did come and walk in towards the later half of the previous session. And it was funny because the the previous speaker, this

is Jeet Day, a really nice session by the way. He was talking about how, you know, we're not there in wipe coding just yet. And I'm supposed to now convince you guys that we are there. Trust me. So, that's that's what this session is going to be about, right? Um pretty interesting stuff that goes on behind the scenes why we are able to do it. And um

uh the interesting thing is uh very recently you know, OutSystems also made an announcement. I obviously could not change my session title. Uh but that's that's what's going to happen, right? So, enterprise wipe um is something that we're calling as agentic systems engineering. How do you go from blind wipe coding to real enterprise grade wipe coding with full system context and getting to production in 30 minutes.

We're actually going to do it in less than 30 minutes today uh because I want to talk about a lot of literature. But I also want to show you guys the actual demo, right? Um I think I was in the conference the last day uh and I saw somebody's bag tag hanging along. It said, "Talk is cheap. Uh show me the code." So, that's hopefully what I

also plan to do at the end of the day today. Uh but first of all, thanks a lot. Thank you so much for coming to the conference, you know, time is the most important commodity that we have. I've been with OutSystems about 1 1/2 years now, 2 years almost now. Um, and I think one of the most surprising things to me has been just the amazing community

of developers that we've got, right, worldwide. So, uh, when it comes low-code platforms or rapid app development platforms, we literally have the largest community, not one of uh, by a large number, large margin. And, uh, we've got some amazing, super enthusiastic people coming to our events all around the world. So, thank you uh, for being a part of this conference, for being a part of our session.

Thanks a lot. And, uh, uh, shameless plug while we're at it. Um, we've got something that we call as Dev Days, Developer Days. So, uh, quick QR code for to the registration page, or you can just come downstairs to our booths, talk about the product more in detail, and talk about our conference in detail. It's basically going to be in at Whitefield in Bengaluru. Uh, we're going

to have uh, our community members and our partners from across India talking about all the cool stuff that they've done on the platform, all the new things that they're doing, and it's just come for the vibes, right? It's a it's a very nice place. There's free booze at the end of the session. but it's good. It's good. Uh, and, uh, just a quick introduction, I think. Thanks

a lot for the nice opener, I'm just a solution architect with OutSystems. Um, primarily involved in a lot of GenAI initiatives across India. that's that's really about it for the most part. I come from background uh, working with a lot of startups who've built agentic solutions, uh, and high-code, basically. That's that's our word for anything that's not on OutSystems. Um, and, um, pre-prior to to my GenAI

stance, I I've worked with startups who are who've been in the robotics and the IoT space, largely. Right? All right. So, quick quick quick quick quickly getting back on track, right? What do you What should we expect today? Um there's largely I've got five sections in the slides that I'm running today. Uh quick intro on the platform, what we are, what we do, how we're able to

do the stuff that we do. something that we call as data fabric, not to be confused with Microsoft's data because it's a key piece of engineering that makes possible what we're going to talk about today. And then the main bit, right? Agentic dev to production really really quickly? And then I've got a ton of appendix slides. So, depending on the questions that we have either right now

or later on, just feel free to come by the booths and we can run through a lot of other That's really about it. So, the OutSystems advantage, right? Why should you come on a platform? So, OutSystems a quick quick breather on what who we are, right? We're about now a 20 25-year-old company. We've had humble beginnings in a garage in Portugal. and since day one, we've been

a platform that have pioneered rapid app development. In 2003, we coined the term low-code with Forrester, and we've kind of pioneered what the modern-day low-code and no-code experiences, right? So, if you pick up any low-code and no-code platform today, um they've actually kind of seen our um progress. They've basically um adopted the kind of way and the development that we've kind of strived to pioneer. All right.

So, it's a unified platform. We'll talk about that. It's super agile in terms of the kind of things that lets you do, and it's enterprise-proven. So, we've always been enterprise-focused at heart, and after enterprise focus, we've always been developer-centric, right? So, we want to empower the developers, the architects, and the platform owners where you don't compromise on whatever you can build. All right. And this essentially is

what we mean by when I say the platform. It's an all-inclusive full software life cycle development platform, right? If you talk about any general enterprise grade app stack today, you can expect something like this. I mean, probably one or two line items may or may not be there depending on the use case, but you can expect to have to manage all of these things. What if you

could do that from a single place, right? And that's basically the OutSystems platform as a whole, right? And I'm I'm just kind of speed running through these slides because we've got more cooler stuff to talk about. But essentially build anything, do anything, all the way from your agents to the kind of apps, agents, workflows that you want to build, wherever you want to integrate it with, whatever

you want to ship it to, with compliance, security, monitoring, analytics, all of it baked in, and being able to run and operate on any deployment model that you want. So, you want cloud native, you want on premises, you want a hybrid deployment option, all of it on a unified agile enterprise grade platform. the next question obviously is parts. If your platform is so good, what can I

build on it? The short answer is practically anything and everything, but um what we have seen over the years, Um from an ROI perspective, or rather one of my customers put it very nicely, um we don't want to solve all of your problems, but we want to solve the majority of your problems, right? So, there's obviously going to be niche use cases or niche modules, microservices, or

applications that you'll want to build where you could do it on the platform, but it doesn't make sense. And that's totally fine, right? We're here to solve the majority of the stuff, not all of it. So, if I had to talk about some of the sweet spots, what we've seen with our customers over the last 20-25 years, um uh there's extensions, there's experiences, there's um efficiencies, and

finally core systems, right? again, I'm going to speed run through this, and now with AI and GenAI coming into the picture, we're talking about internal external agents that interact with your existing applications and systems, right? Including SaaS platforms that you may be using, super old legacy applications that you're supposed to modernize but don't want to touch just Um agentic UX, agentic experiences, what we're bringing on the

platform. How do you, you know, give the user a super amazing cohesive experience. Um agentic workflows, and finally agentic core systems, right? How do you build something complex like an ERP, a CRM, an MES, an HRMS, an ITSM tool from grounds up with agentic AI at its core. Which brings us to data fabric. Super quickly, data fabric is the key piece of technology what makes agentic systems

engineering possible, all right? And the idea is very simple. Whatever data or logic source that you have in your environment, bring it on a data fabric. What data fabric does, let's say you've got a NoSQL database, a SQL database, uh serverless data storage, you've got a data warehouse, you've got your SAPs and your Salesforces of the world, bring all of it on our layer. We're going to

virtualize that and standardize all of those protocols, all of that data into a very simple SQL-like format. So, what that means for architects and for developers is that you don't have to worry about where the data is, where the logic is. You just see everything in a single place in a SQL-like format, and now I can run complex SQL joins, SQL queries as if it was a

single data source. We sort everything out. There's a bunch of cool engineering bits that go into the back-end caching, pagination, um and so on and so forth to make it faster and nicer. Uh but that's largely about it. And now with enterprise context graph, which we'll talk about in a second, we're also bringing in logic on the same layer. So, this includes your MCPs, your A2As, your

REST APIs. Bring everything on a single And that is what is going to make Which we have introduced very, very recently. Uh it's just an evolution of things that we've already been doing coming into a single cohesive experience, right? Um so, largely, the reason why wipe coding is great um and to the credit of either code generators as well as app generators of the world today, they

do an amazing job. They They actually do a kick-ass job at what they do, right? But there's still a lot of issues if you want to go from a wipe coding experience or a generational experience to production. And why we are seeing I mean, uh I talked to a lot of my colleagues in uh in the industry a lot, right? Why are we seeing more and more

gaps? Why are we seeing more and more issues with code that has been shipped a long back, right? It's already been shipped. And then you've got things blowing up and you're on call in the middle of the night, right? So, how do you avoid that? So, largely, we've got three things, right? Context gap. Context gap, I think um Biswajit they uh uh did talk about it a

lot as well. high velocity blast radius, right? So, teams are shipping code faster than you can actually keep track of. Um there was a very interesting um figure from, I believe, Gartner um which said that we've shipped more code or we've generated more code than we've collectively done in the past 60 years in the last year or 2 years. Like, that's absurd, all right? So, we're shipping

faster than we can keep a track of and of course there's there's integration and that. operational risk, right? How do I control what access to AIs have? How do I control access to I don't know, critical features? How do I make sure my agent is not going to do rmrf delete on my Linux server and so on and so forth, right? Um and that's where the context

graph bit comes into the picture, right? So, what we are introducing is as long as you give our systems access to a lot of these things with governance, which again we can talk about in detail later, essentially a self-learning context graph which is one, the self-learning, right? So, it's evolving continuously. It's got full context of your portfolio in terms of where different data sources are, what kind

of architecture you're using in general in your applications, different data sources, um maybe your brand guidelines, your themes, your CSS styling, your design files, so on and so forth. You get built-in enterprise controls which lets you control and govern it very, very finely. Um and of course, uh we want to basically open it to any development path, which we're actively working on. so, your enterprise reality is

going to be different, right? It's going to be your different deployment runtimes, your life cycles, your integrations, and your data and apps and agents, uh which is basically what we're going to encode in this context graph. Um I'm going to skip this stuff. Um we are also going to essentially release this context graph to external code generators, again more on this later, so that regardless of whatever

um development path you're doing, you like cursor, you like Copilot code, anti-gravity, or you want to go the uh you know, different route, whatever you're using, you continue to do that with the benefits of the platform. All right? And the benefits we'll get to in a second as well. So again, just skipping this stuff. Uh just a quick screenshot. This is from my demo environment. Um I

asked the product team to export the context graph and I just had this image generated. So this is basically what it looks like when it when I'm talking about all the applications on my environments. This is the home banking app, a core application, all the different libraries and assets that it's connect connected to, and so on and so forth. And this is a much larger view, a

visualization of what that context graph looks like on a terribly maintained development environment of mine. There's two key pieces of technologies. Just keeping track of time here. Uh Mentor and AI agent generator. we are really short on time. So I'm going to skip this stuff. I'm actually going to go back to the laptop so that we can see it in action. So this is my environment. Again,

I I hope we can all see my screen here. And you can build scratch apps from scratch in OutSystems, but we're going to use Mentor to do that for us. Mentor for context is just basically our take on Copilot, you could say. Um it's your AI Copilot when you're working on OutSystems. And we've tried to come up with an experience which is both what you get with

an app generator like Lovable or Replit along with the experience that you'd get from a code Copilot like Cloud Code or Antigravity, right? So we're talking about the first part of the experience first, right? Being on the app generation side of things. So right now I probably want if there's there's any suggestions from the audience, we'd be happy to build that app. Or otherwise, I've got a

couple of sample BRD documents. So I don't have to actually prompt it to build an app. I can just have an SRS, a design file, whatever really, um that I can go off of. So if there's any ideas or anything that you like from this list, let me know. Otherwise, we'll um pick something randomly. >> Wipe that mark. >> Mobile car park. All right. Uh quick look

at the document. Basically, talks about some stuff. I don't know. I am I'm white coding right now, so I'm just going to ignore all of it. Uh just go ahead with mobile car parking application. And I can now prompt it more things. Follow this design files. Follow this theme that I already have put in here. But, for now, let's just go ahead and see what it builds

for us. Now, unlike the Lovabelles and the Replit's of the world, uh Mentor is first going to actually give you a blueprint that you iterate on before you go on with the final application, right? So, we're just going to give it a couple of seconds and hope that the internet is running at a decent speed. now, while it goes through the documents and creates the blueprint for

us, some really, really interesting thing about when we're done building this application, whatever output we're going to get, is going to be 100% secure, 100% working 100% of the times, right? And how am I able to say that? It's because wait for it uh Mentor does not write a single line of code. All right. So, the nice thing about us is that we've pioneered low-code for a

very long time, right? And over the past 20, 25 years, what we've built is a very amazing and solid machine algorithm, which runs on an abstracted low-code layer, right? So, as a developer on the OutSystems platform, you're never actually writing the code directly. You're working on an abstracted layer. It's still powerful enough where you can build anything that you want to from mobile banking applications which banks

are using to for example the Portuguese Air Force they use it for their aircrafts. Um tons of tons of examples in India Schneider Bosch manufacturing hospitals and so on and so forth, right? So it's still very very powerful, but it's abstracted away. And what that means is as a developer it's difficult for you to screw up. You still can screw up if you wanted to, but it's

very difficult for you to screw up and the platform takes care of a lot of things for you. So when your low code representation is converted into standard code which the platform takes care of, um we take care of things like OWASP top 10. We take care of things like ISO certifications, SOC 2 certifications and so on and so forth, right? So your code is going to

be compliant because it's going through our machine algorithm, right? Again, you can make it non-compliant, uh but by default the platform will make it difficult for you to do so. So when Mendix is working on this blueprint and when I hit on generate it right now, so it's basically come up with these couple of things, right? So it's come up with the data model. So the different

um data models and things that it's going to use over here. So I can actually change things or ask it, how about you pick up my users from say my PSQL database or how about you pick up I mean, this is mobile car park application, um payment booking, parking slots, um car park, user profiles. Maybe I can ask it to pick up user profiles from my um

SSO and or IDP and so on and so If it automatically finds something which it hasn't in this scenario, um it will actually automatically put that over here. Or I can explicitly prompt it, can you just pick this data from here? And it'll do so. It'll also take care of integrations, REST APIs, usage of all of it, so on and so forth. Uh these are all the

screens that it's going to build for us. Um the roles and permissions, so it's going to take care of our back for us. The platform has amazing tools on role-based access controls. And so it's going to take care of all of those things for us, including sample user and sample data generation. And then, it's also going to take care of flows. So, it's not to be confused

with the complex workflows that the platform lets you do, but these are simple state changes, simpler flows inside the application. Now, we can go on and about with this application, but again, we're very short on time, so I'm going to go go ahead and generate. So, when I hit generate, um what Mentor is going to do is going to just write the low-code representation of the Now,

again, a lot of engineering goes behind the scenes, but but essentially, the way we make it possible is that we've given Mentor access to hundreds of thousands, if not millions, of micro low-code development patterns, right? Think of it as how do you implement a text box? And we've given it a thousand ways of doing it, right? A thousand secure and smart ways of doing it. So, it's

able to use all of those tiny LEGO bricks to build your application. The downside, of course, is there's got to be some downside. The downside is very simple. Um if you give it anything, or or you give it something very complex, and if if it thinks it's outside of its scope, or if it doesn't know it, it's just going to leave it as a boilerplate for you,

which, in my opinion, isn't too bad of a thing, right? You can always go back in the IDE, which the platform also ships with, and take care of those things manually yourself. So, the idea is how do you get from zero to 50, 60, 70, maybe even 80% with just a single shot or a multi-shot app generation. Uh which it's doing right now. We're just going to

wait for it to complete. And once it's done, it's going to throw us back into the app editing screen, where we'll be able to see the application at a glance. It's also going to publish the application. It's going to put it on my development environment. From there, I can test the application, basically develop it, push it into test, push it into prod and while we are at

it actually, we're just going to give it a couple more seconds to finish this. Um this is basically the the web control panel of the of the platform, right? So, on the side here, I can see the apps, agents, and workflows. So, all the experiences that we're going to see for the web app, given that we have limited time, all apply to agents and workflows I take

care of your deployments, your entire devops in one single place. You get monitoring, logs, and traces for everything that you build. Uh you get agent evaluations and agent guardrails for all the models and the agents that you use. So, it's a bring your own token token um policy when you're building agents. Any provider, any inference, any hosting, we really don't care. Um manage all of your users,

your emails, domains, IP filters, so on and so forth, right? So, whatever you can think of to actually run a production-grade shop, which a lot of enterprises today do. Um 700 plus enterprises across 70 plus countries. Sorry, 7,000 enterprises and uh I'm just going to quickly show you code quality. I think Mentor would be done in our in our screen over here. Oh, it's publishing the app.

So, code quality is again powered by the same technology. The same co-pilot is basically going to scan your environment twice a day, thrice a day, four times a day, uh depending on the configuration, and it's going to give you industry, development, and archi- tectural best practices in terms of what you're building, right? And again, it utilizes the enterprise context graph. So, what it's going to give me

pointers on are these four severities, oh sorry, these four categories, right? So, security, performance, maintainability, and architecture. And some of these are really cool. So, for example, um it's going to sort them by severity, right? So, low, high, medium, critical. Um so, for example, it's going to give me something basic like you've got rest services or rest API endpoints that are been exposed without authentication. Uh this

is the app where it was identified. Um again, it's not loaded, but it's going to tell me exactly the function, the server function, client-sided function, screen, or API endpoint that it was identified at. When was it found? Who was the last developer to work on So, that's on security. It's going to give me some other neater things like, "Hey, uh you shouldn't apps your apps shouldn't consume

APIs directly. That's an architectural flaw." Should put them in libraries. Um here's a another security uh issue. You shouldn't have get user ID on the client side of things. Um you shouldn't have SQLs running inside of loops. That's a bad uh development pattern. That's a performance issue. And so on and so forth, right? And some of these it goes as deep into probably uh right here. This

is my favorite one. Um into saying so far as you've got a complex function and your developers aren't writing comments on there. Okay, so that's a bad maintenance pattern. So, that's code quality to ensure that after Mendix has built what it's built, how do you make sure that your customizations are on par and with the best practices possible. And we have our application. Awesome. So, it gives

me a high-level overview of all my screens. Um it's taken the liberty of also giving me a screen here to import data for my testing. Uh but, it would have uh built a bunch of other data. So, I'm just going to go ahead preview this application really quickly, see what we've got the 10 minutes that we've used Mendix for. right here are my sample users for me

to impersonate. I'm just going to log in as the admin for now so that we just see the entire app. I don't think we really have the time to go through the different users. Um if I want to make any further changes, add this screen, change this data model, import this, so on and so forth, I can continue to actually iterate over here. Or if I want

to make any granular changes, I'll just go to the IDE. This is basically what the IDE looks like. Um I find my application right here. Um just going to go ahead. Mobile Car Park app. I'll just make any critical changes that I want to. What's also interesting, and the reason why it's Mobile Car Park app, is this is going to be responsive by default. Right? So, it's

going to be a really nice experience on any of the devices. We'll continue to just use it on desktop mode for now. Um and I can easily package it as a mobile web app, or convert it into a hybrid app for me to maintain. And then further after conversion into a hybrid app, I can actually push it natively on both Android and iOS. Again, platform takes care

of all of those things for you. So, I've got my users over here. And I've got my car parks right here. Let's just quickly see this app. Uh oops, dev tools are still open. Right? So, all the different car parks. Of course, this is mostly AI-generated data, so expect that along with my bookings. Um and each of these bookings I can just go on in there, see

the booking details, payment methods, edit these details, say complete this booking as an admin, so on and so forth, right? So, this is again a very simple application that we built. We could have gone with something much more complex. It would have given us a similar result or a better result. I don't know. The more descriptive your prompts and your documents are, it's going to try to

follow the instructions to the T. And um yeah, I mean, this is live right now on this URL. If anybody wants to maybe take a screenshot. And um Go on, try an SQL injection, go on, try a pen testing the application. This is going to be compliant, right? So, that's the cool part. Uh is that because we're we're on that the the we're given the platform guarantee

on the low code abstracted layer. It's going to be secure out of the box. And yeah, I think we're unfortunately very short on time. we'll take the rest of the questions downstairs. [music] >> [music]