AI can build applications faster than ever, but how do you stay in control of your data, workflows, permissions and business logic?
In this 2-day hands-on workshop, we use AI both to create applications and to build AI features into them, without becoming dependent on a commercial platform or model provider. This is the opposite of vibe coding. The AI works within a defined structure (forms, data relationships, permissions) that you can guide, inspect and revise by hand, and the AI picks up your changes and keeps building. Our case study is a mature open source platform, so nothing is a black box: we look at exactly how it all works under the hood. We'll also have an open-weight model running on local hardware, working through the same exercises.
You'll learn practical approaches to AI governance and permissions, designing tools and how they work together, errors that act as prompts so models can recover, human-in-the-loop workflows, and testing the reliability of AI integrations.
You can work through everything on your own laptop if you want, and you will leave with a running application you can move to any server. You will also learn patterns for safely integrating AI into the applications and infrastructure you control.
Our case study is Formulize, an open source (GPL-2.0) application platform, in continuous release since 2005, with no paid tiers for extra features. The open source version is the complete version. In Formulize, the configuration is the application: every form, every field, the connections between them, and the permission to access them are all defined data. The AI reads and changes it through a set of tools, and you can read and change it too, in the admin interface or directly in the database. Formulize is the laboratory for the ideas in this workshop, but they apply to any system you can connect to AI, especially if you can define data structures that drive the application.
Bring a real process or workflow from your own work that needs a better system, and leave with a working application you can start using right away.
This workshop is for:
- Consultants and agency developers asked to add AI to client applications without giving up control of client data
- In-house developers whose data residency, audit or procurement requirements rule out hosted AI app builders
- Technical leads deciding how much internal tooling can be handed to AI, and what guardrails that requires
- Anyone who has built the same CRM, intake form, approvals queue or tracking system a million times
Intro - AI Without the Black Box
- The trade-offs of AI application builders and vibe coding
- Building within a defined structure instead of generating code, and why that keeps humans in control
- Keeping control of your data, infrastructure and business logic
- Open source, self-hosting, and independence from any single platform or model provider
- Two roles for AI: building the application, and working inside it
Part 1 - Building an Application
- Understanding configuration-driven applications
- Building forms, connected data and reports, by hand first
- Defining users, groups and permissions
- Publishing, embedding and deploying the application
- Configuration as code and version control
Part 2 - Connecting AI and Building With It
- Understanding tools, resources and prompts
- Connecting external AI clients through MCP
- Embedding an AI assistant directly into an application
- Building applications from prompts and existing documents
- Changing by hand what the AI built, and having the AI pick up your changes
- Choosing which tools and capabilities to expose
- Working with commercial models, and with open-weight models on local hardware
Part 3 - AI Governance and Permissions
- AI acting as a specific user, with exactly that user's permissions
- Using your application's existing permissions instead of a separate AI allow-list
- Restricting what data an AI assistant can read
- Protecting sensitive and personally identifiable information
- Separating user and administrator capabilities
- Audit trails for AI actions
- Safe protocols for destructive operations
- Prompt injection and other risks
Part 4 - Domain Knowledge and Human-in-the-Loop Workflows
- Giving AI the business context it needs to make useful decisions
- Keeping domain knowledge inside the application, versioned with it, instead of in individual prompts
- Writing rules that AI interprets consistently
- AI-assisted processes run by the people who own them, not only by developers
- Building work queues for recurring AI tasks
- Flag, act, review and approve workflows
- Handling incorrect or ambiguous AI decisions
Part 5 - Designing Tools AI Can Use Reliably
- Writing tool descriptions as instructions for models, not documentation
- Choosing the right tool granularity
- Toolkit design: how tools work together and lead the model from one to the next
- Errors as prompts: responses that help models recover
- Returning the resulting state after write operations
- Declaring valid values and constraints up front
- Structuring tool responses to improve model accuracy
Part 6 - Testing and Improving AI Reliability
- Managing context: shaping how the AI asks for data, and limiting how much comes back
- Reducing and selecting tools to improve reliability
- Creating repeatable tests for AI integrations
- Measuring whether models choose the right tools and arguments
- Comparing behaviour across models
- Testing failure scenarios, including prompt injection
- Identifying and debugging unreliable AI behaviour
- What open-weight models on local hardware handle well, and where they struggle
Participants should have:
- Intermediate development experience
- Comfort with web application concepts
- Basic knowledge of relational data and SQL
- PHP familiarity an asset but not required
- Basic understanding of permission models and API keys
- No prior experience with Formulize is required
What to bring:
- A laptop with a modern browser (any operating system)
- An AI client that supports local MCP servers, such as Claude Code, Claude Desktop, Google Antigravity 2.0, VS Code with GitHub Copilot, etc. A paid plan is needed, since free tiers are too limited for this level of tool use. Or an equivalent local model with sufficient hardware behind it.
- Node.js installed, unless you're using Claude Desktop
- Optional: an API key from Anthropic, Google or OpenAI for the embedded-assistant exercises, or Ollama installed locally to use your own local model instead
Included:
- One year of hosting on formulize.net, if you want to keep your application online
- Hosting is optional: everything works without it, and you can move your application to any server at any time
Not Included:
- Model usage is not included. Participants use their own provider account or a local model.
Duration:
- 2 days
- 9:00 am to 5:00 pm
- 1 hour lunch break included at the hotel's restaurant
- 15 min coffee break every morning and afternoon