/

Insights

/

What 1,400 companies taught us about approving AI-built apps

Insights

What 1,400 companies taught us about approving AI-built apps

Nadia Keller

Nadia Keller

·

·

4 min read

Author

Nadia Keller

Nadia Keller

Co-founder and CEO

Published

Category

Insights

Read time

4 minutes

All posts

A year ago we started tracking one number across every Chamfer workspace: how long an AI-built app waits between its first working version and the moment a named approver releases it. In September 2025 the median was 11 days. Across 1,400 companies and 38,000 apps in production, it is now 26 hours.

Reviewers didn’t start doing less. Teams moved the slow conversations to the start.

Where the days went

In the first quarter of data, most of the wait sat in three places. Someone had to work out which tables the app touched. Someone had to decide who should be allowed to use it. And someone had to find a reviewer who had never seen the app and walk them through it.

None of that is review. It’s discovery, and it was happening in the most expensive week of the project. The pattern held across industries: a claims queue at an insurer and a dock schedule at a freight forwarder stalled in the same places, for the same reasons.

We measured it the plain way. The clock starts when the first version runs against real data and stops when a named approver releases it. Weekends count, because the people waiting on the app count them too.

Four habits of the fastest teams

We looked at the 10% of workspaces with the shortest wait from first build to release. They had four habits in common:

  • They write rules once, for the whole company. Instead of checking column access app by app, they write it down (“never show salary data outside People”) and every new app inherits it.

  • They name the approver before the build. The first prompt, or the first follow-up, says who releases it. The reviewer gets a queue item, not a surprise.

  • They review on realistic records. A staging copy of real data lets an approver click through the app instead of reading screenshots.

  • They release small. The median release in these workspaces changes 40 lines, a diff a reviewer can read in five minutes.

Review the rules, not every screen

The biggest shift was in what reviewers looked at. In the fastest workspaces, security teams spent their time on data sources and permissions and almost none on layout. That’s the right call. A button moving 20 pixels carries no risk. A new write to the payments table does.

“Our auditor asked who could see claims data. We exported the answer from the Logbook before the meeting ended.”

Marit Solberg, Head of IT Risk, Halden Mutual

An answer like that is only quick when the record exists before the question does.

What we changed in the product

Two releases this year came straight out of this data. In April, release reviews moved onto one screen: the diff, the data sources and the roles a change affects. In August, Specs gave security teams a way to write company-wide rules in plain English.

Where approvals still take days

Not everything got faster, and some of it shouldn’t. Apps that write to payroll or patient records still wait three to four days on median, while everything else, from dock schedules to renewals boards, now clears in under a day. Two-person rules on high-value writes are doing their job. The waits we want gone are the ones spent hunting for context, not the ones spent making a decision.

What we’ll measure next

Over the next two quarters we’ll publish the same numbers by industry and by plan. We’ll also add one more: how often a released app needs a permission change in its first 30 days. If the first review was good, that number should be small. We’ll publish the method with the numbers, so anyone can check the math.

Business and Enterprise workspaces can export the Logbook and run the same count on their own apps.

Put your first app in review this week

Create a free website with Framer, the website builder loved by startups, designers and agencies.