Starting, testing, and adjusting

Can employees adjust AI workflows without a developer?

Yes, rules, instructions, and corrections. New connections, write access, publishing, and approval boundaries need agreed ownership and review.

Yes, employees can adjust an AI workflow without a developer when changing a rule, instruction, or proposal. New software connections, write access, publishing changes, and disabling approval boundaries belong to an agreed owner with a second reviewer, rather than one employee acting alone.

This page defines that boundary. It compares Microsoft Copilot Studio, Zapier Agents, n8n, and Make’s September 30, 2026 documentation about natural-language changes, practice costs, management failures, and shadow AI. It explains how your team learns without making the handiest coworker the new helpdesk. See implementation, testing changes, and building yourself versus hiring an agency.

The short answer

  • Microsoft defines three zones: personal read-only agents for everyone, Copilot Studio building by IT-approved makers, and production work for developers (Microsoft Learn, September 12, 2026).
  • Microsoft enables no data policies by default: “By default, no data policies are implemented in the tenant” (August 29, 2026).
  • Natural language starts the work. Microsoft and n8n require review and testing. n8n and Make agent layers remain preview or open beta on September 30, 2026.
  • Zap change approval is Enterprise-only and beta. Zapier Agents are personal automations tied to one account, shared only as template copies (pricing, usage).
  • Of 911 Dutch technology professionals, 72 percent use employer-unapproved AI; 24 percent say otherwise they cannot finish work (SThree, November 12, 2025).
  • High-shadow-AI organizations averaged $ 670.000 greater breach damage (IBM, July 30, 2025).
  • Since February 2, 2025, organizations using AI must ensure staff AI literacy. The law does not prescribe specific measures (Dutch Data Protection Authority).
  • The real self-service test: can another coworker pause the workflow, reverse a rule, and read a failed run while its builder is on vacation?

What exactly can an employee change without a developer?

Employees can safely change content: rules, tone, exceptions, allocation methods. Connections and permissions are different work. Distinguish four layers:

  1. Correct proposals or rules. “Send this supplier’s invoices to purchasing.” “Write more formally to association boards.” Process knowledge belongs to staff doing the work.
  2. Edit workflow steps. Branches, order, prompts in a visual editor. No code, but a power user must understand diagrams.
  3. Add connections or write access. Connect software, link accounts, write to Exact, Dutch accounting software, or send email. This affects company-wide data access.
  4. Publish or change approval boundaries. Everyone uses the new version, or payments and customer messages proceed without humans.

Layer 1 belongs to the process owner; 3 and 4 to management or the vendor. Layer 2 is the gray area where incomprehensible private workflows arise. Microsoft partner I-Experts says standard cases need no programming, but proprietary ERP without a standard connector still needs, translated, “a developer after all” (checked August 26, 2026).

None of the eight best-ranking pages we read on September 30, 2026 distinguishes these layers. They compare tools. The actual question is who may change which layer.

Can you adjust workflows in ordinary language with these tools?

All four accept descriptions, but their makers require checking or identify unfinished features. Natural language lowers the starting threshold without removing review.

  • Microsoft Workflows agent: “You describe what you want to automate in natural language, and Workflows agent generates the corresponding flow for you.” Then: “Always review and test AI-generated flows in the visual designer before enabling them.” It supports limited Microsoft 365 connectors, cannot repair existing flows independently, and is “only available in English” (August 18, 2026). Dutch offices cannot instruct this feature in Dutch.
  • Zapier Agents: text instructions define triggers, actions, and apps. Copilot helps with “making changes, adding actions, investigating errors” (May 7, 2026).
  • n8n Assistant: helps “create, edit, test, and troubleshoot workflows from natural language,” producing ordinary editable workflows. It is preview: “It can make mistakes” (documentation). n8n Agents launched September 25, 2026: “You don’t need to know how workflows work to build one,” but “Still in preview,” with approval advised for sensitive actions (announcement).
  • Make AI Agents (New): “currently available in open beta, so functionality and pricing may evolve” (documentation).

One feature lacks Dutch, one uses personal accounts, and two agent layers are unfinished. An office manager can change a rule in ordinary language but only a test establishes correctness. See testing.

Who may change what in each product?

Publishing, sharing, and rollback differ more than what staff type. These are documented features read September 30, 2026, rather than account tests.

Change layer Microsoft 365 Copilot / Copilot Studio Zapier Zaps/Agents n8n Make
1. Rule/instruction Language-generated flows, test first; zone 1 private read-only agents Language instructions, Copilot help Assistant/Agents, preview Instructions, tools, knowledge, open beta
2. Steps Visual designer for functional administrators/power users Visual Zap editor Node canvas, optional code Scenario builder
3. Connections/write access Standard no-code connectors; proprietary ERP needs developer; DLP off by default Personal account automations User adds credentials without Assistant seeing secrets; Chat user cannot add credentials/workflows Own AI key only on paid plans
4. Publish/rollback Management can disable generative publishing and apply environment DLP Enterprise-only approval beta; history: Professional 1 month, Team 6 months, Enterprise 1 year Separate draft/published versions, restore/unpublish, confirmation for publish/delete Beta behavior may change

Column sources: Microsoft zones, security, DLP, I-Experts; Zapier pricing, building; n8n Assistant, Chat Hub, Agents; Make.

Microsoft offers the finest barriers but defaults them open. Data policies apply per environment or organization: “Policies can’t be applied at the user level” (Microsoft). Zapier Agents are “personal automations tied to your account,” shared only as template copies (Zapier). Nobody else works on the maker’s agent during leave.

What does building and adjusting workflows cost?

Typing changes is free; running and practicing are not. Billing units differ. Tests sometimes count, or natural-language assistance consumes separate credits. Maker prices on September 30, 2026:

Product Starting price Unit AI status
Microsoft 365 Copilot, internal Copilot Studio $ 30 per user monthly, annual contract Per user; licensed users’ internal agents “No charge” within fair use Production
Standalone Copilot Studio $ 200 monthly per 25.000-credit pack, or pay-as-you-go Copilot Credit Production
Zapier Zaps Free 100 tasks; Professional $ 19,99 monthly annually billed, 750 tasks Successful step Editor Copilot beta
Zapier Agents Free 400 activities; Pro from about $ 33,33 monthly annually billed, 1.500 activities Activity, separate from tasks Personal, template-copy sharing
n8n Cloud Starter € 20 monthly annually billed, 2.500 executions, 1.600 Assistant credits Whole workflow run Assistant/Agents preview
n8n Community € 0, self-hosted Unlimited, own server management Preview features
Make AI Agents Price page unreadable September 30, 2026 Credits Open beta on all plans

Sources: Microsoft pricing, billing, Zapier pricing, Agents usage, n8n pricing, Make.

Standalone Copilot Studio: $ 200 / 25.000 = $ 0,008 per credit. A generative answer costs 2 credits, an agent action 5 (Microsoft, September 14, 2026). A thousand questions with one answer/action each use 7.000 credits, about $ 56. Searching organization files adds 10 per message, more than doubling cost. This is list-price arithmetic rather than a quote.

Free Zapier Agents tests count toward 400 activities and agents stop at the limit. Pro tests do not count (May 29, 2026). Penalizing practice pushes it to private accounts, starting shadow AI.

What goes wrong without management?

Problems are personal-account workflows, data sent to unknown services, and indispensable builders. This is shadow AI; see platforms for starting now. It is already normal in the Netherlands.

Recruiter SThree commissioned YouGov to survey 911 Dutch technology professionals from July 11 to August 27, 2025. Unapproved AI use is 72 percent; 24 percent say work/deadlines otherwise cannot be met; 81 percent know privacy/security risks (November 12, 2025). Reasons: own tools faster, 26 percent; missing approved features, 25; official tools slow/awkward, 23. These are technology staff rather than administrators, but a twenty-person office faces the same incentive.

IBM’s 2025 study of 600 organizations found one in five reporting shadow-AI breaches, only 37 percent having AI management/detection policies, and $ 670.000 higher average breach damage with extensive shadow AI. Of AI-incident organizations, 97 percent lacked proper AI access controls (July 30, 2025). Its 2026 report puts average breach costs at $ 4,99 million, up 12 percent (IBM). IBM sells security; these remain widely cited figures.

Dependence is the third problem. “The prompt is normally the visible part of a private method” (Collab365, August 28, 2026). A handy employee builds, colleagues depend on it, and that employee becomes the helpdesk. You have created a new developer without naming the role.

Should you prohibit employees from building workflows?

No. Without approved alternatives, bans move work into invisible tools. SThree finds 81 percent acting despite knowing risks, and managers doing so more often than staff (WINMAG Pro, July 25, 2026).

Microsoft uses zones. Zone 1 lets people create personal/team agents “based on content they already have access to. Agents have read-only permissions and stay private.” Zone 2 uses “IT-approved makers” for writing; zone 3 professional developers with strongest controls (September 12, 2026). n8n Chat user can use chat workflows but “can’t add credentials or workflows by default” (documentation).

Without IT, agree:

  • Everyone may read and propose within existing access.
  • Writing, sending, or posting requires an owned workflow and human approval.
  • New connections or accounts are enabled by one designated person or vendor.

See implementing AI without an IT department.

Is AI literacy mandatory?

Yes, since February 2, 2025. It neither authorizes everyone to build nor specifies training. The Dutch Data Protection Authority says, translated: “Organizations developing or using AI systems must ensure their employees are ‘AI literate’ since February 2, 2025,” and “The law does not specify exactly which measures these are” (updated October 27, 2025).

Workflow editors must know permitted data, destinations, and human review points. Process knowledge plus three boundaries matters more than no-code training. Typeform’s Aleks Bass describes a shift from “can you code” to “can you reason about the problem” (TechTarget, April 17, 2026). Office managers may reason about work better than developers. They need not reason about data flows alone.

How does your team learn to adjust workflows?

Learn through one real task maintainable without the builder after a few weeks. Make visible “its exact purpose, approved inputs, checks, stop conditions, result owner and support route” (Collab365, August 28, 2026). Documentation makes it auditable rather than automatically safe.

Run a handover test:

Question Why it matters Product evidence
Can another coworker find the workflow? Otherwise a private trick Single-account Agents (Zapier)
Are allowed/forbidden data recorded? Shadow AI starts with wrong-tool pasting 97% of AI-incident organizations lacked proper controls (IBM)
Does uncertainty trigger asking rather than guessing? Generated flows can err Review before production (Microsoft, n8n)
Who approves results and changes workflows? Two roles, often two people Owner and support route (Collab365)
Can someone reverse changes? Bad rules need reversal within minutes Restore/unpublish; Professional history 1 month (n8n, Zapier)
What if the builder leaves for two weeks? Proves team ownership Others receive at most template copies (Zapier)

Start layer 1: correct proposals and explain why, like onboarding a coworker. Only after successful handover consider layer 2 for one power user. Layers 3/4 stay with an owner and reviewer. See first processes and piloting.

Is “without a developer” a tool feature or an agreement?

An agreement. Process owners change rules. Nobody independently publishes a writing connection or removes approval.

Microsoft documents zones but defaults DLP off. Zapier personalizes agents and limits change approval to Enterprise. n8n separates using and building. The authority requires literacy without prescribing how. Dutch figures show 72 percent bypassing policy already.

  1. Products lacking the split make the handiest employee a developer, without a role description or replacement.
  2. Canvas-only products still require power users. No code does not mean no specialist knowledge. I-Experts names functional administrators and power users rather than office managers.
  3. Corrections becoming rules let whole teams learn in layer 1 without another builder.

Gartner reportedly expects 70 percent of large enterprises to abandon vendor-built agentic AI by 2028, “citing soaring costs and a lack of internal capability to evolve the systems” (BW Businessworld, September 30, 2026). Different scale, same mechanism: systems teams cannot adjust die when builders leave.

Where is this heading?

Starting gets easier; managing does not. Recent documentation moves from visual editors to natural-language workflows to agents choosing their own steps: n8n Agents on September 25, 2026, Make open beta. Easier demos mean harder subsequent review when preview behavior can change.

Gartner predicts “more than 40% of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls” according to Glean, August 7, 2026. Glean also cites Deloitte: only 21 percent planning/using agents have mature governance.

Our expectation: by the end of 2027, “without a developer” splits into two approaches. One allows language-based rule changes with mandatory tests and technical stops on outgoing email, entries, and payments. The other retains visual builders for one power user per office and inaccessible personal agents.

Makers lower entry while placing publishing/sharing under management: Microsoft zones, Zapier Enterprise approvals, n8n draft/live versions. This fails if Microsoft’s zone 1 permits writing without default DLP or Zapier offers live Team sharing without approval. Then everyone builds everything and shadow work grows.

Bombos enforces the split: team corrections, new tasks published together, approval enabled unless you ask Bombos to remove it at your risk.

What can this not yet do?

  • New connections remain specialist work. Without standard connectors, I-Experts says developers are still needed. Someone else does it for you.
  • Ordinary language is not testing. Makers require review; preview/beta changes can break an exception noticed three weeks later.
  • Someone must enable barriers. Microsoft defaults DLP off; Zapier approval is Enterprise-only.
  • Workflows cannot use unwritten knowledge. Explain or record exceptions. Bombos interviews you; canvases do not do that automatically.
  • This page measures nothing itself. Tables reflect September 30, 2026 documentation rather than our tests. Preview behavior can change tomorrow.
  • No Dutch SME figure exists. The 72 percent measures technology professionals, rather than administrative staff’s private workflows.

How does Bombos approach this?

Team changes stay in layer 1; layers 3/4 follow an agreed route. More work at higher quality with the same team, without an office developer.

Bombos reads incoming work, finds customers and cases, and prepares supported proposals. You approve, edit, or reject in Bombos. Corrections become rules for coworkers too. For shared mailbox distribution, changes mean settings and correcting assignments, rather than custom development. No code or course is needed.

We jointly configure connections to Exact, AFAS, Dutch business software, Nmbrs, payroll software, Microsoft 365, and other packages. Bombos reads/writes after approval. Payments, customer messages, and contracts await a human by default. You cannot disable that technical boundary; Bombos can at your request and risk. See errors and review and AI sending email.

Bombos interviews you about exceptions held in people’s heads. Wegwijzer helps set boundaries and suggests next tasks.

We configure the first task together. Your team teaches the next in its own words without technical skills. Unlike an agency, we do not want you to keep needing us.

Sources

Each source was opened on September 30, 2026. Original excerpts appear verbatim; translations are identified above.

Free, no obligation

More work done, at a higher quality, with the same team.

That is what Bombos is for: companies that grow fast and want to keep the same team. We start with one task that keeps piling up and guide you until your team can handle it. Then your team teaches Bombos the next task. Leave your number and we will call you back to talk about your situation.

We read what you write. Within one working day you hear from the one of us who knows your kind of work best.