Small apps built with AI Personal proposal by Per-Arne Andersen S4 · Spring 2027 https://thesis.uya.no/proposals/build-it-with-guardrails/ Generate a small request-and-approval app with explicit permissions and automatic checks. TECHNICAL - Generate paired Flask/SQLite apps with identical specs, scaffolds and budgets. - Change only authorization: a locked helper versus model-written access checks. DATA (planned) 12 approval-app specs × 2 versions 4 leave, 4 equipment, 4 expense workflows; employee/manager/admin roles. Define 10 checks per spec before generation: 5 workflow and 5 authorization checks. Qwen2.5-Coder-7B-Instruct: https://huggingface.co/Qwen/Qwen2.5-Coder-7B-Instruct Transformers generation settings: https://huggingface.co/docs/transformers/main_classes/text_generation METHOD Use fixed Qwen Coder revisions and greedy settings; run direct-request checks in isolation. Count workflow passes, prohibited actions and failed builds separately. Four administrative users inspect sampled workflows and explain handover requirements. OUTPUT App generator, 12 specs and a 24-app comparison. BACHELOR Task: Build one administrative app from the fixed specification using an existing authentication helper. Data: 12 approval-app specs × 2 versions (planned) Choose one leave, equipment or expense specification from the proposed set. Define employee/manager/admin permissions and 10 checks: 5 workflow and 5 authorization checks. Requires: administrative users, a requirements reviewer, isolated execution and inference compute. Method: Verify workflow and permission requirements with scripted tests and administrator walkthroughs. Plan 4 participant sessions. Output: A working app, access tests and handover documentation. Use relevant literature to justify the established approach; a new research contribution is not the aim of this proposal. MASTER Investigate whether a fixed authorization scaffold changes the kinds of defects in AI-built apps. Hold model/specification/budget constant; compare scaffolded and generated authorization, then connect test failures to administrator handover decisions. Intended contribution: Evidence about the limits of constrained AI development and resulting ownership requirements. STARTING PAPERS Liu et al. (2023) — Is Your Code Generated by ChatGPT Really Correct?: https://arxiv.org/abs/2305.01210 Distinguish passing a public test suite from independently assessed correctness. Nissenbaum (2004) — Privacy as Contextual Integrity: https://digitalcommons.law.uw.edu/wlr/vol79/iss1/10/ Analyse recipient, purpose and information flow rather than treating privacy as a role label. Search Scopus or Web of Science and ACM Digital Library using the topic query, then follow citations to the thesis start date. Record searches and compare methods, data, findings and limitations in literature-matrix.csv. Use that review to confirm or revise the gap and choose a current comparator. The linked papers are starting points. START HERE Tools: Qwen2.5-Coder-7B-Instruct, Flask, SQLite, pytest 1. Write one equipment-request specification and its 10 acceptance checks before generating an app. Confirm access to inference compute and record model, software and hardware versions. 2. Freeze the same Flask/SQLite template, model and decoding settings for both conditions. 3. Generate both versions in isolation and validate the permission tests before expanding to 12 specifications. Literature search: end user development AI generated applications governance maintenance Study controls: - Both conditions receive the same schema, requirements, template and output budget; only authorization implementation changes. - Do not selectively repair outputs. An app that does not run is not counted as secure. - Keep all failures and test direct requests, not only hidden buttons in a UI. - For generation, use do_sample=False and num_beams=1; record model/tokenizer revisions, runtime, quantisation, prompt and output limit. Keep failed outputs. - Before collecting participant data, agree consent, storage and withdrawal handling with the supervisor. Use participant codes, not names, in study files. - For the master’s study, use the research task above to define the factors and comparisons in this pilot plan. Preregister one primary outcome and feasible scope after the literature review; do not add every possible model or interface variant. REQUIRES 4 administrative users, a requirements reviewer, isolated execution and inference compute. -------------------- NON-TECHNICAL - Prepare request forms, approval rules and handover documents for three small apps. - Interview staff about who should own, approve and maintain each app. DATA (planned) 3 fictional apps + 8 interviews Leave, equipment and expenses; recruit 4 administrative users and 4 IT staff. Each packet names data fields, roles and support tasks. METHOD Interview 4 administrative users and 4 IT staff using disjoint packs with clear or missing ownership. Compare deployment conditions and responsibility gaps; code access, testing and maintenance disagreements. OUTPUT Ownership matrix and a handover checklist. BACHELOR Task: Assess whether an AI-built administrative app can be handed over to its owner. Data: 3 fictional apps (planned) Leave, equipment and expenses; recruit 4 administrative users and 4 IT staff. Each packet names data fields, roles and support tasks. Requires: Recruit both roles; use document examples only. Method: Use the fictional handover packs and task scenarios; list missing ownership, support and access information. Plan 4 participant sessions. Output: A practical acceptance checklist and handover template. Use relevant literature to justify the established approach; a new research contribution is not the aim of this proposal. MASTER Explain why a working demonstration may still be unacceptable to its future owner. Compare developer and administrator expectations about support, permissions and responsibility across fixed handover packs. Intended contribution: A theory-based model of acceptance and ownership gaps in AI-built apps. STARTING PAPERS Orlikowski & Gash (1994) — Technological Frames: https://dl.acm.org/doi/10.1145/196734.196745 Compare how roles interpret the purpose, operation and use of the same system. Nissenbaum (2004) — Privacy as Contextual Integrity: https://digitalcommons.law.uw.edu/wlr/vol79/iss1/10/ Analyse recipient, purpose and information flow rather than treating privacy as a role label. Search Scopus or Web of Science and ACM Digital Library using the topic query, then follow citations to the thesis start date. Record searches and compare methods, data, findings and limitations in literature-matrix.csv. Use that review to confirm or revise the gap and choose a current comparator. The linked papers are starting points. START HERE Tools: LibreOffice Writer/Calc, audio recorder with consent; no programming required. 1. Prepare a pilot with 2 examples from: 3 fictional apps + 8 interviews. Write the task questions and a reference answer sheet. 2. Write a recruitment message, information sheet and consent form for the participants named above. Agree privacy handling with the supervisor before contact. 3. Pilot one session after approval; revise unclear questions, freeze the task sets and coding categories, then recruit the planned sample. Literature search: end user development AI generated applications governance maintenance qualitative scenario study Study controls: - Keep app functionality and test facts constant; vary only ownership documentation. - A small role comparison does not estimate population differences. - Before collecting participant data, agree consent, storage and withdrawal handling with the supervisor. Use participant codes, not names, in study files. - Pilot separately, then freeze the questions and coding plan. Check objective answer keys independently; keep an audit trail of coding, including disagreements. - For comparisons, counterbalance order and case assignment; do not show a person both versions of one case. Report participant-level findings, not repeated tasks as independent people. REQUIRES Recruit both roles; use document examples only. Bachelor: apply established methods and evaluate a practical solution or study. Master: position a research question in current scientific literature, investigate a mechanism or unresolved problem, and explain the contribution. Final scope is agreed with me. Study sizes are proposed; participant recruitment and planned materials are not already arranged.