Enterprise mobile app development and the problem nobody quotes: how enterprise mobile application development is distributed and managed on devices you do not own, and what an enterprise mobile application development company has to handle beyond the build

An enterprise mobile app is usually a straightforward build attached to a difficult distribution problem. Getting the app onto the right phones, keeping it updated, controlling what happens to company data on a personal device and removing it when someone leaves is where these projects actually live.

Decide the distribution route before the build

Public store, a private or enterprise distribution programme, or a mobile device management system pushing the app to managed devices. Each has different requirements, review implications and update mechanics, and the choice affects the build. If employees use personal devices, you also need a position on what company data may be stored there and how it is removed on departure. Settle this first; it changes more of the project than any feature.

Authentication has to work with what the company already has

The app should authenticate against the corporate identity provider rather than maintaining its own accounts, which means single sign on, sensible session handling for a device that is carried around, and immediate effect when access is revoked. The gap to watch is offline access: an app that caches data for offline use must also decide how long that remains readable after the person's access is withdrawn.

Assume the device is lost

Phones are lost and stolen at a rate desktops are not, so design accordingly: minimal local caching, encryption of anything cached, no sensitive content in lock screen notifications, and support for remote wipe of the app's data. Where regulated information is involved these are obligations rather than good practice, for example the technical safeguards at 45 CFR 164.312 covering access control, authentication and transmission security.

Support and the long tail of devices

Enterprise fleets include older devices and operating system versions that consumer products have stopped supporting, and users who cannot simply be told to update. Specify the device matrix in the statement of work and agree how long old versions remain supported. Agree too who takes support calls, because an internal app with no support route generates a stream of frustration that lands wherever people can find someone to ask.

Questions people ask about enterprise mobile app development

What decides an enterprise mobile project?

Distribution, not the build. Public store, private distribution or device management push, plus a position on company data on personal devices and how it is removed when someone leaves. Settle it before the build starts.

How should the app handle authentication?

Against the corporate identity provider with single sign on, sensible sessions for a carried device, and immediate effect when access is revoked, including a decision about how long cached offline data stays readable afterwards.

What should we assume about the devices?

That they will be lost. Minimise local caching, encrypt what is cached, keep sensitive content out of lock screen notifications and support remote wipe. With regulated data these are obligations under rules such as 45 CFR 164.312.

Sources

Related answers

Get your agency shortlistDescribe your project