Fix the decision and criteria
The target is an internal application where authenticated staff list, filter, create, update, and audit records from an existing data source.
Evaluate:
- deployment and network boundary — 15%;
- data-source and credential boundary — 15%;
- identity and action authorization — 20%;
- environments, review, and release — 15%;
- backup, restore, and incident evidence — 15%;
- app and data portability — 10%; and
- licensing, staffing, and operating burden — 10%.
Reject any candidate that fails a hard requirement before interpreting the weights.
Normalize public evidence
| Candidate | Documented operating-model signal | Verify hands-on |
|---|---|---|
| Retool | Current pricing documents cloud or self-hosted availability and plan-dependent permissions, audit, source control, and external apps | Exact plan, resource permission behavior, release recovery, export, and self-hosted operations |
| Appsmith | Official introduction describes cloud or self-hosting, database/API connections, JavaScript logic, Git version control, deployment, and sharing | Edition boundaries, granular authorization, secrets, upgrades, restore, and export completeness |
| ToolJet | Deployment guidance distinguishes cloud from self-hosted operation | License behavior, identity and permission depth, release promotion, backup, upgrade, and app export |
| Budibase | Hosting documentation describes cloud and multiple self-hosted methods and makes customer operating duties explicit | Permission behavior, app versus instance backup, update path, external data sources, and portability |
This table intentionally avoids a numeric feature count. The documentation uses different definitions, plans, and levels of detail.
Run one identical build
In every candidate:
- connect to the same disposable database;
- create list, detail, create, and edit screens;
- define viewer and editor roles;
- deny one field and one action to the viewer;
- store a credential using the documented server-side method;
- create development and production configurations;
- change a field and promote a release;
- inspect attributable action evidence;
- simulate an unavailable data source;
- restore or revert the previous app version;
- export the app and representative data; and
- hand the result to a second operator.
Record video or screenshots, configuration exports, timestamps, error messages, plan, version, and operator effort.
Apply hard stops
Remove a candidate when:
- a UI-hidden action remains callable by an unauthorized role;
- production credentials must enter client-side code;
- a builder edit can silently change the live app;
- the buyer cannot retrieve required business data;
- no supported backup or recovery path covers required platform state; or
- the intended operator cannot perform upgrades and incident response.
Interpret without manufacturing a winner
A managed candidate can win when fast operation and vendor support outweigh deployment control. A self-hosted candidate can win when private network access and platform control justify the staffing. An open repository can improve inspectability without making app definitions cross-platform portable.
The output should be two candidates with unresolved questions and a completed test record. A winner is justified only after both receive the same test, version cutoff, and evidence threshold.