Internal tools are the best possible vibe coding target. The users are down the hall, the requirements are real, the design bar is "clearer than the spreadsheet", and nobody is going to attack it from the outside.

1. Watch the current process

Before designing anything, watch someone do the job with whatever they use now. Note every copy-paste, every "and then I check the other tab", every workaround. Those are your features. The thing they complain about is often not the thing that costs them the most time.

2. Build the smallest replacement

Not the whole process — the single worst step. If people spend twenty minutes a day reconciling two lists, build the reconciliation and leave the rest alone.

internal-tool-scope.txt
The team currently does this: <describe the process step by step>
The worst part is: <the step>

Design the smallest tool that removes that step. Specifically:
- What data does it need, and where does it come from today?
- Does it need to write back anywhere, or only read?
- What's the one screen this could be?
- What am I tempted to build that I should leave in the spreadsheet
  for now?

3. Auth, but proportionate

It's internal, but "internal" usually means "on the internet with no link to it". That's not security. Use your company's existing login if there is one, or a single shared password behind HTTP basic auth as a genuine minimum. Anything with real personal or financial data gets proper accounts.

4. Make it obvious, not pretty

Internal tools live or die on legibility. Big text, clear labels, obvious buttons, confirmation when something happens. Nobody needs an animation; everybody needs to know the save worked.

Add an audit trail early — who changed what, when. The first time someone asks "who marked this as paid?", it either exists or it doesn't.

5. Sit with them while they use it

The first week is where the real requirements arrive. Ship rough, watch, fix. This is the enormous advantage of internal tools: the feedback loop is a conversation, not an analytics dashboard.

Ask what they still do in the spreadsheet after your tool exists. That answer is version two.