Skip to main content

Capabilities · AI-SDLC Measurement Platform · Part of Agentic SDLC

The score that tells you if agents can ship in your codebase.

Agents deliver end to end only in a codebase that's ready for them. The AI-SDLC Measurement Platform audits a repository, or your whole portfolio, for the architecture, security, documentation, agent infrastructure, and guardrails that autonomy takes. It returns the gaps, a score, and the roadmap to close them.

The onboarding

An agent joins your team like any engineer. Minus everything human.

A new hire absorbs how you work over months, from people. An agent starts every task on day one, and the repo is the only one doing the onboarding.

How an engineer onboards

  • A buddy to ask when the docs don't say.
  • Meetings and hallways, where the real decisions surface.
  • Code review that teaches the house style, PR by PR.
  • Months of osmosis : how things are done here, absorbed slowly.

How an agent onboards

  • It reads the repo. That's the entire list.
  • Context it can only have if someone wrote it down.
  • Rules and access it can only follow if they're wired in.
  • A definition of done it can only trust if tests encode it.

Everything an agent needs has to live in the repo. And what lives in a repo can be measured.

The test

Hand an agent a feature. Now walk away.

What you find when you come back is decided before the task even starts.

01 · The promise

Done, when you're back.

The feature works, the tests pass, nothing else broke, nothing new leaked. That's what agents are supposed to deliver: end to end, on their own.

02 · The practice

Guided, step by step.

In an unprepared codebase, an agent needs a person alongside: answering what it can't look up, steering it off what it mustn't touch, re-checking everything it calls done.

03 · The difference

It was never the model.

The same model behaves both ways. What changes is the codebase: whether context, access, rules, and a definition of done are already there, or live in someone's head.

The model is state of the art. Autonomy is a property of your codebase.

The dimensions

"Ready" is twelve measurable things.

The audit scores every repository across twelve dimensions: seven engineering virtues the AI era made load-bearing, and five requirements that didn't exist before agents.

AI-SDLC Readiness Audit

Agentic SDLC · Sample readiness report
Project yours Report illustrative sample Window last 90 days
74.6%
score · 352.9 pts standards coverage
01 · Raised stakes

How code actually reaches production.

What we measure

DORA-style delivery health, computed from your git history: how often changes ship, how long they take, how often they fail, how fast you recover.

Why it matters now

Agents amplify the flow they land in: a healthy pipeline compounds their output, a broken one compounds the mess. This is the number every AI initiative ultimately has to move.

Sample checks
deployment frequencylead time for changechange failure ratemean time to recovery

The roadmap

Not a verdict. A to-do list.

Every gap comes back ranked, with a priority, the check it fails, and the effort to fix — written so an engineer can start Monday and a lead can see why it's worth it.

P0

Add a secret-scanning gate to pre-commit or CI

Prevention Coverage · PRV-01 · effort: Low

Nothing blocks a committed credential today; catching one depends on a reviewer noticing. A pre-commit or CI scanner turns that hope into a gate that can't be skipped.

P0

Raise test coverage and add a coverage gate

Quality Assurance · QA-01 · effort: High

Large parts of the codebase carry no tests, and no tool measures what the tests actually exercise. Untested code comes back later as unplanned fix work and leaves agents nothing to verify against.

P1

Pin dependency versions instead of open ranges

Supply-Chain Security · SCS-03 · effort: Low

Open version ranges mean two CI runs on the same commit can resolve different dependency trees. Pin exact versions; let the lockfile and reviewed upgrades do the rest.

P2

Add a docs-freshness check to CI

Documentation · PRV-08 · effort: Low

Docs drift silently — a renamed target here, a moved service there — and an agent can't tell a dead reference from a live convention. A lightweight checker in CI catches the drift automatically.

The items connect: a coverage gap surfaces later as rework; a missing gate surfaces as a leaked secret. And every item traces back to a check, so "fixed" isn't an opinion. Rerun the audit and watch the number move.

The program

A number is only useful if it moves.

Readiness isn't the number the business ultimately cares about; delivery is. The audit is how Agentic SDLC begins, and delivery velocity and volume are what it exists to move.

01

Baseline both numbers

The audit measures your readiness score and, from the same git history, your delivery figures: how fast changes ship, and how much ships per week.

02

Move the score

The program's tracks work the roadmap: hands-on enablement in your repos, governance and security, activation team by team. Readiness climbs check by check.

03

Delivery follows

Rising readiness is the input. The output is velocity and volume — lead time falling, throughput rising — tracked release over release, in terms a board reads.

Readiness is the lever. Delivery is the result.

Find out your number.
The baseline audit runs on your real codebase and comes back with the score, the gaps, and the roadmap. The Agentic SDLC program takes it from there.
Get your baseline audit