$ rg --services ai-sdlc

Your agents can write code. Can your organization trust it?

I help engineering organizations move from AI autocomplete to governed, autonomous delivery. Decisions get made upfront by the people with context. Agents execute them. Every change is reviewed and auditable.

$ cat problem.md

AI adoption is up. Delivery isn't keeping pace.

The problem isn't that agents write bad code. It's that nobody decides how they work as the codebase grows, so every decision gets pushed to the worst possible moment and made by whoever has the least context.

19% slower

Experienced developers using AI tools on mature codebases, while believing they were 20% faster.

METR, 2025

7.2% drop

In delivery stability for every 25% increase in AI adoption.

Google DORA, 2024

3%

Of developers report high trust in AI-generated output.

Stack Overflow, 2025

$ cat approach.md

Decide upfront. Let agents execute.

A decision made upfront, with full context, time to think, and access to stakeholders, is cheap and usually right. The same decision made by an agent halfway through a task is expensive and often wrong.

So the work isn't "get AI to write more code." It's making sure every task an agent picks up has already been decided, is the right thing to build next, and gets independently checked before it ships. Your engineers spend less time typing and rubber-stamping, and more time on the decisions that matter.

$ cat services.yml

Three engagements

$ rg --service audit

01

AI SDLC Audit

Find out where AI is helping your delivery, where it's hurting, and what to change first.

2 to 3 weeks, fixed fee

For: Engineering leaders who have rolled out AI coding tools and can't yet show what they're getting for it.

What you get

  • +Interviews across engineering, product, and leadership
  • +A map of your current lifecycle, from idea to production, with every place agents and humans make decisions
  • +Where AI is creating rework, review bottlenecks, or stability risk
  • +Governance and compliance gaps (EU AI Act, NIST AI RMF, ISO 42001 where relevant)
  • +A prioritized roadmap with the first pilot scoped and ready to start
Related: AI readiness assessment →
$ rg --service pilot

02

North Star Pilot

See a governed AI software factory running on your codebase, with your tools, on real backlog work.

6 to 8 weeks, one team

For: Organizations ready to move past autocomplete and see what end-to-end agentic delivery looks like under their own controls.

What you get

  • +A Definition-of-Ready gate so agents only start work that has actually been decided
  • +Autonomous dispatch of backlog tasks to developer agents in isolated environments
  • +Independent AI review on every change, with signed attestations of who reviewed what
  • +Quality gates and autonomy policies set to your risk tolerance, from advisory to enforced
  • +Before and after metrics on cycle time, rework, and review load
  • +A rollout plan for the next teams
Built on the open-source AI-SDLC framework →
$ rg --service context

03

Decision Context Engine

Turn your institutional knowledge into context that agents and people can query, so decisions get made before the work starts.

Scoped from the audit or pilot

For: Organizations whose agents keep making the wrong call because the reasoning behind past decisions lives in people's heads, old tickets, and scattered docs.

What you get

  • +An ontology and taxonomy for your products, systems, customers, and decisions
  • +Hybrid retrieval that combines Elasticsearch, vector RAG, and a knowledge graph, measured with an evaluation framework
  • +Persistent agent memory, so lessons from one task carry into the next
  • +Signal ingestion from support, CRM, analytics, and roadmap tools into a continuous priority score
  • +Context feeds into the Definition-of-Ready gate, so open questions surface early and get routed to the right person
Related: Knowledge graph proof of concept →

$ git remote -v

Built in the open

These engagements are built on AI-SDLC, an open-source governance framework for AI-driven software delivery that I maintain and use every day to build my own software. You can read the specification, the design decisions, and the code before we ever talk.

Nothing is locked in. It's Apache 2.0 licensed, it runs on your infrastructure, and your team owns it when the engagement ends.

git clone ai-sdlc →

Frequently asked questions

Do we have to adopt AI-SDLC to work with you?

No. The audit is tool-agnostic. The pilot uses the AI-SDLC framework because it's open source (Apache 2.0) and gives you governance out of the box, but it runs alongside your existing repos, CI, issue tracker, and AI coding tools. You keep everything we build.

Which AI tools and models do you work with?

The pilot runs agents on Claude Code and Codex, and reviews run on a different model than the one that wrote the code, so no model checks its own work. The audit covers whatever your teams use today, including Copilot and Cursor. Issue trackers, source control, and CI connect through swappable adapters, so the framework is built to fit GitHub, GitLab, Jira, or Linear.

Is it safe to let agents work on our codebase?

That's the point of the governance layer. Agents work in isolated environments, every change gets independent review, autonomy is set by policy, and every step is signed and auditable. You decide how much runs automatically and where a human signs off.

Do the engagements have to happen in order?

No. Most clients start with the audit because it scopes everything after it. If you already know where you want to go, we can start with the pilot or the Decision Context Engine directly.

Start with the audit.

Two to three weeks to find out where AI is actually helping your delivery, and a scoped plan for what comes next.

start --audit