Function cockpit
Engineering
Agents build, test and document. Engineers own architecture and release.
Phase: Phase 3 — Functional orchestration
Run the intent-to-release graph as a governed system: decomposition, code generation, testing, documentation, vulnerability detection and deployment preparation are agent work; product intent, architecture and production release remain human.
Trust score
0
Touchless
0%
Human review
0%
Override rate
0%
Capacity released
25-40% engineering capacity in selected software-factory settings (case-specific)
Accountable human
Chief Technology Officer
CoS agent: Engineering Chief of Staff
Gates, kill switches, and the decision ledger
Governance
Autonomy is only defensible if the brakes are documented
Every gate below names a threshold, an approver, and a clock. Everything the function has decided recently sits in the ledger underneath, whether a person or an agent made the call.
Active gates
0
Pending decisions
0
Approved this cycle
0
Contained or reversed
0
Gate register
The conditions under which an agent must stop and ask.
| Gate | Trigger threshold | Approver | SLA | Waivable |
|---|---|---|---|---|
Production release authorization Approval gate | Any deployment to a production environment | Release manager and service owner | 1 business day | Hard stop |
Security-sensitive or public API change Approval gate | Authentication, cryptography, payment paths or any published interface contract | Senior engineer and security engineer | 1 business day | Hard stop |
Database migration Approval gate | Any schema change or irreversible data operation | Data owner and CTO delegate | 2 business days | Hard stop |
Agent-authored code sample review Oversight | Weekly review of 10% of agent-authored merged changes | Engineering governance | Weekly | With written rationale |
Decision ledger
Immutable record of what was decided, by whom, and how long it took.
- Approval gate
Payment service release pack awaiting authorization
PendingHighRelease Agent assembled the deployment plan, rollback rehearsal evidence and test attestation for the payments service. Two moderate findings remain open and are documented in the pack.
Release manager · 9d 6h ago
Requester can escalate only at this materiality - Escalation
Secret detected in candidate branch
ContainedHighSecurity Agent detected a live credential in a feature branch, blocked promotion, revoked the token through the identity service and opened an incident record.
Security Agent · 9d 7h ago
- Notification
Dependency batch updated autonomously
Auto-executedLowDeveloper Agent applied 23 low-risk dependency updates with full regression passes and provenance recorded against each change.
Developer Agent · 9d 9h ago
- Escalation
Legacy migration equivalence gap
PendingMediumMigration Agent found behavioral divergence in an interest-calculation routine during translation. Work paused and the divergence packaged for the owning architect.
Principal architect · 9d 12h ago
Requester can escalate only at this materiality
Kill switches
Named, tested, and reachable in one click by the accountable human.
- Unexplained dependency introduced into the build
- Secret or credential exposure detected in a diff
- Test bypass or coverage suppression
- Architecture-policy violation in a merged change
- Rising incident rate after an agent-prepared release
Human accountability
Cannot be delegated to an agent at any autonomy level.
- Architecture and platform standards
- Requirements acceptance and product intent
- Safety-critical code and threat decisions
- Breaking changes and public API contracts
- Production release and irreversible data migration
Signs for this function
Chief Technology Officer