Shefing AI asset · Software engineering
Shefing iSDLC™
Agile reworked for the agent era.
A 7-stage lifecycle in which humans own intent, risk and accountability, while agents execute against versioned, machine-readable context.
- 1Goals
- 2Requirements
- 3Design
- 4Architecture
- 5Coding / CI / Testing
- 6IaC / CD
- 7Observability
AI shifts the bottleneck from writing code to steering and verifying it.
Intent made explicitEvery deliverable verifiableA tamper-evident record of who decided what
The lifecycle
Seven stages. Humans hold the gates.
Agents draft, build, test and watch production. At every stage that carries risk, a named person decides, and that decision is recorded.
01
Goals
Human sets intent
02
Requirements
Human sign-off
03
Design
Agent-led, human review
04
Architecture
Human sign-off
05
Coding / CI / Testing
Agents build, tiered gates
06
IaC / CD
Human gate on data & security
07
Observability
Agent-led, human accountable
agent-led human gate
Main features
Runnable, not just documented.
Seven mechanisms turn "humans in the loop" from a slogan into something a team can run and an auditor can check.
Manifesto · 12 principles
Agile's values, amended
- Human accountability and managed context over individuals and interactions
- Verifiable software and agent-ready context over working software
- Explicit intent over collaboration
- Architectural fluidity over responding to change
Inner loop
Plan → Build → Review
Humans author the plan: objective, Gherkin acceptance criteria, a DO-NOT list, context refs. Agents execute inside those boundaries. A cross-model review closes the loop: FAIL blocks, and every WARN needs a scribed human approval.
Executable workflow
15 skills, shipped as a Claude Code plugin
The methodology runs, it isn't just documented.
- audit
- goals
- requirements
- spec
- wireframe
- architecture
- plan
- build
- tdd
- review
- qa
- security
- redteam
- ship
- observe
Accountability spine
An append-only, hash-chained trail
Records adoption, decisions, review verdicts and deploys, and flags commits that arrive with no justifying evidence. Agents may propose. Only humans attest.
Context substrate
A fresh agent onboards in 60 seconds
STATE.md · SPEC.md · AGENTS.md · QUIRKS.md · ADRs · TECH_DEBT.md · llms.txt, kept current by rule. A doctor command verifies presence and freshness.
Two entry doors
Greenfield, or audit first
Start clean, or onboard an existing codebase by paying down context debt first: SBOM, CVE baseline, secret scan, license and EOL audit, before any agent gets repo access.
Guardrails
Deliberation is never automated away
Nothing auto-writes a plan, auto-approves a PR or bypasses a red gate without an explicit human override plus an ADR. Tiered gating scales ceremony to risk.
Regulation
A core foundation for the EU AI Act
The Act asks software teams for human oversight, traceability, risk management and documentation. iSDLC produces all four by construction, as a by-product of how work gets done.
Article 14
Human oversight
Article 12
Record-keeping and traceability
Article 9
Risk management
Article 11
Technical documentation
Obligations depend on the risk class of your system. iSDLC gives you the evidence and the controls; qualifying a specific system remains a legal assessment.
Bring iSDLC to your team
We run it on our own delivery and stand it up inside yours.
Talk to us← Back to our AI assets