The AI-SDLC loop, layer by layer.
One loop, four depths. Each control adds a layer: the idea, the platform harness, the mechanics, then the full engineering view.
The cited validation outline
Three-way validation, 2026-08-02. Every external link fetched and verified live with a ctrl-F-able quote. Independently fact-checked.
HOW TO READ THIS
Every practice on the boards was pressure-tested against public industry standards by independently prompted validation agents, each required to fetch the source live before citing it. The industry half of that validation is reproduced here with its sources.
AGAINST INDUSTRY STANDARD
What checks out
- The plan-draft-decide-live-learn loop matches continuous delivery practice: DORA ("release changes of all kinds on demand quickly, safely, and sustainably").
- Sandboxed agents with guardrails, and a human decision gate before production, match published agent guidance: Anthropic agent engineering ("extensive testing in sandboxed environments, along with the appropriate guardrails"; "pause for human feedback at checkpoints").
- Per-branch preview environments are standard review-app practice: GitLab review apps ("temporary testing environments that are created automatically for each branch").
- The digest-bound evidence manifest maps to build provenance, stronger than the typical approve-the-PR gate: SLSA provenance.
- Agents having zero production capability is least privilege, applied more strictly than most teams bother to: NIST ("to the minimum necessary to accomplish assigned tasks").
- The reserved-tenant canary and progressive rollout with analysis-driven abort are standard: Google SRE canarying; Argo Rollouts.
- Deterministic CI proof gates match test-automation practice (DORA); privacy-safe secure-by-construction matches NIST SP 800-218, the SSDF.
- Golden-path templates, W3C trace context, and policy as code are all standard: Backstage; W3C Trace Context; Open Policy Agent.
Honest flags
- Review queue time as a first-class parity metric is our own insight, not one of DORA's headline metrics; kept, honestly labeled: DORA metrics guide.
- Hardening candidates: name a SLSA level for the manifest, enforce it at deploy time with attestation-gated deploys, and require hermetic, reproducible builds (Google SRE release engineering).
PROVENANCE
Produced by three independently prompted validation agents on 2026-08-02, each required to fetch every external URL before citing it. Every link was machine-checked, and a fourth independent agent fact-checked every citation and quote in a first draft; it found four issues, all corrected in this version. Across the pass, 38 external sources were checked and all 38 held, and 31 quoted passages were verified word for word.