Matrix/Delivery Management

Delivery Management

How we manage delivery in the age of agents. From human PR review to autonomous delivery pipeline.

4capabilities20levels60practices60guides
The matrix · full map
Capability ↓
Maturity →
L1 · Stage 01
Assisted
L2 · Stage 02
Delegated
L3 · Stage 03
Systematic
L4 · Stage 04
Governed
Sweet spot
L5 · Stage 05
Self-improving
01·15 guides
CI/CD Pipeline→
Speed and reliability of your build-test-feedback loop for AI-generated code
CI runs; everyone waits
3 practices·3 guides→
Ten minutes, runners per team
3 practices·3 guides→
Five minutes, a pipeline per worktree
3 practices·3 guides→
Two minutes in an isolated microVM
3 practices·3 guides→
Feedback in seconds, capacity on demand
3 practices·3 guides→
02·15 guides
Merge & Deploy→
How PRs flow from creation to production - throughput, automation, and conflict handling
Every merge has a human in it
3 practices·3 guides→
A queue does the rebasing
3 practices·3 guides→
Policy decides what merges, and when
3 practices·3 guides→
Green auto-merges straight to production
3 practices·3 guides→
A thousand merges a week, agent-driven
3 practices·3 guides→
03·15 guides
Metrics →
What you measure to understand AI-assisted engineering productivity and quality
DORA at best; AI still unmeasured
3 practices·3 guides→
Token spend is finally on a dashboard
3 practices·3 guides→
You know your cost per merged PR
3 practices·3 guides→
Every agent run ends in a known state
4 practices·4 guides→
Cost per feature, value per token
2 practices·2 guides→
04·15 guides
Governance & Compliance→
Controls around AI-generated code - licensing, security scanning, and audit trails
Personal subscriptions, no policy
3 practices·3 guides→
A policy exists and spend has caps
3 practices·3 guides→
Every agent action leaves a trail
3 practices·3 guides→
Provenance is cryptographic, checks automated
3 practices·3 guides→
Compliance watches the regulators for you
3 practices·3 guides→
Climb the matrix

You don't have to figure this out alone.

Every level in this matrix has a path. Read the playbooks the teams that have climbed it wrote. Run the assessment with our consultants. Start where you are.

Live with Visdom

Book an AI Maturity Assessment session with your team.

We walk you through all four perspectives, score where you actually are, and leave you with a 90-day plan to climb in the dimensions that matter most.

Book an assessment →See what's included90-day plan - scored assessment - coaching
Author Commentary

Delivery's September story is where governance physically lives.

For most of the year it lived in a policy document and in each tool's settings screen. It now lives in the AI gateway. Kong AI Gateway 2.0 puts many MCP servers behind one route and shows each caller only the tools it may use, with one identity carried across rate limiting, cost attribution and access control. Claude Code added exact-version model pinning, hard model denies and a prompt-ID header so a gateway can group every request behind one user prompt - which is commit-to-prompt lineage for free. Copilot now makes admins pick a default for new features before they switch themselves on. And then LiteLLM's MCP auth bypass landed on the CISA Known Exploited Vulnerabilities list: any bearer token got a fully authorised session. The lesson is not to avoid gateways. It is that the gateway is now the most important box in your delivery path, and it needs an owner, a patch SLA and CVE monitoring like any other critical infrastructure.

Identity reached the merge path too. An agent commit should come from a distinct bot identity with a short-lived GitHub App or OIDC token, never from a developer's account, and GitHub's new proof of presence asks for a fresh re-authentication before token creation or webhook edits - small friction exactly where stolen tokens do their damage. The case for all of this is written in EY's survey of 202 large US companies: 98% have formal AI governance policies, 47% skipped them for urgent deployments, and 26% cannot detect unauthorised agents. A policy the fast path can skip is not a control. The fix is not a stricter document, it is making the urgent path run through the same gateway as every other path.

Metrics got two corrections. Meta dropped AI usage from engineer performance reviews and scrapped a token leaderboard covering 85,000 employees - last month's anti-pattern, confirmed at the largest scale available. And cost per iteration needs a new denominator. Gemini 3.8 Flash kept its token price, yet cost per task rose from $0.40 to $0.58 because it takes more steps, and Anthropic's own data has Claude working 3.3x longer per prompt than in March. Price per token tells you what the vendor charges. Cost per task tells you what you pay. Meanwhile CircleCI's numbers across 28M workflows show main-branch success at a five-year low of 70.8% while throughput rose 59%, which is the argument for moving verification before the PR opens and letting CI check evidence instead of re-running everything.

Other perspectives