← AI Feed
AI Feed

Nobody had to form a view

Two places where responsibility is settled and neither reads the other, four quarters in which output rose and review slowed, and skill chains that pass every scanner one skill at a time.

How we organise

Where accountability lives in agentic software development

Responsibility is settled in two places that never refer to each other: the platform controls that say what an agent may do, and the terms that say who answers for it. Across four coding tools and eighteen policy documents they disagree. One provider’s agent approves pull requests and dismisses reviews.

We ask a team to record every decision it waits on from outside, with a named decider on each side. An agent can be named, so the register comes out complete. It never records whether that name can form a judgement. Farrag read policy, not practice.

How we build

DX on four quarters of engineering output

Across 500-plus organisations, median output per engineer rose 37 per cent in four quarters. Pull requests nearly doubled in size, review turnaround slowed, and the developer experience index fell.

Our position is that the constraint on a team is checking work rather than producing it, so cheaper output piles up in front of the reviewers. These figures show that happening. Microsoft measured the same rise and found no quality cost, so both readings stand. DX sells the measurement.

How we assure

Chains built from skills that each pass the scanner

Two attackers were built against an agent skill marketplace, one knowing the victim’s installed skills and one knowing only a role. Both search for a chain whose individual lures name nothing suspicious. Chains formed in up to 83.3 per cent of attempts.

We judge an agent on three things at once: what untrusted material reaches it, what private data sits in reach, and how anything gets out. All three describe one agent. This risk belongs to a chain across several, each of which passed its own controls. The benchmark is the authors’ own.