Engineering
Vendor-neutral guidance for CTOs, CISOs, and engineering leaders on AI-generated code security, measurement, governance, DORA metrics, technical debt, and engineering health. Not legal advice. Does not certify your codebase or determine regulatory applicability.
Is AI-generated code secure?
Evidence on AI-generated code security: failure modes, empirical study caveats, OWASP and NIST SSDF guidance. No absolute secure or insecure claim. Not legal advice.
How do you measure AI-generated code risk?
A defensible framework to measure AI-generated code risk: signals, metrics, and trend thresholds (recommendations, not standards). OWASP, NIST SSDF, DORA. Not legal advice.
How can you detect AI-generated code?
How AI-generated code can and cannot be detected: provenance and telemetry versus probabilistic classifiers, with false-positive and false-negative caveats. Not legal advice.
How do you measure human vs AI-generated code?
Measure human vs AI-authored code share with an explicit denominator (lines, commits, or PRs). Pitfalls, Goodhart warnings, and an illustrative example. Not legal advice.
Does AI coding increase technical debt?
DORA, GitClear churn, SEI debt literature, and Accelerate on AI-assisted coding and maintenance cost — with correlation vs causation caveats. Not legal advice.
How do you measure AI coding ROI?
AI coding ROI: licences, review, remediation vs throughput and cycle time — vanity-metric traps and an illustrative example. SRM figures are estimates. Not legal advice.
How do you measure AI developer productivity responsibly?
AI-era developer productivity with DORA and SPACE at team and system level — not individual ranking. DevEx dated; McKinsey/DX as opinion. Not legal advice.
How do you detect security issues introduced by AI coding agents?
AI agent failure modes — secrets, injection, bad deps, insecure config — mapped to SDLC controls. OWASP, NIST SSDF 800-218A, CWE, CISA, KEV, EPSS, CVSS. Not legal advice.
What is an AI coding governance checklist?
AI coding governance checklist: approved tools, provenance, review gates, secrets and IP. Mapped to ISO/IEC 42001, NIST SSDF and AI RMF. Not legal advice.
What should an AI coding policy include?
Editable AI coding policy template: scope, approved tools, data and IP rules, review, provenance, exceptions, cadence. Mandatory vs recommended. Not legal advice.
How should you review agent-generated pull requests?
Review agent PRs: risk-tier table, reviewer checklist, branch protection, SAST and provenance. OWASP, NIST SSDF, DORA, SLSA. Org practice vs SRM. Not legal advice.
How should you measure technical debt?
Measure technical debt with proxy signals — churn, complexity, defects, remediation cost — each with blind spots. No single authoritative number. SEI, ISO 25010, DORA.
How do you measure engineering excellence without gaming the score?
Measure engineering excellence with DORA, SPACE, reliability, and ISO/IEC 25010 — balanced across delivery, quality, and people. Anti-Goodhart guidance. Not legal advice.
What are DORA metrics and how do you calculate them?
DORA metrics: deployment frequency, lead time, change failure rate, time to restore. DORA program definitions, worked examples, benchmark caveats. Not the EU DORA regulation.
How is an engineering risk score calculated and what can you trust?
How ShipReady Metrics builds an engineering risk score: inputs, weighting, denominators, coverage-as-confidence, and how to read it honestly. SRM methodology — not a standard.
How does ShipReady Metrics measure AI ROI and engineering health?
How SRM measures AI ROI and engineering health: Copilot Metrics ingest, AI-authored floor, DORA metrics, committer metering, engineering risk score. Estimates, not audits.