Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics measure AI ROI and engineering health?
Updated
ShipReady Metrics reports AI ROI, delivery (DORA), AI-authored-code share, per-committer metering, and a coverage-weighted engineering risk composite from connected systems — labeling gaps Not measured and figures as estimates, not audited financials.
Product measurement guide, last verified 10 September 2026 against ShipReady Metrics /methodology and /what-we-measure, DORA and SPACE frameworks for method context, and GitHub Copilot Metrics API documentation for the optional ingest path. Not legal advice.
What this page covers — product behavior, not marketing
Audience: a buyer, CTO, or engineering leader evaluating what ShipReady Metrics actually reports about AI ROI and engineering health. This page describes shipped capabilities and honest limits. It is not legal advice. SRM figures are measurements and estimates from declared inputs and granted provider signals — gaps labeled Not measured — not audited financial statements, not tax advice, and not guarantees of return.
Frameworks like DORA and SPACE explain what kinds of signals matter in the industry. ShipReady Metrics' scoring choices are SRM recommendations documented on /methodology — not industry standards.
Capability map — what ships today
The table below lists real product surfaces. Capabilities not listed are not claimed.
| Capability | What it measures | Data source | Honest limit |
|---|---|---|---|
| AI ROI scoring | Value factors (productivity, spend efficiency, value realization) graded 0–100 | Org-entered AI ROI inputs, optional Copilot Metrics API ingest, AI-vs-human PR cohort when scan enabled | Figures are estimates labeled as such; not audited financials |
| Copilot Metrics ingest | Org-level Copilot usage (active users, suggestions, acceptances) over trailing 28-day window | GitHub Copilot Metrics API when org grants Organization Copilot Metrics scope | Adoption context only — does not alone prove ROI; shows Not measured without scope |
| Per-team AI ROI | Team-level AI ROI from PR cohort comparison when sample size allows | Per-team GitHub sync with E17.3 cohort minimums on each cohort | Below minimum PRs per cohort, shows insufficient sample — not a grade |
| Trial AI-ROI entitlement | Time-limited access to AI ROI scoring on eligible plans | Product entitlement flag | Trial access is not a financial audit |
| AI-authored-code floor | Lower bound on AI-attributed commits from git markers — not a statistical classifier | Commit history with AI attribution markers | Counts attributed commits; does not detect all AI code with certainty |
| DORA metrics (Delivery Health) | Deployment frequency, lead time, change failure rate; MTTR when ops source connected | CI and deployment events from connected providers | Production-only; Not measured when deploy signal missing |
| Per-committer metering | Distinct committers in rolling 90-day window for plan metering | Git author identity on connected repos | Metering for billing — not a productivity score |
| Engineering risk score | Coverage-weighted composite of domain scores (delivery, security, debt, lifecycle, cloud, modernization) | Connected connectors over repository scope | SRM methodology — not an industry standard or audit opinion |
AI ROI scoring — method and labels
AI ROI grades when at least one value factor has inputs. Productivity can use AI-vs-human PR cohort deltas when the authorship scan is enabled and cohort minimums are met. Spend efficiency can use declared AI tool spend and Copilot seat data when available. Value realization can use declared business value inputs.
Hours saved left blank may be estimated from AI-assisted code share and headcount — the UI labels estimates explicitly. Self-reported inputs are labeled self-reported and not independently verified. Nothing in AI ROI is an audited financial statement.
Signed-in admin AI ROI inputs (/admin/ai-roi) are a first-party source the score grades from. Copilot Metrics ingest is optional on the same GitHub connection — it requires org-admin Copilot Metrics scope; without it, adoption-related factors stay Not measured rather than guessed.
- Per-team AI ROI uses the same E17.3 cohort minimums as the org-level PR cohort table — each cohort needs enough merged PRs before a delta is shown.
- Trial AI-ROI entitlement unlocks scoring on eligible plans for evaluation; it does not change the estimate nature of the figures.
- AI ROI export and board views tag figure kinds (observed, estimated, self-reported) where implemented.
AI-authored-code floor — provenance, not detection
The AI-authored-code floor counts commits with AI attribution markers in git history over eligible repositories. It is a measured lower bound from provenance metadata, not a machine-learning classifier that labels every line as human or AI.
The floor appears on signed-in AI Code and Readiness surfaces. It informs AI ROI context and adoption estimates. It does not determine legal ownership of code output and is not legal advice.
DORA metrics and engineering health
Delivery Health implements DORA metrics from connected deployment and version-control sources using production-only filtering — consistent with DORA program definitions (see dora-metrics-explained on this site). DORA provides the method context; SRM's filtering and coverage gates are vendor choices.
Engineering health in SRM is the set of Engineering Excellence domain scores plus AI domains when connectors or telemetry are available: Technical Debt, Security Readiness, IT Modernization, Lifecycle Risk, Delivery Health, Cloud Health, AI Readiness, AI ROI, and Agent Health. Each domain is independent; unmeasured domains are visible gaps.
SPACE framework guidance reminds readers not to collapse health to a single number — SRM shows multiple domains for that reason.
Per-committer metering
Billing uses distinct committers with non-bot git activity in a rolling 90-day window on connected repositories. Committers who only review, administrators who do not commit, and bots excluded by rules are not counted as committers for metering.
Metering is a plan unit — not a developer productivity metric and not input to AI ROI scoring.
Framework method versus SRM product choices
DORA defines delivery throughput and stability metrics — industry research guidance. SPACE defines multidimensional developer productivity — industry research guidance. ShipReady Metrics selects which of those signals to implement, how to filter production deploys, when to withhold scores for thin coverage, and how to weight domains in the composite. Those choices are SRM recommendations on /methodology, not certifications from the DORA or SPACE authors.
What you need to do now
As of last verification on 10 September 2026. Not legal advice.
- Connect GitHub (or other providers) with the scopes you are willing to grant; Copilot Metrics requires org-admin Copilot Metrics scope.
- Enter AI ROI inputs you are willing to stand behind, or accept labeled estimates where the product offers them.
- Enable the AI authorship scan if you want PR cohort comparisons — understand it uses attribution markers, not certainty.
- Review repository scope so engineering scores reflect the repos you intend.
- Read the measure-ai-coding-roi guide on this site for ROI methodology depth. The measure-ai-developer-productivity guide on this site covers SPACE-aligned productivity. The dora-metrics-explained guide on this site covers delivery metrics. The engineering-risk-score-explained guide on this site covers the composite.
Checklist
Evaluation checklist for buyers — not a warranty and not legal advice.
- Do we know which figures are measured, estimated, or self-reported?
- Is Copilot Metrics connected or honestly Not measured?
- Do per-team AI ROI views meet cohort minimums before we cite them?
- Are DORA metrics computed from production deploys we recognize?
- Which engineering domains are Not measured in our estate?
- Have we avoided quoting AI ROI dollars as audited financials?
Where this shows up in ShipReady Metrics
Signed-in /scores/ai-roi — AI ROI score, cohort table when eligible, labeled inputs and estimates.
Signed-in /admin/ai-roi — org AI ROI assumptions and Copilot Metrics connection status.
Signed-in /scores/delivery-health — DORA metrics and Delivery Health grade.
Signed-in AI Code and Readiness report — AI-authored-code floor from attributed commits.
Signed-in /admin/committers — per-committer metering for the active-committer plan unit.
Signed-in /dashboard — ShipReady Score composite and domain cards with coverage headline.
Signed-in team pages — per-team AI ROI card when cohort minimums are met.
This product does not file regulatory reports, does not certify ROI, and does not provide legal classifications of AI systems.
Primary sources (last verified 10 September 2026)
ShipReady Metrics /methodology and /what-we-measure — authoritative vendor documentation for platform behavior. SRM recommendation.
DORA research program (dora.dev, Accelerate, State of DevOps reports) — delivery metric method context.
SPACE framework (Forsgren et al., ACM Queue, 2021) — multidimensional productivity method context.
GitHub REST API — Copilot Metrics endpoints (organization-level usage metrics); optional ingest path, requires org-admin scope.
Not legal advice. Not audited financial guidance.
Frequently asked questions
Are AI ROI dollars audited financial figures?
No. AI ROI scores and any dollar translations are measurements and estimates from declared and self-reported inputs, labeled by kind; connector-backed signals stay Not measured until granted. They are not audited financial statements and not tax or legal advice.
Does ShipReady Metrics detect all AI-generated code?
No. The AI-authored-code floor counts commits with AI attribution markers in git history. It is a provenance-based lower bound, not a classifier that labels every line with certainty.
Why is per-team AI ROI sometimes blank?
Per-team AI ROI requires enough merged pull requests in each cohort to meet E17.3 minimums. Below that threshold the product shows insufficient sample rather than a misleading grade.
Is the engineering risk score a DORA certification?
No. Delivery Health uses DORA-style metrics from your deploy data. The composite engineering risk score is ShipReady Metrics' vendor methodology — not a DORA program certification and not an industry standard.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.