Skip to main content
Back to Home
1. Product2. Agents3. Governance4. CloudOps5. FinOps6. Security
AI + Data + Cloud · Pillar 6
🔒

Security & Quality

Adoption & Scaling

6,298Real Tests

6,298 real tests. 104K lines of mock theater deleted. SOC2 + APRA CPS 234 alignment. Zero testing theater.

First SAST scan in <2 minutes via container
AI agents build governed & Humans ship trusted. 80% autonomy & 100% accountability.
Section Six (Ch.28-32)

The Keys to Unlock Adoption and Scaling

For every $1 you spend on developing a digital solution, plan to spend at least another $1 (and sometimes more) to ensure full adoption and scaling. That additional $1 will go toward implementing process changes, user training, change management initiatives.

Chapter 31: Managing risk and building digital trust. Beware of the new risks introduced by your digital and AI transformation into areas such as cybersecurity, data privacy, and AI biases. ADLC addresses this through deterministic hook enforcement, APRA CPS 234 + SOC2 alignment, supply chain SBOM, and the Testing Theater anti-pattern elimination.

Source: Rewired: The McKinsey Guide to Outcompeting in the Age of Digital and AI (Lamarre, Smaje, Zemmel, 2023)

Platform Evolution

AI vulnerability detection improves with model updates. NemoClaw kernel-level sandboxing adds hardware-enforced boundaries. Anti-pattern catalog grows with each incident.

Component Map

9 components implementing this pillar

TypeNameWhyBusiness Value
Agentsecurity-compliance-engineer (opus)SOC2, APRA CPS 234, ISO 27001, PCI-DSS compliance gatingRegulatory risk caught at design — not after audit
Agentqa-engineer (sonnet)3-tier test strategy: snapshot / LocalStack / AWS live90-100% bug detection before production deployment
Agentdevops-security-engineer (sonnet)CI/CD supply chain hardening, SBOM, Trivy scanningSLSA Level 2+ provenance on every release
Command/security:sastSAST + container scanning via nnthanh101/terraform:slimZero critical/high vulnerabilities before merge
Skilltesting/3-mode-validationPlaywright + AWS MCP combined accuracy gate (>=97%)Two independent sources — SELF_COMPARISON_VALIDATION prevented
Skilltesting/battle-conftestL1 (--help) / L3 (real READONLY) battle test tiersDRYRUN_OVER_READONLY prevented — real API validation
Skillbdd/feature-coverageBDD scenarios with pytest-bdd step definitionsBusiness language tests that non-engineers can read
Hookdetect-testing-theater.shBlock mocks without assertions, coverage omit expansion6,298 real tests — 104K lines of mock theater deleted
Hookdetect-hardcoded-env-data.shBlock AWS account IDs, org IDs in product docsHARDCODED_ENV_IN_PRODUCT_DOCS eliminated from git history

Risk & Scalability

What happens without this pillar, and why ADLC scales from 1 person to enterprise

What if you skip?

McKinsey: “For every $1 you spend on developing a digital solution, plan to spend at least another $1 (and sometimes more) to ensure full adoption and scaling” (Rewired S6, p.287). Chapter 31 warns: “Beware of the new risks introduced by your digital and AI transformation into areas such as cybersecurity, data privacy, and AI biases” (p.288). Without security and quality gates, adoption fails because users don’t trust the system.

Scalability

Testing theater detection and supply chain enforcement are automated via hooks. Coverage gates are honest (fail_under measured, not estimated). The quality bar is the same whether shipping a PyPI package or deploying to production AWS accounts.

Industry Relevance

ANZ enterprise verticals where this pillar is most critical

FSI
APRA CPS 234 + SOC2 Type II audit evidence generation
Energy
NERC CIP-013 supply chain security with SBOM attestation
Telecom
GSMA security accreditation for network function virtualization
Aviation
DO-178C Level A requires 100% structural coverage — no theater allowed

Continuous Improvement Flywheel

Each pillar feeds the next — creating a self-reinforcing cycle of capability building

Pillar 6 feeds Pillar 1
Security & QualityProduct Management

Quality metrics and security posture feed back into the business roadmap — closing the continuous improvement loop.

Digital Products

Real products built and governed by this pillar

Explore Pillar 6 Components

Browse the full component catalog or read the documentation

AI agents build governed & Humans ship trusted.