← The ADLC library
Governance, security & compliance
A desk of the Fastpace GroundTruth library
The questions an auditor will ask, before they ask them.
Provenance, least privilege for agents, data residency and change control, plus the vertical series on regulated industries. Consistently more interested in what a control can prove than in what a vendor claims it prevents.
Governance & securityVerticalsOpen knowledge 5 articles
Articles
- What auditors will start asking about AI-written code The questions are not new. What is new is that the answers your change-management process has given for a decade quietly stopped being true, and nobody has told the auditor yet.
- What agentic delivery changes in fintech and payments Money movement has a property most software does not: the failures are irreversible and somebody else's. That changes which parts of the agentic life cycle you can adopt quickly and which you cannot.
- What the AI-native SDLC playbook gets right, and the layer it leaves out Anthropic has published a six-stage model for building software with agents. The diagnosis is correct and the artifacts are the best version of that idea anyone has shipped. Two things are missing, and both are load-bearing.
- Audit chains explained without the crypto hype Strip away the marketing and a tamper-evident log is a very old, very boring idea that fits on a napkin. Worth understanding, because the boring version is the one that holds up.
- Proving what an agent did, six months later The question is never asked on the day. It is asked half a year later, by someone who was not there, about a change nobody remembers, and your answer has to survive that.
The other desks
Delivery & program intelligenceWhat the numbers do when agents arrive. Engineering leadershipWhat happens to the people when the code writes itself. Product & acceptance criteriaDone, defined precisely enough that a machine can check it. Platform economics & toolingWhat this actually costs, and what it is worth.