Maturity Matrix
Capability 04 of 04 · Delivery Management

Governance & Compliance

Controls around AI-generated code - licensing, security scanning, and audit trails.

5
maturity levels
15
practices
15
guides
L4 · Stage 04OptimizedMost teams aim here
Criteria - what to measure
  1. 01Full provenance tracking per change: model version, prompt context, agent session ID, iteration count
  2. 02Automated compliance checks run without manual intervention on every merge
  3. 03AI-generated code is distinguishable from human-written code in version control (metadata, labels, or attribution)
  4. 04Provenance data is queryable (e.g., "show all changes made by model X in the last 30 days")
  5. 05Compliance check results are aggregated into a governance dashboard
L5 · Stage 05Autonomous
Criteria - what to measure
  1. 01Continuous compliance: agent monitors regulatory changes (EU AI Act updates, SOC2 changes) and proposes policy updates
  2. 02Audit trail is self-documenting (agent decisions include reasoning, not just outcomes)
  3. 03Enterprise-grade RBAC is enforced per agent (Stripe Toolshed model: each agent has scoped permissions for specific tools and repositories)
  4. 04Policy update proposals from compliance agent are auto-tested against existing codebase before rollout
  5. 05Agent RBAC permissions are audited automatically for least-privilege compliance

Which level is your team at in Governance & Compliance?

The criteria above are what we check in a facilitated assessment. Run it yourself to place this capability, see which gates you have passed, and compare it against the other 3 in Delivery Management.

Start the assessment →

Other capabilities in Delivery Management