Agent Readiness Index

Know the risk.
Earn the speed.

See where to pilot coding agents, what to improve, and what still needs testing.

Local static scanSource stays on your machine for the baseline. Opt-in commands need customer-controlled network policy.
Evidence, not opinionEvery finding points to a rule and repository evidence.
Comparable over timeVersioned standards separate repository change from rubric change.
01 · The executive question

“Where can we introduce coding agents with confidence?”

ARI gives CIOs and CTOs an evidence-backed view of repository health, change safety, and coding-agent readiness. It shows what is observable, what remains untested, and what to improve first.

“AI doesn't fix a team; it amplifies what's already there.” Strong feedback loops and loosely coupled systems realise more value; weak control systems turn more change into more instability.Google Cloud, 2025 DORA State of AI-assisted Software Development
01

Engineering foundations

Can engineers reproduce, understand, test, and safely modify the repository?

  • Setup and dependencies
  • Tests and feedback
  • Structure and knowledge
02

Change safety

What controls stand between a proposed change and an avoidable incident?

  • CI and quality gates
  • Security boundaries
  • Task and review quality
03

Agent operability

Does the repository expose the context and guardrails needed for supervised coding-agent work?

  • Tool-compatible guidance
  • Portable environment
  • Bounded permissions
04

Evidence confidence

How much was directly observed, executed, unavailable, or merely inferred?

  • Coverage disclosed
  • Proxies labelled
  • Unknowns stay unknown
02 · A layered assessment

Static evidence first. Capability only when it is actually tested.

The first pass is fast, private, and deterministic. Deeper conclusions are earned through execution and real tasks. File-presence checks alone cannot establish autonomy.

Available now · deterministic

Repository preflight

Inspects files, configuration, and available git history.

  • Reproducibility signals
  • Verification and CI controls
  • Security, file-shape proxies, docs, and agent guidance
Available by explicit opt-in

Command evidence

Runs an approved command plan in a temporary checkout copy inside your environment. It is not a security sandbox.

  • Build, tests, lint, or types as configured
  • Exit status, duration, and bounded output
  • Clean-clone and service validation remain future work
Available by explicit opt-in · limited

Bounded task trials

Repeats an approved agent and verifier command on fresh temporary copies; results never alter the static score.

  • Named agent, version, task, and harness
  • Per-attempt verifier status and duration
  • Hidden-test isolation and cost capture remain future work
No universal autonomy badge. A repository can be ready for documentation changes, guarded bug fixes, or dependency updates while remaining unsuitable for cross-system migrations or production deployment. The current scan does not assess symbol-level coupling or naming quality. Task-class results require separate evaluation.
03 · The repository report

Executive clarity, with evidence engineers can challenge.

The headline shows static readiness, three decision lenses, evidence coverage, and the assessment boundary. Priorities are ranked by gain; every technical claim remains traceable.

Live, self-contained reports generated by the product. Scroll inside the report.

04 · The portfolio decision

Do not average the payment platform with an archived utility.

Repository findings become useful to leadership when mapped to business criticality, production status, ownership, sensitivity, and repository profile. Change frequency and cross-repository dependency centrality are not yet measured.

Prioritise by criticality × readiness

Illustrative portfolio view. Red signals a high-impact system with weak static controls. Green suggests a candidate for a bounded, separately evaluated pilot. Agent-task success requires its own evaluation.

Business criticality →
payments-coreCritical · 42
claims-engineCritical · 51
policy-apiCritical · 84
identityCritical · 88
customer-webHigh · 63
agent-consoleHigh · 69
design-systemHigh · 76
notificationsHigh · 81
reporting-jobsMedium · 48
ops-scriptsMedium · 57
docs-siteMedium · 73
sdk-javaMedium · 87
Static readiness →
AI rollout map

Where bounded pilots may make sense, which tasks need empirical proof, and where foundational work comes first.

90-day investment plan

A suggested sequence from criticality and recurring static findings; owners validate effort, dependencies, and impact.

Critical risk register

Secrets, missing verification, orphaned systems, fragile setup, and unavailable evidence separated from the score.

Before / after reassessment

Re-run the versioned baseline after remediation. Review score changes alongside rubric changes; automatic portfolio trend attribution is planned.

Above: an illustrative portfolio concept. Embedded report: actual output from four fixture repositories. Open the full portfolio report ↗

05 · Choose your assessment

Start with the decision you need to make.

ARI focuses on coding-agent adoption. Repository health and change safety are also available as independent reviews, whether or not you are introducing agents.

Primary assessment

Agent Readiness Index

Where should coding-agent adoption begin? Get a repository baseline, priorities for improvement, and candidates for bounded task trials.

Scope an ARI assessment ↗
Available independently

Repository Health Review

Where is engineering friction coming from? Review setup, tests, documentation, and maintainability with your engineers, then agree the improvements that matter most.

Scope a repository health review ↗
Available independently

Change Safety Review

What controls support reliable change? Review verification, release gates, and ownership. Include deployment and rollback evidence in the agreed scope.

Scope a change safety review ↗

Choose one assessment or combine them. Each has an agreed scope, evidence requirements, and its own executive readout.

06 · Six-week ARI pilot

Baseline. Decide. Improve. Prove.

Start with 10–20 representative repositories and the coding-agent tasks you want to enable. Include critical systems and the areas engineers find difficult to change.

Week 0

Map the estate

Repository inventory, profiles, ownership, criticality, and assessment scope.

Week 1

Run the baseline

Private static scans and evidence review. Run approved verification plans by explicit opt-in inside the customer environment.

Week 1

Executive readout

Portfolio heatmap, systemic risks, AI rollout zones, and decisions required.

Weeks 2–5

Remediate

Teams address the highest-value controls with targeted support and CI feedback.

Week 6

Reassess

Measure movement, record unresolved constraints, and agree the next investment cycle.

07 · The assessment

A clear starting point for agent adoption.

ARI connects repository evidence to the decisions behind a coding-agent rollout: where to begin, which foundations need work, and which tasks need proof. Repository health and change safety inform this assessment and can also be reviewed independently.

Evidence and uncertainty visible in the executive report
Profiles identify uncalibrated repository types and keep them out of portfolio ranking
Static scanning runs locally; command execution requires explicit customer opt-in
Static agent preconditions separated from measured agent-task success
Versioned results support reassessment; portfolio trend attribution is planned

Before agents accelerate change, know what they will amplify.

Choose one business unit, 10–20 repositories, and the tasks you want coding agents to handle. ARI gives you a baseline and priorities for a measured rollout.

Scope your ARI pilot