davidfacer.com / aimaturitymodels.com / AI-Native Maturity Models / AI-Native SDLC / D11

Under review. Whole dimension carries deferred/research status in the locked baseline — not yet research-complete, see this model's own README

Security & compliance

An AI agent with shell access can do, in seconds, what would once have taken a person with bad intentions real time and effort. This dimension asks the question that follows from that fact directly: what actually stops an agent from doing something destructive, unauthorized, or simply wrong — and is that protection real, or assumed?

This entire dimension carries an open flag. The locked baseline marks it deferred for further research — what follows is a structured draft derived from the existing A–E ladder, not a claim that the research is complete. Read it as the current best draft, not settled ground.

Where most organizations start (Nascent)

Agents execute with unrestricted access to the filesystem, shell, and network — no sandboxing, no pre-execution validation of dangerous operations, and no agent-specific identity, meaning agent activity is indistinguishable from the human who launched it. The first real step is containment: sandboxing, filesystem and network restrictions, pre-execution checks for dangerous patterns, and deterministic security scanning on everything generated, regardless of origin.

Where the real gains happen (Modeled → Integral)

The meaningful shift is giving agent activity a distinct, auditable identity — per-agent or per-session credentials, every agent-authored change traceable to a specific session and initiating human — rather than agents quietly acting under shared human credentials. The bigger gain beyond that is moving from attributable-but-bypassable controls to centrally enforced gates: required checks that can't be individually overridden, with agent tooling itself — skills, plugins, MCP servers — inventoried as supply-chain surface subject to the same scrutiny as any other dependency.

What the top of the curve actually looks like (Telemetric)

At full maturity, security policy is enforced at the point of action, not just before or after it — least-privilege scoping and runtime guardrails constrain what an agent can actually do while it's doing it, with a real-time termination capability if something goes wrong mid-action. Shared memory and context are actively monitored for injected or anomalous content, not just tagged with provenance after the fact.

Why this dimension matters

Strong code review (D8) answers "is this code good." It does not answer "was this agent allowed to run that command in the first place" — that's a different surface entirely, and this dimension is where it's governed. No amount of maturity elsewhere compensates for this one being weak.


Drafted from the SDLC model's real locked content — including the transition and verification notes now folded into ai_native_sdlc_maturity_model.md itself (2026-07-27). D11 carries the family's most significant open review flag: the entire dimension is marked deferred/research-incomplete in the locked baseline — read accordingly.

Drafted from the AI-Native SDLC model’s real locked content, per Option A (ship now, label the gap above).

Feed This to Your AI© 2026 David Facer