Skip to content

root / tags / intercom

#Intercom

2 fiches

Quality & Security Auto-verified translation

Anthropic sécurise un SDLC où l'IA écrit 80 % du code : le cycle redevient le socle

SFEIR's decryption (firm voice) of Jason Clinton's (Deputy CISO, Anthropic) debrief published five days earlier — already documented in [[clinton-anthropic-secure-ai-native-sdlc-2026-07-21]]. **The added value lies not in the facts but in the thesis that rereads them**: if Anthropic's controls hold, it is because **a cycle with named stages exists to hang them on** — "the SDLC is the foundation, not a formality." The demonstration proceeds by rereading the mapping (**PSR at Plan, CLAUDE.md + egress allowlist at Code, review agents at Test, continuous DAST at Deploy, triage + SIEM routing at Monitor**), then through a **four-part anaphora**: (1) *without an SDLC, productivity gains do not materialize* — Clinton cites **Amdahl's law**: multiplying code volume by 8 multiplies nothing if review stays sequential and human, and Anthropic gained not by distributing agents but by **identifying the blocking stage (Test) and rebuilding it** — "you don't optimize a bottleneck you haven't mapped" (echoing DORA 2025's **mirror effect**); (2) *without an SDLC, security has no anchor point* — a **gate is by definition a control placed between two stages**, and Clinton's three threats are addressed at distinct moments; (3) *without an SDLC, no **token FinOps** policy can be formulated* — agentic scanning is billed on consumption and grows with code throughput, so **risk-based tiering IS the FinOps policy** (it decides where three agent passes get paid for and where a SAST suffices), otherwise "token spend is not steered, it is discovered at month's end"; (4) *without an SDLC, there is nothing to measure* — the indicators (16% → 54% of PRs commented, one third of past incidents intercepted) exist only because there are stages where a counter can be placed; absent that, one produces only **usage figures** (licenses, tokens) that say nothing about quality or risk. Two strong points beyond the thesis: the reading of the **incident agent-à-agent** ("a security perimeter that rests on an instruction in a prompt is not a perimeter"; **an agent's access to other agents is part of its attack surface**) and an **explicit methodological caveat** — Anthropic's figures about Anthropic, unaudited, published by the vendor of the model described, in the context of a young codebase with no mainframe: **what transposes is the method, not the figures**.

#SDLC#AI-native SDLC#development cycle

SFEIR (voix éditoriale du cabinet, article non signé individuellement) — commentaire de Jason Clinton (Deputy CISO, Anthropic)

AI Coding Agents & Skills Auto-verified translation

2× – nine months later: We did it

Public update from Darragh Curran (R&D, Intercom) nine months after his commitment to double R&D productivity in 12 months through AI. Result: **3x achieved in 16 months, with no signs of plateauing**. Quantified data from a 500-person R&D organization / 8.5M lines of code: **93.6% of PRs are agent-driven**, **19.2% AI-approved** (target >50%), cost/PR **-50%**, defect backlog **-54%**, time-to-shipping **-39%**, breaking-changes downtime **-35%**, top 5% of performers at **6x the median PR throughput**, **497 autonomous PRs** in the first 4 weeks, **153 contributors / 267 specialized skills** in a private *Skills-Based Plugin Architecture*. Curran declares ***"All technical work is becoming agent-first. This is the top priority for R&D."*** Pivotal article of the *agent-first organization* dossier, comparable only to Stripe Minions and StrongDM in the 2026 corpus.

#Darragh Curran#Intercom#Fin Ideas

Darragh Curran (R&D leader, Intercom — publication via Fin Ideas, plateforme média Intercom).