Konrad Kowalski (rootsher)Principal Platform & Reliability Architect001110101001000010110001001001001101001000101110

What a standardized Agentic SDLC looks like

date
category
AI Agents
also in
AI Engineering · Engineering Practices
reading
3 min / 645 words

We started with a managed agent.

We did not add services because they exist.

Each element showed up because at organizational scale a concrete problem appeared.

The Implementer Agent's final flow looks like this:

text
JIRA
issue -> Ready for AI
|
v
TRIGGER
Jira Automation / event layer
|
v
MANAGED RUNTIME
Foundry / AgentCore / Vertex
|
v
IMPLEMENTER AGENT
|
v
jira.get_issue(PAY-123)
|
v
create workspace
|
v
git clone payments-service
|
v
read AGENTS.md
|
v
need external knowledge?
|-- no
`-- yes -> RAG
|
v
implement
|
v
run tests
|
v
GitHub tool / MCP
|
v
create PR

Around this flow the organization provides:

text
models
identity
policies
state / memory
observability
security controls
evals

What the organization standardizes

AreaWhat is shared
Triggerhow agent roles are started from SDLC events
Modelsapproved models and how they are accessed
Agent templatethe base structure of an agent repo
Workspacebootstrap, clone, branch, base image
RAGshared engineering knowledge sources
Toolsapproved MCP/tools and auth
Runtimehosting, identity, scaling
State / memorythe durability mechanism
Human-in-the-looppause/resume, question channels, timeout and escalation
Observabilitytraces, logs, metrics, dashboards
Securityguardrails, DLP, tool policies
Evalshow behavior is measured and quality gates

Evals are part of the agent's normal lifecycle

Evals are not a one-off test run at the first deployment.

In practice the organization can adopt a simple rhythm:

text
every agent PR
-> small regression suite

model / prompt / RAG / tools change
-> extended suite

release
-> full regression + baseline comparison

production
-> sampling of real traces

periodically
-> another full regression

That way the agent is controlled like other parts of the SDLC: not just before the first deployment, but across its whole lifecycle.

What the team still defines

The team is still responsible for what its role means.

For the Implementer Agent it decides:

  • when a task is ready,
  • what the agent is supposed to achieve,
  • which repo and workflow it handles,
  • which tools it needs,
  • which instructions are product-specific,
  • which eval cases really represent correct work.

Agent roles

The Implementer Agent is only the first example.

You can build others the same way:

text
Reviewer Agent
-> started on a PR

Incident Agent
-> started on an incident

Release Agent
-> started before a release

Each role has its own internal workflow.

We do not create a separate agent for every step.

text
Implementer Agent:
ticket
-> code
-> tests
-> PR

Reviewer Agent:
PR
-> diff
-> context
-> review

Tools: a market map

LayerAzureAWSGCPIndependent
Models / AI platformMicrosoft FoundryAmazon BedrockVertex AIdirect provider APIs
EventsEvent Grid / FunctionsEventBridge / LambdaEventarc / Cloud Runwebhooks
RuntimeFoundry Agent ServiceAgentCore RuntimeVertex AI Agent EngineKubernetes
RAGAzure AI SearchBedrock Knowledge Bases / OpenSearchVertex AI RAG EnginePinecone, Weaviate
Tools / MCPFoundry tools / MCPAgentCore GatewayAgent Gateway / MCPyour own MCP
State / memoryFoundry state / Cosmos DBAgentCore MemorySessions / Memory Bankyour own layer
ObservabilityApp Insights / Foundry TracingCloudWatch / AgentCore ObservabilityCloud Trace / MonitoringOpenTelemetry, Langfuse
SecurityFoundry Guardrails / Prompt ShieldsBedrock Guardrails / AgentCore PolicyVertex safety / DLPcustom controls
EvalsFoundry EvaluationsBedrock / AgentCore EvaluationsVertex Gen AI EvaluationLangSmith, Phoenix

The biggest change since the previous series

In the previous series we asked:

How do you build and run an effective agent?

Here the question is different:

How do you let many teams build different agent roles on a shared platform while the organization still knows what those agents do, what they have access to, how much they cost and whether they work correctly?

That is the next stage: standardizing AI in the SDLC across the organization.

Not more autonomy for one agent.

More standardization, observability and control around the whole way of working with agents.

Materials

top