Skip to slide
Chapter 16 · Production Realities: Economics, Security, and Governance
126 / 142

CHAPTER 16 · Production Realities: Economics, Security, and Governance · 5 / 10

Governance and the staged rollout

At enterprise scale, the controls are the product. The guide's principles: scope repository permissions so an agent only touches what it should, isolate secrets from the sandbox, log every action for audit, and apply least privilege to agents exactly as to humans. The highest-leverage pattern is headless execution in CI/CD: run the agent on every PR to pre-screen reviews, generate tests, and handle routine fixes, then route to a human gate before merge. CI is also where caching pays off most, because the same repo context is sent on every automated invocation.

The recommended adoption arc is staged: pilot on one or two teams with low-risk, verifiable tasks and mandatory review; expand to early adopters with a good AGENTS.md per repo and Codex in CI; standardize with shared skills, policy-managed plugins, and explicit budgets; operate at org scale where agents are the default first pass on well-defined tasks. Attach metrics from day one (PR review cycle time, share of merged PRs that started with an agent, test coverage, and crucially cost per task), and judge the steady state, not the honeymoon; the data shows adoption peaks then settles, with gains concentrated among engaged users.

← → arrow keys work too