The Agent Stack Gets Its Quality Gates
Cloudflare’s Security Audit Skill orchestrates isolated coding agents to discover, validate, verify, and report vulnerabilities with coverage-led evidence. It is Principle 14 in practice: agentic security work needs an immune system that records what was checked, by whom, and with what proof.
Spotify details how AI changed its software-building process, including the quality and reliability controls it tightened as development accelerated. Outcome engineers should treat velocity as an input, not an outcome—Principle 16 requires validating that shipped work preserves intended behavior.
Anthropic redesigns Claude Projects for parallel work, turning one work description into coordinated threads that can run through Claude Code. This makes Principle 09 operational: orchestration becomes a system for decomposing work, managing context, and consolidating agent outputs rather than simply spawning more agents.
Anthropic adds centralized skill management for organizations, with approved skills, group targeting, permissions, and review workflows. The control plane matters because reusable agent capabilities need ownership and boundaries—Principles 10 and 15, not just prompt distribution.
AI agents erase the paper trail, reshaping audit assurance as automated judgments replace informal human records. If an agent’s decision cannot be reconstructed from inputs, actions, and evidence, it cannot support a durable outcome; Principle 13 makes documentation part of the system, not an afterthought.