Should we fund a staged rollout of an enterprise coding agent to 5,000 engineers?
ev-001
MEASURED
ev-002
MEASURED
ev-003
MEASURED
ev-004
MEASURED
ev-005
MEASURED
ev-006
MEASURED
ev-007
MEASURED
ev-008
EXTERNAL_REFERENCE
ev-009
EXTERNAL_REFERENCE
ev-010
EXTERNAL_REFERENCE
ev-011
EXTERNAL_REFERENCE
ev-012
EXTERNAL_REFERENCE
ev-013
EXPERT_JUDGMENT
ev-014
EXPERT_JUDGMENT
ev-015
EXPERT_JUDGMENT
ev-016
FORECAST
ev-017
FORECAST
ev-018
ASSUMPTION
ev-019
ASSUMPTION
ev-020
ASSUMPTION
ev-021
ASSUMPTION
ev-022
INFERENCE
ev-023
INFERENCE
ev-024
UNKNOWN
ev-025
UNKNOWN
ev-026
UNKNOWN
| NPV low | NPV mid | NPV high | Payback | Peak funding |
|---|---|---|---|---|
| -£5,351,240 | £5,085,455 | £38,138,347 | 0.0y | £0 |
| attribution_factor | £16,922,975 |
| uplift | £15,669,421 |
| fully_loaded_cost_gbp | £3,760,661 |
| training_cost_per_engineer_gbp | -£507,769 |
| annual_support_cost_gbp | -£413,223 |
DEFER → DEFER [ev-015, ev-026]
The staged rollout proposal presents a measured approach to expanding an enterprise coding agent to 5,000 engineers based on promising pilot results. However, unresolved security concerns and the potential for significant technical challenges in scaling up to legacy codebases remain critical uncertainties that could undermine the viability of this investment.
held position: whether the agent's performance generalizes to legacy/untyped codebases at scale
REQUEST_EVIDENCE → REQUEST_EVIDENCE [ev-008, ev-012, ev-015]
The unresolved security concerns, particularly the open prompt-injection vulnerability and lack of documented human review processes for AI-suggested changes in regulated systems, pose a significant risk to the organization's security posture. These issues need to be adequately addressed before proceeding with the proposed rollout.
DEFER → DEFER [ev-015, ev-026]
The staged rollout proposal fails to adequately address unresolved security concerns and uncertainties around full-scale adoption rates, which pose unacceptable risks to the organization's security posture.
ciso: REQUEST_EVIDENCE — The open prompt-injection concern (ev-008) has not been resolved, leaving unaddressed a potential security risk in the full rollout.; The pilot did not exercise the agent against any system handling regulated customer data (ev-015), so it's unclear if the security review's findings generalise to a full rollout.; The real-world incident rate for the open prompt-injection concern at full rollout scale is unknown (ev-026), which could impact security posture. [ev-008, ev-015, ev-026]
No human decision recorded yet for this run.