The AI-Native SDLC with Claude Code, Rebuild your software lifecycle around agentic AI – with gates, evals and audit evidence that actually hold.
Description
This course contains the use of artificial intelligence.
Something specific happens about eight weeks after an engineering organisation hands agentic coding to everyone. Merged pull request volume roughly doubles. Everybody celebrates. And then the second number arrives: median time in review climbs, change failure rate creeps up, and a quarter later somebody in an audit asks who approved the change an agent wrote at two in the morning – and nobody can answer.
That is not an AI problem. It is a process problem. We got very good at making AI write code, and we left every stage around the code running at human speed.
This course rebuilds the lifecycle itself. It follows Anthropic’s AI-Native SDLC Playbook – six stages arranged as a loop rather than a line, where each stage ends by committing an artifact and the next stage begins by reading it. You will build the whole chain: an intent file, a spec file, a plan file, the diff and its tests, the pull request with its review findings, and the incident record that writes the next intent.
Every mechanism is built, not described. You will write a PreToolUse hook that blocks an edit and names the route to approval. You will interrogate Claude into a plan before a line of code exists. You will stand up an eval suite that regression-tests your agent’s configuration when a skill changes. You will write a review-policy file with a severity threshold and a nit cap. You will set a production gate that the agent may act up to and cannot pass. And you will wire statistical control bands so a 3-sigma breach diagnoses itself and files an intent file before anyone is paged.
Governance is treated as a first-class concern, not an afterthought. Every play in this course names what is enforced, what the evidence is, where it is logged and who approves. You will learn the single most expensive design error teams make – choosing the wrong strength of control – and the difference between a rule that holds and a sentence in a file that nobody enforces.
We work through one company the whole way. Meridian Pay is a 640-person B2B payments platform: FCA-authorised, DORA in scope for its EU entity, PCI-DSS on the cardholder path, SOC 2 and ISO 27001. It rolled Claude Code out to 90 engineers, doubled its PR volume, watched change failure rate go from 8% to 19%, and failed an internal audit because it could not evidence who approved agent-authored changes inside PCI scope. Its CTO has one quarter to fix it without giving the speed back. Every decision in this course is made against that constraint.
You will finish with artefacts, not notes. Templates for intent, spec, plan and review. A protected-path hook and a production-gate hook. An eval-suite starter. A control-band config. A leading/lagging metric pack with a baseline capture step. A gate-to-control mapping worksheet linking each gate to NIST SSDF, ISO/IEC 42001 and SOC 2. And a 90-day rollout plan you can defend to your leadership on Monday.
Thirty-five lectures, eight sections, five assignments and a final practice exam. Built for engineering leads, platform teams and anyone accountable for the speed and the evidence.
Who this course is for:
- Engineering leads and staff/principal engineers whose review queue became the bottleneck after rolling out agentic coding
- Platform engineering and DevEx teams who own the guardrails other teams work inside
- Heads of engineering and delivery leads accountable for cycle time, change failure rate and the audit story for AI-written code
- Application security, QA and release managers who each own one gate in the loop
- Technical product owners who will write and accept an intent file
- Anyone in a regulated organisation who has been asked to prove who approved an agent-authored change
