Peter Pedross, CEO & Founder, PEDCO – SAFe Fellow

Agentic Engineering fundamentally changes how engineering organizations establish trust. As autonomous systems increasingly participate in software development, periodic audits alone are no longer sufficient to demonstrate that engineering decisions remain aligned with architectural principles, quality objectives and organizational intent. This article introduces the concept of Continuous Adherence—the continuous evaluation of whether everyday engineering activities remain consistent with an organization’s defined engineering system. Rather than collecting evidence at the end of a endeavor, Continuous Adherence connects engineering intent, architecture, governance and operational evidence throughout the development lifecycle. This approach is particularly relevant for organizations working within frameworks such as Automotive SPICE, ISO 26262 and ASQMS, where explainability and objective evidence are essential. Platforms such as PEDCO AuditPro help make engineering behavior observable, enabling organizations to continuously demonstrate not only that they are compliant, but that they are consistently engineering systems as they were intended to be.

From Periodic Audits to Continuous Insight

One of the most interesting observations we have made while working with autonomous engineering systems has surprisingly little to do with artificial intelligence itself. Instead, it concerns a question that engineering organizations have been asking for decades: How do we know that we are building software the way we intended to?

For decades, the traditional answer to this question was the audit. Engineering teams prepared evidence, documentation was reviewed, interviews were conducted and, at a defined moment in time, auditors determined whether a project complied with internal processes, external regulations or industry standards. For many years, this model was practical and, in many contexts, sufficient. Software changed less frequently, important decisions could usually be traced back to identifiable individuals and engineering activities were comparatively easy to reconstruct. Compliance was therefore often verified through a point-in-time assessment.

Agentic Engineering changes these operating assumptions. Modern engineering organizations evolve continuously. New capabilities appear every day, deployments happen automatically and autonomous agents increasingly participate in activities that were previously performed exclusively by engineers. For example, with our own agentic development within PEDCO AuditPro, we work a lot with Lean UX, runnable mockups,  and prototypes. The following executable mockup was designed, tested, and altered several times within half a day, directly together with product managers and designers.

Decisions are no longer concentrated in the hands of a few experienced architects or technical leads. They emerge throughout the engineering system—from developers, pipelines, AI assistants and increasingly autonomous agents. More decisions are being made, at greater speed and across a growing number of human and autonomous participants.  This raises a different question. Rather than asking whether an organization is compliant today, engineering leaders increasingly need to understand whether everyday engineering decisions remain aligned with architectural principles, quality objectives and organizational intent. The distinction may appear subtle, yet it fundamentally changes the role of governance. Conventional compliance assessments often examine whether required processes, controls and evidence are present at a defined point in time. Adherence asks something much more operational:

Are we actually engineering systems the way we agreed we would?

Adherence does not replace compliance. It closes the gap between the engineering system an organization has defined and the work that is actually being performed. Continuous Compliance and Continuous Adherence are therefore closely connected, but they are not identical. Continuous Compliance asks whether internal and external obligations continue to be satisfied. Continuous Adherence asks whether everyday engineering behavior remains aligned with the architecture, processes, quality objectives and governance model designed to satisfy those obligations.

The Evidence Already Exists

This question cannot be answered through process documentation alone. It requires evidence from actual engineering work.

Fortunately, modern engineering organizations already generate an extraordinary amount of such evidence every day. Source repositories capture every implementation. DevOps pipelines document builds, tests and deployments. Architecture Decision Records preserve the rationale behind important design choices. Requirements evolve continuously, automated tests verify expected behavior and operational telemetry provides insight into software running in production. Individually, these artifacts tell only part of the story. Collectively, however, they describe how an engineering organization actually behaves.

They allow us to ask:

  • What was intended?
  • What decision was made?
  • Why was it made?
  • Which controls and architectural principles applied?
  • What evidence supports the decision?
  • What happened when the change reached production?

This observation fundamentally changes the purpose of auditing. The challenge is no longer merely to collect evidence—although evidence quality and accessibility remain important challenges. The greater challenge is to connect and interpret that evidence in the context of the organization’s engineering intent. Evidence should therefore no longer be viewed only as something prepared for auditors at the end of a project. It becomes a continuous feedback mechanism that allows organizations to evaluate whether architecture, governance and engineering intent remain visible in everyday work.

Why This Matters in Regulated Engineering

This challenge is particularly relevant for organizations operating in regulated industries. Automotive organizations need to demonstrate alignment with frameworks and standards such as Automotive SPICE, ASQMS and ISO 26262. Aerospace and defense organizations operate within their own safety, quality and assurance frameworks. Medical device manufacturers with ISO 13485, rail operators and financial institutions face similar expectations. As shown in the example below, we can check adherence to a process of an individual endeavor. The contents of an endeavor’s repository are examinded, classified and checked for adherence with the defined process. As example, here a screen shot of a medical device assessment for ISO 13485 with PEDCO AuditPro.

The terminology and regulatory context may differ, but the underlying question is remarkably consistent:

Can we explain not only what decision was made, but also why it was made and whether it remained aligned with the organization’s engineering principles and obligations?

A final document may show that a required activity was completed. It does not necessarily demonstrate how a decision emerged, whether the relevant architectural constraints were considered or whether an autonomous agent remained within its permitted boundaries. That requires a connected view of intent, decisions, execution and evidence.

What Continuous Adherence Means

We use the term Continuous Adherence to describe an organization’s ability to continuously evaluate whether actual engineering activities remain aligned with its declared engineering system—including its Solution Intent, architecture, quality objectives, working agreements, processes, controls and regulatory obligations. Continuous Adherence does not imply that every engineering decision can be reduced to an automated compliance check. Nor does it eliminate the need for professional judgement, independent audits or human review. Its purpose is to make deviations visible early enough for the organization to understand and address them while the relevant engineering context still exists.

It asks questions such as:

  • Are architectural principles reflected in implementation?
  • Are quality objectives visible throughout delivery?
  • Do engineering decisions remain consistent with the documented Solution Intent?
  • Are required review and approval boundaries respected?
  • Do autonomous agents operate within the same guardrails that guide human engineers?
  • Can the organization explain why a particular implementation was considered acceptable?

These questions cannot realistically be answered only once every six or twelve months. Increasingly, they need to be answered as part of the engineering lifecycle itself. Consider a seemingly simple example. An autonomous agent modifies an interface between two services. The code compiles, all automated tests pass and the change can be deployed successfully. From a delivery perspective, the change appears complete. From an adherence perspective, however, additional questions arise. Was the interface constrained by an Architecture Decision Record? Did the change affect a security or safety requirement? Was human review required? Were the relevant quality objectives considered? Does the implementation still reflect the documented Solution Intent? Neither the code change nor a conventional compliance checklist can answer these questions on its own. The answer emerges only when intent, execution, and evidence are connected. Have we met the defined Definition of Done for this context? The picture below illustrates an automated check for a given DoD.

Making Engineering Behavior Observable

This perspective also changes the role of platforms such as PEDCO AuditPro. Their purpose is not simply to automate audit activities. Their broader purpose is to make engineering behavior observable and explainable. By connecting engineering artifacts, operational evidence, process knowledge, regulatory expectations and architectural intent, organizations gain the ability to understand how decisions emerge across both human and autonomous contributors. A standards mapping can explain which obligations apply. A process model can describe how work should be performed. A source repository can show what was implemented. A pipeline can demonstrate which tests were executed. Only the relationship between these elements reveals whether actual engineering behavior remains aligned with organizational intent.

Trust While Work Is Happening

Perhaps the most significant consequence is that trust itself begins to change. Historically, organizations established trust primarily by periodically reviewing completed work. In the age of Agentic Engineering, retrospective assurance alone is no longer sufficient. Trust increasingly emerges from the ability to understand work while it is happening—to trace decisions, observe the application of controls and identify deviations before they become systemic.

The Trust Loop is important because evidence is not the end of the process. Evidence makes adherence observable. Adherence creates feedback. Feedback improves architecture, processes, guardrails and organizational intent. The engineering system itself becomes more capable—not necessarily because the underlying AI models have changed, but because the environment in which humans and autonomous agents operate has become clearer, more consistent and more explainable.

  • Audits become confirmation rather than discovery.
  • Evidence becomes continuous rather than exceptional.
  • Governance becomes visible rather than implicit.

Ultimately, this may become one of the defining characteristics of autonomous engineering systems. The objective is not merely to generate software faster. The objective is to create engineering organizations whose decisions remain transparent, explainable and continuously aligned with the principles upon which the organization itself was built.

 

Previous Chapter Next