From AI-Assisted to Agentic: Building a Governed SDLC on GitHub

A half-day, in-person working session with Lantern

September 23, 2026
9:30 AM – 1:30 PM MST

Spaces Civic Center
16W-125, 1560 Broadway, 16th & 17th Floors,

Denver, CO 80202

Why this session:
 

Most engineering organizations have adopted AI faster than their platform can safely support it. Developers are already running multiple agents and merging AI-written pull requests, while the foundation underneath — branch protection, required security checks, cost visibility, agent governance — often hasn’t caught up. 

DORA’s 2025 research states it plainly: AI is an amplifier. It magnifies an organization’s existing strengths and weaknesses, and the returns come from the surrounding system, not the tool itself. 

This session walks through what a governed agentic SDLC looks like on GitHub, built live from real repositories — and gives you a way to locate exactly where your organization stands today. 

What you’ll leave with:

  • A self-assessment of your current maturity across two axes — Platform Foundation and Agentic Capability — on a defined L0–L5 scale. 
  • A map of which specific GitHub and Copilot capabilities move each dimension up a level. 
  • A 30/60/90 plan scoped to one workflow you can start immediately. 
  • Enough shared context for engineering leaders and hands-on engineers to agree on the same next steps. 

Why engineering leaders should attend: 

This session is built for the people accountable for delivery, not only the people writing code. You’ll leave able to: 

  • Reduce AI-related delivery risk: see the guardrails (required checks, code owners, branch protection, agent security) that stop ungoverned agents from merging problems into production. 
  • Improve software delivery throughput: with AI, the bottleneck shifts from writing code to reviewing and reworking it. DORA’s 2025 research finds the throughput payoff holds only when the platform around the agents is strong; you’ll see how spec-driven work and required checks cut rework upstream, so lead time falls without the change-failure rate climbing. 
  • Create consistency across teams: replace personal, one-off AI practices with a shared standard (Spec Kit, AGENTS.md) that every team and agent inherits. 
  • Establish governance before scaling agents: put model and agent policy, cost limits, and audit in place at the L2→L3 transition, rather than retrofitting them later. 
  • Measure the ROI of AI investment: cost per pull request (agent-assisted vs. hand-written), cost per developer, and team-level spend from GitHub’s Copilot metrics tracked as DORA deltas against a Day-0 baseline. 

Who should attend:

  • Engineering leaders — VPs, directors, and senior managers accountable for delivery, risk, and cost. 
  • Hands-on engineers — staff and senior engineers, and platform/DevEx leads who will implement. 

The session runs as a single track. Each segment covers both the technical detail and the business implication. 

Reserve your spot today!

Agenda

Start 

Length 

Topic 

9:30 

20 min 

Opening — why AI amplifies the system. The DORA finding and the L0–L5 maturity model (two axes, five dimensions). 

9:50 

15 min 

Where most teams actually are. Adoption vs. platform foundation, and the gaps that matter most: blocking checks, branch protection, cost visibility, agent governance. 

10:05 

40 min 

Spec-driven development. Turning intent into tracked, reviewable work with Plan Mode, Spec Kit, and repo-level AGENTS.md. (Intent & Planning: L1/L2 → L3.) 

10:45 

45 min 

Orchestrating a team of agents. Specialist agents via .agent.md, reusable skills, and the Copilot SDK — with the cost of each task made visible. (Code & Change and Governance: L2 → L3.) 

11:30 

10 min 

Break. 

11:40 

45 min 

Putting agents on the platform. The coding agent, Copilot CLI in Actions, and agentic workflows — and the checks that gate them: tests, GHAS, CODEOWNERS, branch protection. (Quality & Security: L2 → L3/L4.) 

12:25 

35 min 

Governing, securing, and measuring at scale. The agent control plane, agent security (MCP allow-lists, egress control), and cost/ROI reporting. (Governance and Outcomes: L3 → L4/L5.) 

1:00 

20 min 

Your maturity self-assessment and 30/60/90 plan. 

1:20 

10 min 

Q&A and next steps. 

 

Demonstrations use real repositories and real checks; timings are approximate. Microsoft and GitHub subject-matter experts attend for live Q&A. 

Format

  • In-person, single track, roughly four hours including a short break. 
  • Model-neutral: the focus is the system around the agents, not any one model or vendor. 
  • Every attending organization is offered an optional follow-up assessment to benchmark its maturity and scope a first workflow. There is no obligation. 

FAQ

No. It’s a working session built around live demonstrations on real repositories. The follow-up assessment is optional.

No. Each segment covers both the implementation detail and the business implication, so leaders and engineers get value from the same room.

We stay model-neutral. What determines your results is the system around the agents — governance, checks, and measurement — not the specific model.

The examples span retail and software, and the maturity model and roadmap are general. You’ll leave with your own scores and plan, not a generic one.

One candidate workflow you’d consider handing to an agent — for example, issue triage, test generation, or a low-risk maintenance task.