From AI-Assisted to Agentic: Building a Governed SDLC on GitHub
A half-day, in-person working session with Lantern
September 23, 2026
9:30 AM – 1:30 PM MST
Spaces Civic Center
16W-125, 1560 Broadway, 16th & 17th Floors,
Denver, CO 80202
Most engineering organizations have adopted AI faster than their platform can safely support it. Developers are already running multiple agents and merging AI-written pull requests, while the foundation underneath — branch protection, required security checks, cost visibility, agent governance — often hasn’t caught up.
DORA’s 2025 research states it plainly: AI is an amplifier. It magnifies an organization’s existing strengths and weaknesses, and the returns come from the surrounding system, not the tool itself.
This session walks through what a governed agentic SDLC looks like on GitHub, built live from real repositories — and gives you a way to locate exactly where your organization stands today.
What you’ll leave with:
- A self-assessment of your current maturity across two axes — Platform Foundation and Agentic Capability — on a defined L0–L5 scale.
- A map of which specific GitHub and Copilot capabilities move each dimension up a level.
- A 30/60/90 plan scoped to one workflow you can start immediately.
- Enough shared context for engineering leaders and hands-on engineers to agree on the same next steps.
Why engineering leaders should attend:
This session is built for the people accountable for delivery, not only the people writing code. You’ll leave able to:
- Reduce AI-related delivery risk: see the guardrails (required checks, code owners, branch protection, agent security) that stop ungoverned agents from merging problems into production.
- Improve software delivery throughput: with AI, the bottleneck shifts from writing code to reviewing and reworking it. DORA’s 2025 research finds the throughput payoff holds only when the platform around the agents is strong; you’ll see how spec-driven work and required checks cut rework upstream, so lead time falls without the change-failure rate climbing.
- Create consistency across teams: replace personal, one-off AI practices with a shared standard (Spec Kit, AGENTS.md) that every team and agent inherits.
- Establish governance before scaling agents: put model and agent policy, cost limits, and audit in place at the L2→L3 transition, rather than retrofitting them later.
- Measure the ROI of AI investment: cost per pull request (agent-assisted vs. hand-written), cost per developer, and team-level spend from GitHub’s Copilot metrics tracked as DORA deltas against a Day-0 baseline.
Who should attend:
- Engineering leaders — VPs, directors, and senior managers accountable for delivery, risk, and cost.
- Hands-on engineers — staff and senior engineers, and platform/DevEx leads who will implement.
The session runs as a single track. Each segment covers both the technical detail and the business implication.
Reserve your spot today!
Agenda
Start | Length | Topic |
9:30 | 20 min | Opening — why AI amplifies the system. The DORA finding and the L0–L5 maturity model (two axes, five dimensions). |
9:50 | 15 min | Where most teams actually are. Adoption vs. platform foundation, and the gaps that matter most: blocking checks, branch protection, cost visibility, agent governance. |
10:05 | 40 min | Spec-driven development. Turning intent into tracked, reviewable work with Plan Mode, Spec Kit, and repo-level AGENTS.md. (Intent & Planning: L1/L2 → L3.) |
10:45 | 45 min | Orchestrating a team of agents. Specialist agents via .agent.md, reusable skills, and the Copilot SDK — with the cost of each task made visible. (Code & Change and Governance: L2 → L3.) |
11:30 | 10 min | Break. |
11:40 | 45 min | Putting agents on the platform. The coding agent, Copilot CLI in Actions, and agentic workflows — and the checks that gate them: tests, GHAS, CODEOWNERS, branch protection. (Quality & Security: L2 → L3/L4.) |
12:25 | 35 min | Governing, securing, and measuring at scale. The agent control plane, agent security (MCP allow-lists, egress control), and cost/ROI reporting. (Governance and Outcomes: L3 → L4/L5.) |
1:00 | 20 min | Your maturity self-assessment and 30/60/90 plan. |
1:20 | 10 min | Q&A and next steps. |
Demonstrations use real repositories and real checks; timings are approximate. Microsoft and GitHub subject-matter experts attend for live Q&A.
Format
- In-person, single track, roughly four hours including a short break.
- Model-neutral: the focus is the system around the agents, not any one model or vendor.
- Every attending organization is offered an optional follow-up assessment to benchmark its maturity and scope a first workflow. There is no obligation.
FAQ
Is this a product pitch?
No. It’s a working session built around live demonstrations on real repositories. The follow-up assessment is optional.
Do I need to be technical?
No. Each segment covers both the implementation detail and the business implication, so leaders and engineers get value from the same room.
Which models or tools do you use?
We stay model-neutral. What determines your results is the system around the agents — governance, checks, and measurement — not the specific model.
Will this apply to my organization?
The examples span retail and software, and the maturity model and roadmap are general. You’ll leave with your own scores and plan, not a generic one.
What should I bring?
One candidate workflow you’d consider handing to an agent — for example, issue triage, test generation, or a low-risk maintenance task.