Process & tooling / L2 detail
SDLC and pipelines
Linked Level 3 activities
Level 3
DevOps / DevSecOps pipeline integration
Integrate evals, policy gates, and security checks into CI/CD with explicit alignment between technology teams and oversight/control teams
Open Level 3 detail
Level 3
DataOps pipeline integration
Treat data changes as production changes impacting agent behaviour, not background hygiene
Open Level 3 detail
Level 3
Control gating and approvals in CI/CD
Implement approvals based on risk tier and evidence, while requiring human review for higher-risk classes regardless of test results
Open Level 3 detail
Level 3
Agent testing harnesses (evals, simulations)
Build repeatable harnesses to simulate workflows, tool failures, adversarial inputs, and boundary violations
Open Level 3 detail
Level 3
Environment management (dev / test / prod)
Add safe sandboxes for tool actions and controlled test data where appropriate, not only staging for chat/UI
Open Level 3 detail