The AI-native software development lifecycle
The AI-native software development lifecycle (SDLC) runs plan, design, build, test, deploy, and maintain as one loop in which every stage commits an artifact the next stage reads: intent.md, spec.md, plan.md, the diff with its tests, the reviewed pull request, and the incident record. Agents do the first pass at each stage; named humans own the gates.
This page is for the developer, tech lead, or CTO whose agents now produce a working diff in an afternoon, while the ticket still took a week to write and the pull request still waits two days for review. Build stopped being the slow step; the human-speed steps around it did not. Rebuilding those steps is what this section covers.
The process follows The AI-native SDLC playbook (Anthropic, 21 August 2026). The artifacts are plain files, so Claude Code, Codex, and Cursor all fit the same loop — see the tool map.
What each lifecycle stage commits, and who signs it off
Section titled “What each lifecycle stage commits, and who signs it off”Each row is one stage. The artifact is what the stage commits; the evidence column is how the gate is checked without a human reading every generated line.
| Stage | Artifact committed | Evidence the gate checks | Human who owns the gate |
|---|---|---|---|
| Plan | intent.md in the originator’s words | Problem, outcome, and constraints are stated; open questions listed | Product owner accepts intent |
| Design | spec.md with acceptance criteria | Each criterion is testable; policy skills applied and named | Tech lead approves the spec |
| Build | plan.md, then the diff and its tests | Diff matches the plan’s file list; new tests fail before the change | Engineer accepts the plan |
| Test | Test and lint output attached to the change | The session ran the project’s check command and pasted the result | Automated; engineer reads failures only |
| Deploy | Pull request with review-agent findings | Findings resolved, CI green, and risk class set | Named reviewer merges; release owner promotes |
| Maintain | Incident record and the next intent.md | A deterministic alert fired; evidence gathered read-only | On-call engineer accepts the new intent |
The chain of commits is also the audit trail: who asked for what, what the agent produced, and who approved it. Human review of the code itself stays for regulated and critical changes; reading evidence instead of code defines which ones.
Start the loop on your next change
Section titled “Start the loop on your next change”The playbook breaks each stage into plays — one practice each — and the plays are modular. Five have no prerequisites: intent.md, the instructions file (CLAUDE.md or AGENTS.md, or Cursor rules), skills, the session feedback loop, and hooks as approval gates. Start there on one real change.
-
Pick one change that is already in your backlog and small enough to merge this week.
-
Turn the ticket into
intent.mdwith the first prompt below, then have the person who asked for the change accept it. -
Enter plan mode, ask for a plan that names the files, the order of work, and the tests that prove it, and commit the accepted plan as
plan.md.Start with
claude --permission-mode plan, or type/planin a running session.Type
/planin the Codex terminal UI to switch to Plan mode before the run starts.Switch the agent to Plan Mode before you describe the change.
-
Tell the agent the one command that proves the change — for example
npm run typecheck && npm run lint && npm test— and require its output before it reports done. -
Open the pull request with the artifacts linked, run a review agent, and merge only after a named human accepts the evidence.
Run
/code-reviewin the session. For a deeper pass, runclaude ultrareviewfrom the shell.Type
/reviewin the Codex terminal UI, or runcodex exec reviewin CI.Let Bugbot review the pull request.
Delegate, review, own at every stage
Section titled “Delegate, review, own at every stage”Across all six stages, split the work three ways:
- Delegate the mechanical first pass: a draft spec, boilerplate, a first review, and log triage.
- Review for completeness, security, and domain fit.
- Own priorities, architecture, UX, merge, and production sign-off.
Agent output that looks confident is still a draft until a named human accepts it at the gate. Human in the loop covers where that attention belongs.
What breaks when a team adopts the AI-native lifecycle?
Section titled “What breaks when a team adopts the AI-native lifecycle?”- Artifacts are written and never read.
plan.mddrifts from the diff within a week. Recovery: updateplan.mdin the same commit as the code, and have the review agent check the diff against the plan. - Automation lands before the gates. Agents in CI push changes through a pipeline with no hooks and no review agent. Recovery: adopt hooks and pull request review first; the playbook lists them as prerequisites for pipeline automation.
- Two sources of truth. Jira says one thing,
spec.mdanother. Recovery: name one system as the source of truth per artifact, or at minimum link the record ID and the commit SHA both ways (the artifact chain shows the three options). - Gates become rubber stamps. Approvals arrive in seconds. Recovery: make each gate check the evidence column above, and track it with SDLC metrics.
Lifecycle guides: artifacts, tools, metrics, and rollout
Section titled “Lifecycle guides: artifacts, tools, metrics, and rollout”Where to go next with the lifecycle
Section titled “Where to go next with the lifecycle”Place the lifecycle against the autonomy ladder first in one map, then walk a feature through the artifact chain. For per-tool setup, use the Claude Code, Codex, and Cursor sections.