prism-d1-velocity

PRISM D1: Velocity — AI Development Lifecycle Workshop

:warning: Sample Project — Not Production-Ready

This project is provided as a sample and reference implementation only. It is not designed, tested, or hardened for production use. Use it as a starting point or learning resource, and perform your own security review, testing, and operational hardening before deploying to any production environment.

Compress the idea-to-production loop with disciplined AI adoption.

Part of the PRISM Framework (Progressive Readiness Index for Scalable Maturity) — the D1 Velocity pillar focuses on AI-native software development lifecycle practices that are measurable from Day 1.

Architecture

PRISM D1 Velocity Architecture

What This Repo Contains

For Engineering Leaders (Top-Down Visibility)

For Engineering Teams (Bottom-Up Activation)

For Security Leaders (Governance & Compliance)

Quick Start

Prerequisites

./scripts/setup.sh

Or install manually: AWS Account with Bedrock access, Node.js 20+, Python 3.11+, AWS CLI v2, CDK v2, Claude Code CLI, Git 2.40+, jq, GitHub CLI.

Deploy the Metrics Platform

cd infra
npm install
npx cdk bootstrap   # First time only
npx cdk deploy --all

This deploys: EventBridge bus, 8 Lambda processors, DynamoDB tables (KMS-encrypted), 5 CloudWatch dashboards, 12 alarms, Bedrock Guardrails, model pricing table, identity mapping table.

For cost tracking: Enable CloudTrail data events for Bedrock after deploying. See Bootstrapper Step 6. Without this, the Cost Intelligence dashboard sections will be empty.

For Security Agent: Add --context enableSecurityAgent=true if Security Agent is enabled in your account. See the Security Agent Setup Guide.

Assess a Customer

Run the PRISM Assessment to determine maturity level and onboarding track. See the full methodology guide for scanner logic, interview rubrics, and scoring formulas.

Run the Workshop

Start with Module 00: Prerequisites and work through sequentially.

Run the Sample Agent (No AWS Required)

cd sample-app
npm install && npm run dev          # Start the task API

cd agent
pip install -e ".[dev]"
python scripts/run-demo.py --mock   # Run agent demo with mock model

Adopt the Bootstrapper (Post-Workshop)

cp -r bootstrapper/ ~/your-repo/.prism/
cd ~/your-repo

# Install hooks and workflows
.prism/metric-hooks/install.sh
cp .prism/github-workflows/*.yml .github/workflows/
cp .prism/claude-code/CLAUDE.md ./CLAUDE.md

# For agent projects:
cp .prism/agent-configs/ ./agent-configs/
cp .prism/claude-code/CLAUDE-agent.md ./CLAUDE-agent.md

# For Security Agent:
.prism/security-agent/setup.sh --api-url <url> --api-key <key> --team-id <team>

# Configure your team ID
echo 'PRISM_TEAM_ID=your-team-name' >> .env

Enhanced AI-DORA Metrics

Metric Source L2 Target L4 Target
Deployment Frequency GitHub/CodePipeline Weekly Daily+
Lead Time for Changes PR created → deployed < 1 week < 1 day
Change Failure Rate Rollback/hotfix ratio < 15% < 5%
MTTR Incident → resolution < 24h < 1h
AI Acceptance Rate Git hooks + Claude Code >= 30% >= 55%
AI-to-Merge Ratio CI metadata >= 20% >= 45%
Spec-to-Code Turnaround Spec commit → PR ready Baseline set < 2 days
Post-Merge Defect Rate Defect correlator + AI origin tag <= 1.2x human <= 0.9x
Eval Gate Pass Rate Bedrock Evaluations in CI >= 80% >= 95%
AI Test Coverage Delta Coverage tool + AI origin tag > 15% > 40%

Workshop Modules

# Module Duration Key Outcome
00 Prerequisites 30 min Environment ready, Bedrock access confirmed
01 AI-SDLC Foundations 45 min Claude Code configured, first AI-assisted commit
02 Agent Development 70 min Strands agent + MCP server (with auth) + multi-agent orchestration
03 AI-Assisted Development 45 min Spec-driven development with Kiro, Claude Code IDE, or Claude Code CLI
04 Instrumenting AI Metrics 45 min Git hooks + CI emitting 18 event types to EventBridge
05 Eval Gates in CI/CD 45 min 5 Bedrock eval rubrics + SECURITY-09 blocking bad merges
06 Dashboards & Visibility 30 min 5 dashboards live (Team, Executive, CISO, 2 QuickSight)

Extension exercises: Security Agent design review (+10 min in Module 03), code review (+10 min in Module 05), CISO dashboard walkthrough (+5 min in Module 06).

PRISM Maturity Levels (D1 Velocity)

Level Name What It Looks Like
L1 Experimental Ad hoc AI use, no metrics, no shared tooling
L2 Structured Claude Code + Kiro adopted, acceptance rate tracked in CI
L3 Integrated Eval gates in pipeline, AI-DORA dashboards live, spec-driven workflow
L4 Orchestrated Multi-team platform, AI FinOps, governed agent scope, Security Agent
L5 Autonomous Agents contributing to architecture, >20% autonomous deployments

AI Agent Development

Component Technology Location
Agent Framework Strands Agents SDK (Python) sample-app/agent/
Tool Integration Model Context Protocol (MCP) with scope-based auth sample-app/src/mcp/
Production Hosting Amazon Bedrock AgentCore bootstrapper/agent-configs/
Agent Eval Bedrock Evaluations (5 rubrics) bootstrapper/eval-harness/rubrics/
Security Bedrock Guardrails + MCP authorization + Security Agent infra/lib/constructs/
Workshop Module 02: Agent Development workshop/02-agent-development/

Documentation & Resources

Resource Description
Data Architecture & Dashboard Guide 9 data sources, 18 event types, 5 dashboards (widget-by-widget guide), 30+ CloudWatch metrics, 12 alarms
Competitive Landscape PRISM vs. Swarmia, Jellyfish, LinearB, DX, Faros AI — 9 differentiators
Community Roadmap Prioritized backlog across 9 phases
Security Agent Setup Guide 10-step guide: console setup, domain verification, GitHub connection, webhook, identity mapping
AI-DLC Steering Files Development workflow rules adapted from awslabs/aidlc-workflows
ROI Model Defensible ROI calculations for CFO conversations

GitHub Pages: sunilpp.github.io/prism-d1-velocity

License

Internal use — AWS Solutions Architecture, Startups Organization.