AI Agent Framework for Enterprise Software Development and Release Automation

Authors

  • Prashant Singh Tewatia

Keywords:

AI governance, Agentic AI, Continuous Integration and Continuous Delivery (CI/CD), Development, Enterprise AI, Release automation, Security, and Operations (DevSecOps)

Abstract

Large Language Model (LLM)-based Artificial Intelligence (AI) systems are extending software automation from code assistance to agentic workflows that can interpret repository context, invoke tools, modify artifacts, execute tests, and participate in release operations. Enterprise adoption, however, depends not only on technical capability but also on whether workflow actions can be bounded, independently verified, governed, observed, and recovered. This study develops and refines the Enterprise Agentic Development and Release Automation (EADRA) Framework through an exploratory qualitative design combining a structured and traceable literature synthesis with three semi-structured expert interviews. Hybrid deductive-inductive thematic analysis identified five themes: (1) risk-bounded autonomy, (2) context, orchestration, and tool-boundary readiness, (3) independent assurance and accountable decision rights, (4) lifecycle reliability supported by production feedback, and (5) socio-technical adoption shaped by trust, integration, cost, and accountability. The analysis retained nine EADRA dimensions while sharpening context and token governance, agent/runtime identity and provenance, independent security assurance, post-release feedback, adoption economics, and multi-dimensional measurement. EADRA advances evidence-conditioned autonomy. Execution authority should increase only when the workflow is bounded, acceptance evidence is sufficiently independent, failures are observable and recoverable, policy constraints are satisfied, and accountable ownership is established. Because the expert sample is small and the literature records do not constitute a completed systematic-review audit trail, the framework is presented as exploratory, literature-informed, expert-refined, and testable rather than validated or generalizable.

References

H. Xinyi et al., “Large Language Models for Software Engineering: A Systematic Literature Review,” arXiv: 2308.10620, Aug. 2023.

J. He, C. Treude, and D. Lo, “LLM-Based Multi-Agent Systems for Software Engineering: Vision and the Road Ahead,” arXiv.org, Apr. 2024.

C. Qian et al., “Communicative Agents for Software Development,” arXiv.org, July 2023.

S. Hong et al., “MetaGPT: Meta Programming for A Multi-Agent Collaborative Framework,” arXiv.org, 2023.

J. Yang et al., “SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering,” arXiv (Cornell University), May 2024.

Y. Zhang, H. Ruan, Z. Fan, and Abhik Roychoudhury, “AutoCodeRover: Autonomous Program Improvement,” In Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis, Sept. 2024, pp. 1592–1604.

C. S. Xia, Y. Deng, S. Dunn, and L. Zhang, “Demystifying LLM-Based Software Engineering Agents,” Proceedings of the ACM on Software Engineering, vol. 2, no. FSE, pp. 801–824, June 2025.

C. E. Jimenez et al., “SWE-bench: Can Language Models Resolve Real-World GitHub Issues?,” arXiv.org, Oct. 2023.

M. Fu, J. Pasuksmit, and C. Tantithamthavorn, “AI for DevSecOps: A Landscape and Future Opportunities,” ACM Transactions on Software Engineering and Methodology, Jan. 2025.

E. Soares, G. Sizilio, J. Santos, D. Alencar, and U. Kulesza, “The Effects of Continuous Integration on Software Development: a Systematic Literature Review,” arXiv.org, 2021.

X. Zhao, T. Clear, and R. Lal, “Identifying the primary dimensions of DevSecOps: A multi-vocal literature review,” Journal of Systems and Software, p. 112063, Apr. 2024.

H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, “Asleep at the Keyboard? Assessing the Security of GitHub Copilot’s Code Contributions,” IEEE Xplore, May 2022.

N. Perry, M. Srivastava, D. Kumar, and D. Boneh, “Do Users Write More Insecure Code with AI Assistants?,” Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Nov. 2023, pp. 2785–2799.

A. Chhabra, S. Datta, S. K. Nahin, and P. Mohapatra, “Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges,” IEEE Access, vol. 14, pp. 49455–49482, 2026.

K. Z. Cui, M. Demirer, S. Jaffe, L. Musolff, S. Peng, and T. Salz, “The Effects of Generative AI on High-Skilled Work: Evidence from Three Field Experiments with Software Developers,” Management Science, Feb. 2026.

D. Russo, “Navigating the Complexity of Generative AI Adoption in Software Engineering - RCR Report,” ACM Transactions on Software Engineering and Methodology, July 2024.

X. Zhou et al., “Exploring the problems, their causes and solutions of AI pair programming: A study on GitHub and stack overflow,” Journal of Systems and Software, vol. 219, p. 112204, Sept. 2024.

S. Abrahão, J. Grundy, M. Pezzè, M.-A. Storey, and D. A. Tamburri, “Software Engineering by and for Humans in an AI Era,” ACM Transactions on Software Engineering and Methodology, vol. 34, no. 5, pp. 1–46, May 2025.

B. Kitchenham, L. Madeyski, and D. Budgen, “SEGRESS: Software engineering guidelines for REporting Secondary Studies,” IEEE Transactions on Software Engineering, vol. 49, no. 3, pp. 1273–1298, Mar. 2023.

M. J. Page et al., “The PRISMA 2020 statement: An updated guideline for reporting systematic reviews,” British Medical Journal, vol. 372, no. 71, 2021.

V. Braun and V. Clarke, “One Size Fits all? What Counts as Quality Practice in (reflexive) Thematic analysis?,” Qualitative Research in Psychology, vol. 18, no. 3, pp. 328–352, Aug. 2021.

A. Tong, P. Sainsbury, and J. Craig, “Consolidated criteria for reporting qualitative research (COREQ): a 32-item checklist for interviews and focus groups,” International Journal for Quality in Health Care, vol. 19, no. 6, pp. 349–357, 2007.

Published

2026-09-17