Strategic Insights

The executive view: health, risk, and where agents pay off

Engineering reporting tells a team what to fix. Strategic Insights tells a leadership team what is actually happening to the estate, what it should worry about, and where an agentic programme would pay back fastest. Findings are produced overnight, so the answer is waiting rather than being assembled on request.

One number leaders trust

Strategic Health, from 0 to 100

A weighted blend of seven sub-scores: quality, security, coverage, dependencies, standards compliance, end of life, and known-exploited vulnerabilities. Banded A to E, so the conversation starts with a letter rather than a spreadsheet.

  • Seven weighted sub-scores, each shown alongside the headline so the number can be interrogated.
  • Bands A to E with the thresholds published, not hidden.
  • Unmeasurable sub-scores are dropped and the remaining weights rescale, rather than being scored zero.
  • Per-category health across your own business structure, with the comparison table behind it.
Risk Map

Rank the risk, then fix the right things first

Composite risk blends quality gate, coverage, security, dependencies, technical debt and duplication into one banded figure per project, then ranks what to do about it by how much risk each fix actually clears.

  • Risk matrix by your own category axis, so a domain owner sees their own exposure.
  • Highest-leverage fixes ranked by risk points cleared, not by issue count.
  • Shared causes where one change resolves findings across many projects.
  • Single-owner critical systems, the organisational risk that never shows up in a code metric.
Priorities

A short, ordered list of what to do next

Grouped by the reason it matters, so a priority arrives with its justification attached rather than as a bare ranking.

Security and dependencies

Where exposure is real and a safe upgrade exists.

Coverage and quality gates

Where the safety net is thin enough to make change risky.

Debt and duplication

Where accumulated debt is now slowing delivery measurably.

End of life

Where a platform or runtime is running out of support runway.

Priorities export to Excel and CSV in a column order that imports cleanly into Jira, so the list becomes backlog rather than a screenshot.

External Exposure

End-of-life and known-exploited risk, up front

The risks that come from outside your codebase and change without you touching anything. Fed by public catalogues rather than by our own opinion.

  • End of life today and in twelve months, plus what has already passed its long-term support window.
  • Known-exploited vulnerabilities from the CISA KEV catalogue, separated from ordinary CVEs.
  • Blast radius across direct and transitive dependencies.
  • Concentration by category, so you can see whether the exposure is spread or clustered.

Sources: the National Vulnerability Database, the CISA Known Exploited Vulnerabilities catalogue, and endoflife.date.

The agentic transition

Where agents should go next, and whether adoption is real

Two of the seven Insights areas exist specifically to answer the questions leadership is being asked about AI. Both are covered in full on the Agentic Engineering page.

Agentic disposition on two axes

Every system is placed on two axes. Replacement pressure is how much the business is paying to keep it as it is. Replacement feasibility is how safely agents could take it on, given test coverage, interface clarity, specification stability and the risk of cutting over. The four resulting verdicts are Rebuild, Contain, AI-maintain and Maintain.

  • Rebuild Pressure: High Feasibility: High It costs you to keep, and agents can safely take it on. This is where an agentic programme pays back fastest.
  • Contain Pressure: High Feasibility: Low It costs you to keep, but it is not safe to hand over yet. Limit the blast radius and fix the things blocking feasibility.
  • AI-maintain Pressure: Low Feasibility: High It is not hurting, and agents could work on it comfortably. Let agents carry the routine maintenance.
  • Maintain Pressure: Low Feasibility: Low It works, it is cheap to keep, and there is no case for disturbing it. Leave it alone.
Agentic Candidates: a disposition for every system, with the evidence behind it.
Engineering Performance

How the organisation is actually delivering

Built deliberately as a coaching and risk surface rather than a ranking tool, because the alternative destroys trust faster than it produces insight.

  • Leaderboards use descriptive measures only, and are never sorted on rework or issue rate.
  • Boards with too few measured contributors are withheld rather than shown.
  • Organisation-level views are anonymised and name no individual.
  • Key-person risk is banded by team, which is where it is actionable.
Overnight discovery

Nine kinds of finding, waiting when you arrive

Rather than asking you to interrogate a dashboard, Insights runs discovery overnight and presents what changed. A badge shows what is new since the last run.

Unexpected change

An anomaly against the estate's own recent behaviour, not against an arbitrary threshold.

Linked signals

Two measures moving together in a way that suggests a shared cause.

Sustained deterioration

A regression that has persisted long enough to be a trend rather than noise.

Projected risk

Where a current trajectory ends up if nothing changes.

Shared cause

One root cause producing findings across many projects, and therefore one fix.

Licence policy

A component licence that conflicts with the policy you set.

Team pattern

A pattern in how a team works that is worth a conversation.

AI adoption

A meaningful movement in how much agentic work is being attributed.

AI outcome

A difference in how agentic work performs against everything else.

Each project also gets a dossier: its composite risk, the dimensions contributing most to it, and the lowest-effort change with the projected risk after it lands.

For the board

Export the whole view as a board pack

The figures leaders present should be the figures the engineering organisation actually runs on. Exporting the view directly is how you keep those two things the same.

7 areas
one surface
Overnight
findings ready
Bands A to E
published thresholds
Board pack
exported directly
Questions

Strategic Insights, answered

How is the Strategic Health score built?
It is a weighted blend of seven sub-scores: quality at 0.25, security at 0.20, coverage at 0.15, dependencies at 0.15, standards compliance at 0.10, end of life at 0.10 and known-exploited vulnerabilities at 0.05. A sub-score that cannot be measured is dropped and the remaining weights rescale, so the number never quietly punishes you for missing data.
What are the bands?
A is 85 and above, B is 70 to 84, C is 55 to 69, D is 40 to 54, and E is below 40. The thresholds are published in the product because a banded score whose boundaries are secret is not a score anyone can act on.
Who is this for?
Engineering leadership and the people they report to. Enterprise Reporting is the team-level detail; Strategic Insights is the layer above it, aimed at where to direct attention and investment rather than which file to fix.
Does it tell us what our AI tooling costs?
No. Insights covers engineering health, risk and the agentic transition, not spend. Per-review token and cost accounting for the AI reviewer is available separately in organisation settings.

Give leaders the whole picture

Book a demo and see a health score, a risk map and a board pack built from your own estate.

Book a Demo