Nova — The Autonomous Cloud Delivery Platform

Shifting from Operational Overhead to Strategic Value

Product Development & Citizen Developer Overview

Nova — The Autonomous Cloud Delivery Platform

Slide 1 — The Problem

Product teams now own their cloud infrastructure — but ownership without discipline is destroying value.

  • No lifecycle planning. Resources are authored for creation, not for patching or rollback — so changes are destructive.
  • No proactive scanning in authoring. AI-frontier models exploit zero-days faster than teams can react; modules must be scanned as code and at runtime, remediated at threat pace.
  • Bandwidth gaps. Remediation plus the push for innovation leaves operations under-resourced; detections are missed, incidents grow.
  • Tribal knowledge. Operations depend on a few administrators; when they leave, the knowledge leaves with them. The platform should encode the discipline, not the person.
an autonomous cloud delivery platform that encodes discipline as policy, scans proactively, remediates rapidly, and makes operations visible to leadership.
Nova — The Autonomous Cloud Delivery Platform

Slide 2 — Nova's Vision

Infrastructure operations become visible. Every environment provisioned, every incident healed, every risk remediated — by an autonomous system whose trustworthiness is provable, not promised. Human attestation remains required at stage gates; the operator is never in the loop of normal operations.

  • Visibility is the recurring theme — security posture, remediation velocity, reliability, and lead time as queryable signals
  • Provable, not promised — trust established by deterministic scripts that calculate a score; the platform functions without AI
  • Autonomy in operations, human at stage gates — QA signs off for production; SRE greenlights operational readiness
the destination is autonomous operations with provable trust — security, remediation velocity, reliability, and lead time made visible to leadership, not promised to them.
Nova — The Autonomous Cloud Delivery Platform

Slide 3 — Strategic Objectives

4 Strategic Objectives:

  1. Zero-touch operations — autonomy as the default, not the demo; stage-gate attestation (QA, SRE) remains human by design
  2. Provable trust in automated decisions — deterministic scripts calculate a score; the platform functions without AI; Decision Ledger, confidence scoring, circuit breakers, blast-radius controls
  3. Compounding, quantifiable ROI — four CTO-grade metrics, all flowing into PowerBI:
    • Lead Time (PR → Production) · Infrastructure Vulnerability Count (trend) · MTTR · Cloud Spend Reduction
  4. Integrate with externally owned development platforms — regardless of source — PDLC, SDLC, Agentic, or Citizen Developer; Nova provides skills + MCP endpoints; all prod intents go through the same controls and quality gates
the scope is explicit — Nova governs infrastructure and delivery, integrates with any upstream source through one validated contract, and measures success on four metrics a CTO can repeat back.
Nova — The Autonomous Cloud Delivery Platform

Slide 4 — Anti-Goals (What Nova Is NOT)

  1. Not a general-purpose AI agent platform
  2. Not a system that removes humans from accountability — only from normal operations
  3. Not an upstream development platform (no product backlogs, IDE, code authorship)
  4. Not a replacement for the Product Development Lifecycle (PDLC)
the boundaries are explicit — Nova is purpose-built for infrastructure operations and delivery, not a general-purpose AI agent or an upstream development platform.
Nova — The Autonomous Cloud Delivery Platform

Slide 5 — Scope: Downstream of PDLC

Nova governs infrastructure and delivery. The PDLC is upstream — Nova stays downstream of it. Integration is through one validated contract.

  • The PDLC is upstream — product backlog, code authorship (AI agent, IDE, agentic SDLC), sprint planning, application business logic. Nova stays downstream of it.
  • Nova is downstream: contract ingestion → submission-readiness gate → policy enforcement → cloud resource lifecycle → environment progression (dev → qa → prod → dr) → immutable audit + attestation
  • One validated contract — any upstream source (AI agent, agentic SDLC, dev platform) produces submissions subject to the same compliance standards; Nova validates the submission, not the author
a clean scope boundary — Nova is purpose-built for infrastructure operations and integrates with any upstream source through one contract, so the platform team's surface area stays bounded.
Nova — The Autonomous Cloud Delivery Platform

Slide 6 — RACI: Who Owns What

Four roles, one matrix — citizen developer owns FRs + UAT, platform owns NFRs + infra, quality engineering owns the gate evidence, SRE owns operational readiness.

Work Category Citizen Dev Platform Quality Eng SRE
Functional Requirements R/A C I I
User Acceptance Testing R/A C I I
Non-Functional Requirements I R/A C C
Infrastructure (cloud, state, IAM) I R/A I C
QA (policy, confidence, schema) C R R/A I
Production deployment to cloud I R/A C C
Quality attestation (QA sign-off) A R R I
Production readiness (SRE sign-off) A R C R

R=Responsible · A=Accountable (sign-off) · C=Consulted · I=Informed. Production readiness is co-owned: the platform runs attestations agentically; the citizen developer authorizes the promotion at the stage gate.

every party knows what they bring, what the platform provides, what quality engineering guards, and where SRE signs off — accountability is explicit, never diffuse.
Nova — The Autonomous Cloud Delivery Platform

Slide 7 — The Platform Pipeline

How intent becomes verified infrastructure — fail-fast policy scanning before the plan, runtime scanning after it.

class:tall

  • The pipeline — see the diagram; two scan stages (static code, then resolved plan) feed a confidence signal to the stage gate before apply + evidence + ledger
  • Fail-fast, quick feedback — Checkov runs on the authored Terraform code before terraform plan so developers get immediate policy feedback
  • Wiz on the plan when configured; Checkov as a drop-in otherwise — Wiz scans the plan output; when Wiz credentials are absent, Checkov runs against the plan instead. Wiz and Checkov are never both run on the plan.
two layers of scanning, zero operator involvement in normal operations — fast deterministic feedback at authoring time and a runtime scan on the resolved plan.
Nova — The Autonomous Cloud Delivery Platform

Slide 8 — The Decision Ledger

Every automated decision is captured, immutable, queryable — and accountable.

  • What is captured: the chosen action, the confidence score, the alternatives considered, whether a human overrode it, and the outcome (backfilled once the apply completes). Every stage-gate attestation (QA, SRE) is captured with approver identity and the evidence presented.
  • "AI decisions" are really automated decisions — deterministic scripts calculate a score and a band; the platform functions without AI, and a later LLM planner emits richer alternatives without breaking the schema.
  • The value is accountability, not the storage engine — the ledger is append-only and tamper-evident; every decision is queryable for auditing, traceable to an outcome, and impossible to rewrite after the fact.
"autonomous" is defensible because every decision is immutable, queryable, and accountable — and the audience knows exactly what "automated" means here: deterministic scoring, not a black-box LLM.
Nova — The Autonomous Cloud Delivery Platform

Slide 9 — Attestation Matrix: QA

The designed controls that keep humans at stage gates — QA concerns, freshness-validated.

Concern Env Freshness Description
Functional correctness qa 24h The application behaves as specified; evidence accepted from the consumer's UAT.
Performance baseline qa 7d The deployment meets its performance envelope vs. the agreed baseline.
Security posture qa 24h The deployment's security findings have been reviewed and accepted.
QA signs off on quality before any promotion — the gate is explicit, not implicit.
Nova — The Autonomous Cloud Delivery Platform

Slide 10 — Attestation Matrix: Prod/DR

Production and DR controls — operational readiness, resilience, and disaster recovery.

Concern Env Freshness Description
Operational readiness prod 30d SRE confirms the deployment is operable: runbooks, dashboards, on-call.
Incident response prod 90d The on-call path has been exercised; a working incident-response plan exists.
Capacity & cost prod 30d Capacity headroom and monthly cost are within the agreed envelope.
Resilience: DR drill prod 180d A DR drill has been run and recovery met the RTO.
Resilience: chaos prod 90d A chaos exercise has been run and the deployment absorbed the failure.
Resilience: backup prod 30d Backups are restorable and tested within the freshness window.
DR region deploy dr 180d The DR region can be deployed and is reachable.

Separation-of-duties on prod: the approver cannot be the same person who built the deployment.

the gate model is explicit — autonomy in operations, human in accountability, by design. The matrix is what makes autonomous operations safe enough to trust in production.
Nova — The Autonomous Cloud Delivery Platform

Slide 11 — Telemetry & Live Ops

Every metric in this deck is traceable to a real emitted signal — the live-ops dashboard makes operations visible in PowerBI.

class:tall

  • Platform components → CloudEvents envelope → event log + decision ledger + run records → collector → cold store → PowerBI views → live ops dashboard
  • The live ops dashboard (PowerBI) surfaces the four CTO-grade metrics (Lead Time, Vulnerability Count, MTTR, Cloud Spend) alongside trust metrics (Decision Ledger coverage, Attestation coverage) and efficiency metrics (touchless resolution, escalation frequency)
  • Every number is traceable to a signal — when a CFO asks "where does this number come from?", the answer is a query against the cold store, not a Slack thread
the architecture is the trust substrate — leadership sees the same numbers the platform produces, in PowerBI, with full traceability. Operations become visible.
Nova — The Autonomous Cloud Delivery Platform

Slide 12 — Decision Ledger + Attestation Coverage

By design, no change reaches production without a ledger entry and a human attestation — both queryable for auditing, with full traceability.

  • Decision Ledger coverage: 100% — every platform run emits a decision record with outcome backfill; no automated decision is ever lost
  • Attestation coverage: 100% — every prod/dr promotion is attested by a human (QA for quality, SRE for production readiness), recorded with approver identity, separation-of-duties check, and the evidence matrix
  • No change to production without both — the ledger entry and the human attestation are mandatory, enforced by the pipeline, not by policy
  • Full traceability — a production change is traceable from the contract that declared intent, through the policy scan, the confidence score, the attestation, to the applied outcome
trust is provable — not a marketing claim, a queryable record. An auditor answers "who approved this, when, on what evidence?" in one query; a CTO answers "how many of last quarter's prod changes were touchless?" in one query.
Nova — The Autonomous Cloud Delivery Platform

Slide 13 — Cost & ROI

The ROI formula and the cost estimates — grounded, with the production denominator honestly flagged.

  • Cost estimates are pre-apply and offline — the platform reads the terraform plan and estimates cost before anything is applied; a cost regression is caught before the spend happens
  • The ROI formula:
    Platform ROI = (FTE hours saved × blended rate + cloud savings + avoided downtime) ÷ platform op cost
  • The four CTO-grade metrics are the ROI proof: Lead Time (PR → Prod), Infrastructure Vulnerability Count (trend), MTTR, Cloud Spend Reduction — all flow into PowerBI
  • Honest caveat: derived metrics run on internal data today; the production-denominator activates with a pilot estate.
the ROI is not a black box — the formula is shown, the four metrics are committed, and the production-denominator caveat is stated up front. The CFO sees exactly what is real today and what activates with a pilot.
Nova — The Autonomous Cloud Delivery Platform

Slide 14 — What's Deferred — and Why

Honesty about what is not measured yet — and the blocking work for each.

These deferrals are measurement infrastructure, not the autonomy itself — the platform runs without an operator in normal operations.

# Deferred metric Blocking work
1 Live infra health, outbox write rate, SLA Live AWS re-provisioning (currently torn down to zero-cost steady state)
2 Tamper-evident ledger checkpoints Audit-ledger build-out (Object Lock + signed checkpoints)
3 Onboarding funnel (requested → granted) Auto-grant implementation
4 Drift auto-reversal Drift-detection scheduler (not yet built)
5 Live cost reconciliation Live AWS re-provisioning + actual-spend feed
6 Predictive vs reactive ratio ML anomaly-forecasting service (not yet built)
the boundaries are explicit — what Nova measures today, and exactly what blocks the rest. The autonomy is real; the measurement gaps are documented with the work that unblocks each one.
Nova — The Autonomous Cloud Delivery Platform

Slide 15 — Roadmap to the North Star

The path from the grounded metrics to the 12–18 month targets — each deferred metric has an unblock path and a timeframe.

Timeframe Work Unblocks
Near-term Live AWS re-provisioning Live infra health, outbox write rate, live cost reconciliation, SLA
Near-term Auto-grant implementation Onboarding funnel (requested → granted)
Mid-term Drift-detection scheduler Drift auto-reversal
Mid-term Audit-ledger build-out (Object Lock + signed checkpoints) Tamper-evident ledger checkpoints
Mid-term Hot-path activation (batch → near-real-time) Live-ops dashboard freshness
Longer-term ML anomaly-forecasting service Predictive vs reactive ratio

Re-evaluation triggers: each blocking piece of work lifts on its own schedule; the metrics layer evolves as each one lands.

every deferred metric has an unblock path — nothing is hand-waved; everything has a plan and a timeframe.
Nova — The Autonomous Cloud Delivery Platform

Slide 16 — 12-Month Product Roadmap

The product arc from pilot activation to integration — four quarters, four outcomes.

Quarter Theme Board-level outcome
Q1 Pilot Activation Nova runs a real customer estate end-to-end, autonomously, with a measurable zero-touch rate.
Q2 Provable Trust Every automated decision lands in a tamper-evident ledger; the CFO sees real cloud-spend reconciliation.
Q3 Compounding ROI Quarter-over-quarter cloud spend drops; drift is detected and reversed without a human.
Q4 Integration & Predictive AI agents deploy through Nova by default; the ML anomaly-forecasting service goes live.

Grounded in the four strategic objectives (autonomy, provable trust, ROI, integration) and the deferred-metric unblock paths.

the 12-month product arc — each quarter activates a strategic objective and its corresponding board-level metric, from pilot activation through integration leadership.
Nova — The Autonomous Cloud Delivery Platform

Slide 17 — Quarter-by-Quarter Outcomes

Quarter Product theme Key deliverable Target metric
Q1 Pilot Activation Re-provision live AWS; activate first pilot estate; onboarding auto-grant Touchless ≥ 99% · Escalation < 0.1% · Accuracy ≥ 99.5%
Q2 Provable Trust Tamper-evident ledger (Object Lock + signed checkpoints); daily checkpoints; live cost reconciliation Decision Ledger Coverage 100% · Cost Savings ≥ 25%
Q3 Compounding ROI + Drift Drift-detection scheduler; auto-reversal; pre-apply → actual-spend reconciliation on the pilot estate Drift Auto-Reversal ≥ 95% · Spend Reduction ≥ 25%
Q4 Integration + Predictive ML anomaly-forecasting; AI-agent intent surface; multi-cloud (Azure/GCP) preview Predictive:Reactive ≥ 3:1 · AI-Agent Intent Share (first measurement)

Month-18 destination: "Nova is the layer enterprise leadership points to when they say 'we don't have an infrastructure ops team anymore, and the audit trail is stronger than it ever was.'"

each quarter has a concrete deliverable, a target metric grounded in a strategic objective, and a path from "honestly deferred" to "shipped and measured."
Nova — The Autonomous Cloud Delivery Platform

Slide 18 — Production-Grade Guidance via Atelier (1/2)

Nova instructs the citizen developer's AI agent on production-grade engineering — a set of skills and an MCP server.

  • Skills — markdown files keyed to production-grade engineering domains (API, security, data, testing, observability, errors, DevOps, infrastructure-as-code, compliance); the skills extend the baseline catalog with Nova-specific production-grade principles
  • MCP server — a plugin-registry, stdio server exposing four tools: lookup_principle, list_domains, matrix_lookup, validate_against_principles. The developer's AI agent (or any agentic SDLC platform) calls these tools to look up the principles that apply to its submission
  • The integration point is the same regardless of source — whether the submission comes from an AI coding agent, an agentic SDLC platform, or a traditional IDE, the same skills and MCP server apply. This is how Nova makes the citizen developer production-grade without owning the PDLC
the citizen developer's AI agent is not unguided — Nova provides production-grade engineering principles as skills and as an MCP surface, so submissions arrive at the contract boundary already aligned with the platform's standards.
Nova — The Autonomous Cloud Delivery Platform

Slide 19 — Production-Grade Guidance via Atelier (2/2)

Agentic validation catches engineering-discipline gaps that deterministic scanners miss — and the validation is reproducible.

  • Beyond deterministic scanners — Wiz, Checkmarx, and Mend check policy and secrets; they do not check engineering discipline. The Atelier MCP server catches correctness, clarity, and observability gaps that deterministic tools cannot: "is this service observable?", "is this error path handled?", "is this API contract clear?"
  • Agentic validation, not a second policy engine — the MCP server gives the AI agent the principles to validate against; the agent does the validation. The agent reasons about the submission against the principles, not a second static scan
  • Vendored for audit reproducibility — Atelier is vendored at a pinned tag. A validation result is replayable against the exact principles that produced it, so an audit can reproduce a validation months later, not just trust a log line
the citizen developer's submission is checked for engineering discipline, not just policy compliance — and the check is reproducible for audit. That is what makes the submission production-grade, regardless of which upstream platform produced it.
Nova — The Autonomous Cloud Delivery Platform

Slide 20 — Recap + Ask

The 4-beat recap + the business decision.

Recap:

  • Problem: product teams own infrastructure without the discipline and lifecycle planning it requires; bandwidth gaps and tribal knowledge leave operations exposed
  • Solution: autonomous cloud delivery — operations become visible, trust is provable (deterministic scoring), humans at stage gates
  • Proof: 100% ledger coverage, 100% attestation coverage, grounded ROI formula, four CTO-grade metrics flowing into PowerBI
  • Roadmap: deferred metrics have unblock paths; the 12-month product arc activates one strategic objective per quarter

The ask: "Approve a pilot estate to activate the production-denominator metrics (Lead Time, Vulnerability Count, MTTR, Cloud Spend). Then approve the tamper-evident ledger build-out (S3 Object Lock + signed checkpoints). Together these move Nova from 'pipeline-ready' to 'production-proven.'"

a clear business decision — approve a pilot and the ledger build-out — with the confidence that every claim in this deck is grounded, derived, or honestly deferred.
Nova — The Autonomous Cloud Delivery Platform

Appendix A1 — Metrics Glossary

KPI Definition Status
Touchless Resolution Rate runs without operational stage-gate block ÷ total partial (Post-Pilot)
Human Escalation Frequency operational stage-gate blocks ÷ total partial (Post-Pilot)
Automated Decision Accuracy decisions not followed by failure within 5min partial (Post-Pilot)
MTTR (p95) apply.failed → successful retry grounded
Confidence-Gate Halt Rate runs with band=block ÷ total grounded
Provisioning Lead Time run.completed − run.started grounded
Deployment Frequency count(run.completed) per day grounded
Cost Savings (pre-apply) sum(delta_usd where delta < 0) partial (live reconciliation deferred)
FTE Hours Saved run count × manual baseline × rate derived (N=0 caveat)
Platform ROI (labor + cloud + avoided downtime) ÷ op cost derived (N=0 caveat)
Decision Ledger Coverage decisions with outcome ÷ total grounded
Attestation Coverage prod/dr attested ÷ total prod/dr grounded
Policy Compliance Rate 1 − failed_assets ÷ total grounded
a reference for every metric mentioned in the deck.
Nova — The Autonomous Cloud Delivery Platform

Speaker notes: Do not frame this as "humans are the problem." The problem is that ownership was granted without the discipline, tooling, and lifecycle planning that infrastructure requires. The operator is not the bottleneck because operators exist — the bottleneck is that operations depend on a few individuals instead of an encoded system.

Transition: Here is the destination Nova is building toward.

Talking points: Open with the shift: "you build it, you run it" put Terraform into product teams — ownership without discipline is destroying value; Land the lifecycle-planning gap: resources authored for creation, not for patching/rollback → destructive changes; Land the urgency: AI-era 0-day pace demands proactive scanning as code + at runtime, remediated at threat pace; Call out tribal knowledge / the rockstar-operator problem — the platform should encode the discipline, not the person; Do NOT frame this as "humans are the problem" — the problem is ownership without the discipline and tooling; Key takeaway: the problem is infrastructure ownership without discipline; the answer is an autonomous platform that encodes the discipline

Speaker notes: "Visible" is the operative word. The vision is not just that operations run without an operator — it is that operations become observable, queryable, and accountable. That is what makes the trust defensible.

Transition: The vision is ambitious — here are the strategic objectives that make it concrete, and the anti-goals that keep it focused.

Talking points: Read the vision verbatim — "infrastructure operations become visible" is the operative phrase; Emphasize "provable, not promised" — trust established by deterministic scripts; the platform functions without AI; State the attestation model up front: QA for production, SRE for operational readiness; Key takeaway: autonomous operations with provable trust — security, remediation velocity, reliability, lead time made visible, not promised

Speaker notes: Objective #2 is the one to land carefully: trust is established by deterministic scoring, not by an LLM. The platform functions without AI.

Transition: The objectives are concrete — here is what Nova is NOT, to keep it focused.

Talking points: Objective #1: zero-touch operations — autonomy as the default, not the demo; stage-gate attestation (QA, SRE) remains human by design; Objective #2 is the one to land carefully: trust = deterministic scoring, not an LLM; the platform functions without AI; Objective #3: four CTO-grade metrics (Lead Time, Vuln Count, MTTR, Spend) — all flow into PowerBI; Objective #4 is the integration thesis: Nova integrates with any upstream source; provides skills + MCP; all prod intents go through the same controls; Key takeaway: the scope is explicit — Nova governs infra + delivery, integrates with any source through one contract, measures success on four CTO metrics

Speaker notes: Anti-goals #3 and #4 protect the scope boundary — Nova will not become an IDE or a product-planning tool.

Transition: The scope boundary is explicit — here is exactly where Nova sits relative to the product development lifecycle.

Talking points: Not a general-purpose AI agent platform; Not a system that removes humans from accountability — only from normal operations; Not an upstream development platform (no product backlogs, IDE, code authorship); Not a replacement for the Product Development Lifecycle (PDLC); Anti-goals #3 and #4 protect the scope boundary — Nova will not become an IDE or a product-planning tool; Key takeaway: the boundaries are explicit — Nova is purpose-built for infra ops + delivery, not a general-purpose AI agent or an upstream dev platform

Speaker notes: This slide protects the scope. The moment Nova starts owning the PDLC, it loses focus. The contract boundary is what keeps Nova deep on infrastructure and delivery rather than shallow on everything.

Transition: With the scope clear, here is who owns what across the delivery lifecycle.

Talking points: Nova governs infra + delivery only; the PDLC (backlog, code authorship, IDE) is upstream — Nova stays downstream of it; Integration is only through the validated contract boundary; Any upstream source (AI agent, agentic SDLC, dev platform) produces submissions subject to the same compliance standards; Nova validates the submission, not the author; Key takeaway: Nova is purpose-built for infrastructure operations; the scope boundary is clean and bounded

Speaker notes: Quality attestation is now owned by Quality Engineering (not the Platform), and Production readiness is owned by SRE. The Platform runs the checks agentically but is never the Accountable party for the gate — that separation keeps the platform honest.

Transition: With ownership clear, here is how the pipeline enforces it.

Talking points: Four roles now: Citizen Developer, Platform, Quality Engineering, SRE; Quality attestation is owned by Quality Engineering (not the Platform); Production readiness is owned by SRE; The Platform runs the checks agentically but is never the Accountable party for the gate — that separation keeps the platform honest; Production readiness is co-owned: the platform runs attestations; the citizen developer authorizes the promotion at the stage gate; Key takeaway: you bring FRs + UAT; Nova provides NFRs + infra; QE guards the gate evidence; SRE signs off on production readiness

Speaker notes: The two-stage scan is the key design: static code scanning catches policy violations before the cost of a plan; runtime plan scanning catches what the static code cannot (resolved values, cross-resource issues). The platform picks the runtime scanner based on configuration — never both, to avoid duplicate noise.

Transition: The pipeline produces decisions — here is how every decision is captured and made accountable.

Talking points: Walk the pipeline left-to-right: contract → resolver → adapter → Checkov (static) → plan → Wiz (on plan) → confidence → gate → apply; Two-stage scan: Checkov on static code BEFORE the plan (fail-fast dev feedback); Wiz on the plan (or Checkov as drop-in if no Wiz creds); Never both Wiz + Checkov on the plan — avoid duplicate noise; Dev is autonomous; qa/prod/dr require attestation (QA for quality, SRE for production readiness); Key takeaway: two layers of scanning, zero operator involvement in normal operations

Speaker notes: Do not dwell on the storage substrate. The audience cares that the ledger is append-only, queryable, and tied to outcomes — not that it is a hash-chain in a SQLite file. The D-122 honesty point is restated without the decision ID: the platform's decisions are deterministic; the ledger captures that real path.

Transition: Decisions are captured — here is how stage-gate attestation keeps humans in accountability.

Talking points: "AI decisions" are really automated decisions — deterministic scripts calculate a score; the platform functions without AI; Do not dwell on the storage substrate — the value is accountability (immutable, queryable, traceable to outcome), not the database; Every stage-gate attestation is captured with approver identity and the evidence presented; When an LLM planner is added later, it emits richer alternatives without breaking the schema; Key takeaway: autonomous is defensible because every decision is immutable, queryable, accountable — and "automated" means deterministic scoring, not a black-box LLM

Speaker notes: The matrix is not a rubber stamp. Each concern has a freshness window and a plain-language description of what is being attested. The "operator-supplied" label from the prior deck was dropped — every concern now has a plain-language description.

Transition: QA is half the matrix — here are the production and DR controls.

Talking points: The matrix is not a rubber stamp — structured, freshness-validated; Each concern now has a plain-language description of what is being attested (the old "operator-supplied" label is gone); Three QA concerns: functional correctness (24h), performance baseline (7d), security posture (24h); Each concern has a freshness window — evidence older than the window does not satisfy the gate; Key takeaway: QA signs off on quality before any promotion — the gate is explicit, not implicit

Speaker notes: The prod/DR rows are the operational-readiness and resilience gates — SRE signs off on operability, incident response, capacity, and the three resilience checks (DR drill, chaos, backup). Separation-of-duties on prod is the rule that keeps the gate honest: the approver cannot be the same person who built the deployment.

Transition: You've seen how Nova works — the pipeline, the ledger, the attestation gates. Here is how Nova instruments itself so that every claim in this deck is traceable to a real signal.

Talking points: Seven prod/DR concerns: operational readiness, incident response, capacity & cost, DR drill, chaos, backup, DR region deploy; SRE signs off on operability (runbooks, dashboards, on-call), incident response, capacity, and the three resilience checks; Each concern has a freshness window — 30d/90d/180d depending on the control; SoD on prod: the approver can't be the same person who built it — the rule that keeps the gate honest; Key takeaway: autonomy in operations, human in accountability, by design — the matrix is what makes autonomous operations safe enough to trust in production

Speaker notes: The value is not the plumbing — it is that the platform's metrics surface in a tool leadership already uses (PowerBI), and every number is traceable. The live-ops dashboard is where the "infrastructure operations become visible" theme lands concretely.

Transition: The architecture is sound — here is the measured proof.

Talking points: Deliberately minimal: Nova-native CloudEvents; no Kafka/Prometheus/ClickHouse; The live-ops dashboard is built in PowerBI on top of the exported views — leadership sees the same numbers the platform produces; Every number in the Proof slides is traceable to a signal — "where does this number come from?" → a query against the cold store; This is where the "infrastructure operations become visible" theme lands concretely; Key takeaway: the architecture is the trust substrate — operations become visible in PowerBI, with full traceability

Speaker notes: The mandatory-by-design point is the one to land. The ledger + attestation are not a best-effort feature; they are a gate. No change reaches production without both. That is what makes the 100% numbers credible — they are enforced, not aspirational.

Transition: Trust is provable — here is the cost side of the ROI.

Talking points: Both 100% — no automated decision is ever lost; no prod/dr promotion lands without a human sign-off; The mandatory-by-design point: the ledger entry + the human attestation are a gate, not a best-effort feature; Easily queried: by run, by environment, by approver, by outcome — the audit trail is a query, not a forensic exercise; Key takeaway: trust is provable — not a marketing claim, a queryable record; no change to production without both the ledger entry and the human attestation

Speaker notes: The formula is shown inline, not hidden. The "no fabrication" constraint in action: show the formula, show the caveat, do not pretend the production numbers exist.

Transition: The proof is grounded — here is what is honestly deferred, and why.

Talking points: The ROI formula is shown inline — not hidden in a footnote; The four CTO-grade metrics are the ROI proof — Lead Time, Vuln Count, MTTR, Cloud Spend; The N=0 caveat is stated explicitly: the formula is grounded; the production numbers activate with a pilot; Key takeaway: the ROI is not a black box — the formula is shown, the four metrics are committed, the production-denominator caveat is up front

Speaker notes: The preempt is critical: these deferrals are measurement infrastructure, not autonomy. The platform runs without an operator in the loop. What is deferred is the evidence pipeline for live-infra health, drift, predictive remediation — not the autonomy itself.

Transition: The proof is honest — here is the roadmap from here to the targets.

Talking points: The preempt is critical: these deferrals are measurement infrastructure, not autonomy — the platform IS autonomous in operations; The blocking work is named in plain language (no decision IDs) — "live AWS re-provisioning", "drift-detection scheduler", "ML service"; Showing this to leadership demonstrates honesty, not weakness; Key takeaway: the autonomy is real; the measurement gaps are documented with the work that unblocks each one

Speaker notes: This is the bridge from "honestly deferred" to "here is how we get there." The roadmap uses timeframes, not status — most of it is not implemented yet, so a status column would be noise.

Transition: The unblock path is clear — here is the 12-month product arc.

Talking points: Each deferred metric has an unblock path and a timeframe — near-term, mid-term, longer-term; No status column: most of it is not implemented yet, so status would be noise; Re-evaluation triggers: each blocking piece of work lifts on its own schedule; Key takeaway: every deferred metric has a plan and a timeframe — nothing is hand-waved

Speaker notes: The roadmap is organized by product outcome, not by technical milestone. Each quarter activates one strategic objective from the North Star.

Transition: Here is the quarter-by-quarter detail.

Talking points: This is the *product* roadmap, forward-looking only; Q1 Pilot Activation → Q2 Provable Trust → Q3 Compounding ROI → Q4 Integration & Predictive; Each quarter activates one strategic objective from the North Star; Key takeaway: the 12-month product arc — each quarter activates a strategic objective and its board-level metric

Speaker notes: Q1–Q3 are committed (grounded pipeline + known unblock paths). Q4 targets are committed-deliverable, aspirational-metric — the ML service ships, the intent-share number is a first measurement (we do not control adoption rate).

Transition: Production-grade guidance is how Nova helps the citizen developer's AI agent meet the bar — here is the first half.

Talking points: Q1: three post-pilot metrics go live (Touchless ≥99%, Escalation <0.1%, Accuracy ≥99.5%) — denominator activates with the pilot; Q2: Decision Ledger Coverage was already grounded — tamper-evidence is the Q2 upgrade (local hash-chain → Object Lock + signed checkpoints); Q3: Drift Auto-Reversal ≥95% unblocks when the drift scheduler ships; Spend Reduction ≥25% measured against the pilot baseline; Q4: Predictive:Reactive ≥3:1 requires the ML forecasting service; AI-Agent Intent Share is a first measurement (aspirational-metric); Key takeaway: each quarter has a concrete deliverable, a target metric grounded in a strategic objective, and a path from deferred to shipped

Speaker notes: This is the first half of the Atelier story — the surface (skills + MCP). The next slide is what the surface catches that deterministic scanners cannot.

Transition: Here is what that guidance catches that deterministic scanners cannot.

Talking points: Nova instructs the citizen developer's AI agent via skills (markdown, keyed to engineering domains) + an MCP server (4 tools, plugin-registry, stdio); The integration point is the same regardless of source — AI agent, agentic SDLC, traditional IDE all get the same skills + MCP; This is how Nova makes the citizen developer production-grade without owning the PDLC; Key takeaway: the citizen developer's AI agent is not unguided — Nova provides engineering principles as skills + MCP

Speaker notes: The value is the gap deterministic scanners leave: engineering discipline. Policy scanners catch "is this S3 bucket public?"; the MCP server catches "is this service observable if that bucket fails?". The vendoring point is audit reproducibility — the validation is not a black box.

Transition: You've seen the problem, the solution, and the proof. Here is the recap and the ask.

Talking points: The value is the gap deterministic scanners leave: engineering discipline (Wiz/Checkmarx/Mend check policy/secrets, not discipline); The MCP server catches "is this service observable?", "is this error path handled?", "is this API contract clear?"; Vendored at a pinned tag → audit reproducibility — a validation result is replayable months later; Key takeaway: submissions are checked for engineering discipline, not just policy compliance — and the check is reproducible for audit

Speaker notes: The ask is a business decision, not insider language. "Approve a pilot estate" is a C-suite decision. "Approve the ledger build-out" is a budget decision. The recap reinforces the 4-beat arc — the audience leaves with the structure, not a pile of facts.

Talking points: Recap the 4-beat arc so the audience leaves with the structure; The ask is a business decision: approve a pilot estate + the tamper-evident ledger build-out; "Pipeline-ready" → "production-proven" is the value proposition; Key takeaway: approve a pilot + the ledger build-out to move from pipeline-ready to production-proven

Talking points: Reference for every metric mentioned in the deck; Use if the audience asks "what does X mean?"