← narwal.one/Second Brain
SecondBrain
Ask the Brain
Index/Conceptupdated Sun Sep 27 2026 08:00:00 GMT+0800 (Philippine Standard Time)

Software Factory

ai-engineeringenterpriseharnessforward-deployedwarpcursorgovernancevariability-control

Software Factory

An emerging term-of-art at the AI Engineer WF 2026 for the enterprise infrastructure that turns an AI-engineering practice into a governable, cost-controlled, security-compliant production system. Coined-in-adoption at the event by multiple speakers (notably Zack Lloyd of Warp and Pauline Brunet of Cursor), with a specific origin story from Lloyd:

Zack Lloyd's evolution of the term

Interviewed by Latent Space (reported via Nathaniel Whittemore in 5 AI Engineering Trends That Non Engineers Should Know About (AI Daily Brief)):

  1. Started with one-off automations — "run an agent in the cloud." A lot of platforms began here.
  2. Then it became run an agent in the cloud on a timer.
  3. The next question was: what was the most valuable loop to automate? — the answer: the main loop of software engineering: triage, specification, implementation, review, verification, shipping, and monitoring.

That full-lifecycle-loop is the shape of the factory.

Why the factory (not the interactive agent)

Lloyd's follow-up X post (paraphrased by Whittemore):

"Extensive interactive agent use has created a number of problems, from cost controls to governance to security. The root problem is that interactive agents have human operators, and those humans all use them in very different ways, which don't always maximize business value and can create risk."

Concrete failure modes Lloyd names:

  • Cost drift — a human defaulting to the most expensive model regardless of task (contradicts Model Routing discipline)
  • Security drift — a human installing MCP tools that grant too much access (contradicts Capabilities vs Instructions (Agent Keys))
  • Governance drift — no institutional lineage over what an interactive-agent session actually did

"The idea behind a factory approach is to set up a system that minimizes human variability and maximizes output with controls that ensure security and compliance." — Zack Lloyd

The factory's structural pieces

Not fully anatomised at WF 2026 but the language across Warp + Cursor + peer platforms converges on:

  • Cloud-hosted agent runtime — Cursor SDK; Warp platform — the substrate for long-running / parallel / triggered work
  • Automation triggers — timer / event / PR / user (the "agent on a timer" stage generalised to arbitrary sources)
  • Applications built on top — Brunet: "we've deployed cloud agents, long-running agents, automations, and we've built applications on top of our Cursor SDK"
  • The main-loop taxonomy (Lloyd) — triage → spec → implementation → review → verification → shipping → monitoring — as the process shape the factory implements
  • Variability-control layer — model routing, security policies, spend budgets — the "controls" Lloyd names as the point of the factory framing
  • Human-in-loop decision points — which parts of the loop get human oversight is a factory-configuration question, not a per-run one

Where it sits vs the vault's existing threads

  • Harness (LLM Agents) — a software factory is what happens when a harness graduates from single-engineer-lever to enterprise-infrastructure. The AI Engineer WF 2026 Trend-1 arc (agents → systems around agents) makes harness engineering the discipline; software factory is the product form the discipline ships in an enterprise.
  • Loops as Core Primitive + Tasks to Responsibilities Shift — Lloyd's main loop of software engineering is a resident cross-functional loop (Ryberg's Era 3) implemented at the organisation rather than the individual level. The workflow is the responsibility; the factory is the loop's operating environment.
  • Skills (Claude Code) + Skill Engineering — skills are what get factory-produced (Uber's 2,500+ agent skills per Napali); the factory is what industrialises them.
  • IT Ops Models (A B C) — the factory is Brovich's Platform layer (Model C) — the shared platform the "pods + platform" answer (Model B+C) depends on. Where Brovich left the platform under-specified, Lloyd's software-factory framing gives the platform-side a concrete shape.
  • Verification Tax — the factory's verification stage (Lloyd's review + verification) is where Brovich's "10× to generate, 3× to validate" verification tax gets industrialised — automated tests, agent evals, staged rollouts as first-class factory stages rather than after-thoughts.
  • Reverse Information Paradox — a factory keeps the learning-loop artefacts (traces, evals, corrections) inside the enterprise rather than leaking them into vendor systems. Satya's five-Cs discipline is a factory design principle, not a policy layer.

Whittemore's generalization

Whittemore's follow-through in the episode: the software-factory frame is "very much a software conversation, but I think that a lot of the problems that these software factories are trying to solve for are going to find themselves repeated as agents find their way into other areas of knowledge work." The same variability + cost + security + governance problems show up in marketing agent deployments, sales agent deployments, finance agent deployments — each will need its equivalent factory. Uber's Agentic Pods is the closest working example the vault has of what a non-engineering factory shape looks like: the pods are the factory's assembly line for domain-specific agent skills.

Autonomous-mode note

Named as a "more general term for the set of enterprise infrastructure that apparently was being used a lot at the event" per Whittemore's paraphrase of McManus. Both Warp and Cursor use the term operationally, but each maps it slightly differently onto their platform (Warp explicitly is "a software factory platform" by self-description; Cursor's phrasing is functional / SDK-oriented). Watch for a second event or a substantive Latent Space essay that formally anatomises the concept; this vault expects it will graduate to a full sub-industry vocabulary within 6–12 months.

2026-09-26 — The practitioner's version: gardeners, observability, and 20% time (AI Skills with Matt Pocock (The Pragmatic Engineer))

Matt Pocock gives the factory a human-scale shape and a stakeholder argument:

  • Role: "We are our agents' platform team"; replying to a "every team needs a gardener" post — "the only thing your team needs are gardeners." The core skill is diagnosing codebase entropy (lint suppressions "creeping like ivy") before it bites, and queueing work for agents. Example he cites: Lars Grammel (Vercel AI SDK) building a whole software factory to handle the library's issue volume.
  • How to sell fundamentals to non-engineering stakeholders: (1) observability over every agent in the org — success/failure rate per repo ("invasive for developers, fine for agents — we're paying for this service"); (2) someone owns that data and spreads what high-yield repos do; (3) a common org-wide skill set everyone contributes back to; (4) A/B test workflows across teams. "How do we get more juice out of these tokens?"
  • Budget: maybe ~20% of time on the factory that builds your software — possibly done quietly and revealed with results.
  • Minimal factory loop he runs himself: a daily scheduled improve-codebase-architecture proposal → one click to turn it into tickets → agents ship it; a feedback button in his app that files a GitHub issue → implement agent → review agent → he aligns on the result.
  • The unsolved recursion: automated review agents enforce standards and catch tautological tests — "but then how do you know if the automated review agent is doing a good job?"
  • Cloud, not laptops: Orosz reports Ramp/Stripe/Uber platform teams moving the full dev setup into cloud machines invocable from Slack; 70–80% of devs choose it voluntarily (frontend the exception).

2026-09-27 — McKinsey's "agent factories" (per Rewiring Talent to Value in the Age of AI (McKinsey))

McKinsey uses "agent factories" for coordinated groups of AI roles (workflow architects, agent-ops leads, governance liaisons, knowledge specialists) handling end-to-end workflows — arguing that in this setting talent pools matter as much as individual critical roles. Same pattern as the software factory, generalized beyond code. See Talent to Value.

Sources

  • 5 AI Engineering Trends That Non Engineers Should Know About (AI Daily Brief) — Whittemore's July 2026 read-out of Richard McManus's AI Engineer WF 2026 write-up; Lloyd + Brunet + Napali's parallel Uber-pods result
  • AI Skills with Matt Pocock (The Pragmatic Engineer) — gardener/platform-team framing, agent observability as the stakeholder metric, ~20% factory time