Methodology Reference · August 2026 · AI-Augmented Software Engineering · Agentic AI Platforms & Orchestration · AI TRiSM

The Five-Gate
Manufacturing Model

How governed, sovereign enterprise software is delivered at machine speed. A single requirement becomes a deployed, WAF-assessed, compliance-audited application inside your own Azure tenant — through five human gates and eight specialist agents. Classified by Gartner under AI-Augmented Software Engineering (AIASE) and Agentic AI Platforms & Orchestration, with AI Trust, Risk, and Security Management (AI TRiSM) enforced at every gate.

AI-Augmented Software Engineering Agentic AI Platforms & Orchestration AI TRiSM Custom AI Development Services

The Manufacturing Philosophy

Three principles borrowed from industrial manufacturing.

01

Specification before fabrication

No material is cut before the blueprint is locked. No code is written before the requirement is fully specified, governance constraints are surfaced, and a human has approved the design. This eliminates the largest source of enterprise software failure — ambiguous requirements that expand mid-build.

02

Quality gates, not quality reviews

A quality gate is binary: pass or block. An output that fails a gate does not advance. There is no override path for a failing gate — the defect is resolved before progression. Recommendations that may or may not be acted on are not gates.

03

IP transfers at Gate 5. Operations continue.

At Gate 5, intellectual property transfers in full — source code, deployment history, model lineage, compliance documentation, as-built records. The client owns 100% of what was built, with no vendor lock-in. For Tier 2 and Tier 3 clients, managed platform operations then continue as a standing service — keeping the estate evergreen, the guardrails current, and the compliance posture maintained.

The Five Gates

Humans govern the transitions.
Agents manufacture the work between them.

Requirement
Gate 1
Architecture
Gate 2
IaC Plan
Gate 3
Build
Gate 4
Deployed
Gate 5
Handover
1

Specification sign-off

Approver: Client stakeholder — business or IT lead

Minerva issues a Readiness Passport — a scored specification covering data residency, regulatory classification, data source integrity, connectivity, and business impact. Scored out of 100. Conditional items are logged with resolution owners. Any BLOCKED item prevents progression.

Artefact northbridge-requirements.md — engagement ID, gate-by-gate RAG assessment, score, condition log, authorisation
2

Architecture and cost sign-off

Approver: Solution architect or IT director

Vitruvius designs the cloud topology and scores it against five WAF pillars (minimum 6, target 8). The Sovereign Gate auto-rejects any design scoring below 7 in Security or Reliability. Plutus queries live Azure pricing, confirms UK South availability, and verifies all AI model SKUs are Standard regional — Global routing breaks data sovereignty. Themis challenges the architecture before Gate 2 opens.

Artefacts northbridge-adr.md · northbridge-hld.md · sku-manifest.json
3

IaC plan and compliance sign-off

Approver: Security architect or compliance lead

Nemesis queries the live Azure Policy REST API — including management-group-inherited assignments — classifying every Deny, Modify, and Append effect as a hard constraint on the build. Themis runs a pre-flight compliance report against ISO 27001, ISO 42001, FCA SYSC, UK GDPR, and NCSC CAF. Fabricius converts the approved architecture, cost, and governance constraints into a machine-readable implementation plan with AVM modules pinned at live-verified versions.

"Gate 3 is where most enterprise projects hide their debt. The Five-Gate Model makes governance constraints, compliance review, and build contracts all hard before a single line of Bicep is written."

Artefacts northbridge-governance-constraints.md · northbridge-audit-preflight.md · northbridge-implementation-plan.md
4

Deployment authorisation

Approver: IT operations lead or platform team

Vulcan reads only Fabricius's approved implementation plan and generates AVM-first, born-compliant Bicep: tagging lock on every resource, zero hardcoded secrets, no public endpoints on data or AI services, diagnostic settings throughout. Cassandra then runs a deployment what-if — predicting every resource change against the live subscription state and cross-checking against Nemesis's governance constraints. Any policy violation or unexpected delete blocks Gate 4. Cassandra prophesies. Cassandra never deploys.

Artefacts Bicep module set · whatif-preview.md · Azure DevOps backlog CSV
5

Final acceptance and handover

Approver: Client executive or programme sponsor

Themis executes the definitive adversarial review of the live deployed system — not the design, the running infrastructure. WAF scorecard produced. Gate 5 status: APPROVED, CONDITIONAL, or BLOCKED (critical finding triggers rollback). IP transferred in full — source control, deployment history, model lineage, compliance documentation.

"Gate 5 is the only gate that can trigger a rollback. A critical finding means the deployment does not proceed to production. The client never inherits a critical security gap."

Artefacts northbridge-gate5-handover.md · northbridge-waf-scorecard.md

Governance Coverage

Framework alignment — applied at defined gates.

ISO 27001 Gate 3 Information security controls
ISO 42001 Gate 3 AI governance — explainability, bias, model risk
FCA SYSC 6.3 Gates 1 & 3 Operational resilience
FCA Consumer Duty Gates 1 & 5 AI decision explainability
NCSC CAF Gates 3 & 5 Cyber resilience — CNI and defence
UK GDPR Gates 1 & 3 Data minimisation, purpose limitation
JSP 440 / JSP 936 Gates 3 & 5 Defence information security assurance
Azure WAF 2026 Gates 2 & 5 Five-pillar Well-Architected assessment

The factory delivers.
The platform operates.
The client owns everything.

Read the full methodology whitepaper, see the Five-Gate Model run end-to-end on the NorthBridge Bank reference engagement, or explore how the Land / Establish / Expand commercial model works in practice.