Skip to content

2026 06 13 standardization customization balance context ai

github-actions[bot] edited this page Jul 1, 2026 · 1 revision

How should the balance between standardized and customized internal tooling shift across industries, organisation sizes, maturity levels, and Artificial Intelligence (AI) agent adoption patterns, and what evidence exists for effects on productivity, innovation, and employee experience?

Research Question

How should the balance between standardized and customized internal tooling shift across industries, organisation sizes, maturity levels, and Artificial Intelligence (AI) agent adoption patterns, and what evidence exists for effects on productivity, innovation, and employee experience?

Scope

In scope:

  • Differences between regulated and less-regulated sectors, including finance, healthcare, and software-intensive technology organisations.
  • How organisational size and maturity change the viable balance between standardization and local customization.
  • Evidence on outcomes such as productivity, innovation, employee experience, resilience, and governance burden.
  • How shared skill libraries, shared agent files, or centralized agent platforms alter the trade-off in Artificial Intelligence (AI)-enabled environments.

Out of scope:

  • A single universal policy recommendation for every organisation.
  • Detailed human-resources policy, compensation policy, or labour-market forecasting.
  • Full technical implementation design for any one industry.

Constraints: This is a synthesis item that should integrate the findings of the four companion backlog items in this series before it is started.

Context

This item informs how decision-makers should choose different governance balances for different contexts instead of importing one standardization policy across organisations with very different risk profiles, dependency structures, and Artificial Intelligence (AI) operating models.

Approach

  1. Compare how regulation, auditability, and operational criticality change the case for standardization across industries.
  2. Analyse how organisational size and maturity affect the cost of local customization and the value of shared tooling.
  3. Review empirical or case-study evidence on productivity, innovation, and employee-experience outcomes from standardization initiatives.
  4. Assess how Artificial Intelligence (AI) agents and shared skill libraries change the feasible balance between local autonomy and central platforms.

Sources

Related


Research Skill Output

(Full output from running the research skill, retained verbatim in the completed item. Sections 0 to 5 are the investigation; section 6 seeds the Findings section below.)

§0 Initialise

Question: How should the balance between standardized and customized internal tooling shift across industries, organisation sizes, maturity levels, and Artificial Intelligence (AI) agent adoption patterns, and what evidence exists for effects on productivity, innovation, and employee experience?

Scope: In scope is a comparison of regulated versus less-regulated sectors, organisational size and maturity effects on the standardization-customization trade-off, empirical evidence on productivity/innovation/employee-experience outcomes, and how AI agents and shared skill libraries change the feasible balance. Out of scope is a single universal policy recommendation, human-resources or compensation policy, and full technical implementation design for any one industry.

Constraints: This is a synthesis item (item_type: synthesis) that integrates four companion repository items completed on 2026-06-13 (local-global throughput dynamics, fragmentation-threshold measurement, platform-engineering/InnerSource (the use of open-source collaboration principles inside an organisation) hybrid patterns, and shadow Information Technology (IT) governance transition), plus three earlier repository items on banking agent governance, shadow AI behavioural drivers, and AI/low-code platform-engineering integration. No new primary field research is conducted in this item; the contribution is cross-item integration plus three additional seed sources (a healthcare standardization framework, a classic international-management framework, and the DORA (DevOps Research and Assessment) 2025 report) that the companion items did not fully cover.

§1 Question Decomposition

Approach 1: regulation, auditability, operational criticality across industries. 1a. How does the banking/financial-services case change the standardization case relative to general software delivery? (companion: banking agent sprawl) 1b. How does the healthcare case change the standardization case relative to general software delivery? (seed: Sinsky et al. 2021) 1c. Does the shadow-IT literature identify regulation as a modifier of the general governance answer, not just its intensity?

Approach 2: organisation size and maturity. 2a. What structural multipliers change the crossover point between local-tooling benefit and cost as organisations scale? (companion: fragmentation-threshold measurement) 2b. What does a maturity-stage model (the Cloud Native Computing Foundation (CNCF) Platform Engineering Maturity Model) say about how the standardization/customization balance should shift as platform capability matures? 2c. Does Bartlett and Ghoshal's transnational framework generalise the size/maturity finding to an industry-independent structural logic?

Approach 3: empirical evidence on productivity, innovation, employee experience. 3a. What does DORA (DevOps Research and Assessment) 2025 report about AI's effect on organisations with different tooling/platform maturity? 3b. What does the local-global-optima companion item's Faros AI telemetry show about the local/global throughput trade-off under AI-assisted delivery? 3c. What does the shadow-IT literature report about employee-experience benefits (satisfaction, agility) versus organisational risk costs (continuity, control loss)?

Approach 4: AI agents and shared skill libraries changing the feasible balance. 4a. How does the shadow-AI-behavioural-drivers companion item change the governance answer relative to earlier, non-agentic shadow IT? 4b. What does the platform-engineering/InnerSource companion item say about golden-path and Trusted Committer patterns as the AI-era mechanism for combining central control with local extension? 4c. What does the AI/low-code Software Development Lifecycle (SDLC) integration companion item say about where the standardization line should sit for AI-specific governance surfaces?

§2 Investigation

1a. Banking case. Uncoordinated department-level agent growth in banks shifts risk from single-model error toward cross-division coordination failure, and banking sources converge on the need for one central governance core for inventory, policy, version history, and resilience evidence, even while domain teams keep running agents locally inside shared rules. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html] Bank model-risk-management guidance requires review intensity to scale with an agent's size, complexity, and risk profile rather than applying one uniform review standard to every tool, which is a proportional-tiering answer rather than a uniform-standardization or uniform-customization answer. [inference; source: https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html] Automation in banks relocates the operational bottleneck into validation, exception handling, incident triage, and compliance decision queues rather than eliminating human control work, meaning the standardization case in a regulated sector centres on queue and evidence infrastructure rather than on the local tool itself. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html]

1b. Healthcare case. Sinsky et al. (2021), writing in a peer-reviewed family-medicine journal, argue that excessive standardization in clinical workflows reduces professional autonomy and clinicians' ability to address unique patient contexts, while excessive customization produces chaos and inefficiency, and that current healthcare practice leans too far toward standardization relative to the optimal balance. [fact; source: https://www.annfammed.org/content/19/2/171; https://europepmc.org/article/MED/33685879] This is a directly opposing directional pressure from the banking case: banking evidence argues for centralising governance infrastructure as agent volume rises, while the clinical case argues that the existing standardization level in a comparably high-stakes, high-regulation domain is already excessive relative to the value of professional judgement at the point of care. [inference; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html] The reconciling structural distinction is that the banking evidence targets governance infrastructure (inventory, audit trail, review-tiering, resilience testing) rather than the frontline task itself, whereas the healthcare critique targets standardization of the frontline task (the clinical workflow) rather than the supporting audit infrastructure; the two cases are not in direct conflict once "standardization of infrastructure" is separated from "standardization of task execution." [inference; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html]

1c. Regulation as a modifier of the general governance answer. The shadow-IT systematic-review literature that the companion governance-transition item draws on states directly that strict forbidding of local tooling may be the more reasonable choice for critical processes or highly regulated businesses, even though the same literature argues against blanket prohibition as a general policy. [fact; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] This confirms regulation changes the correct governance answer qualitatively, not only its intensity: regulated, operationally-critical domains shift the default away from permitted local customization and toward centrally validated standard paths, while less-regulated domains retain wider latitude for local extension. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]

2a. Structural multipliers and the crossover point. The fragmentation-threshold companion item identifies three structural multipliers that accelerate the point at which aggregate local-tooling cost exceeds customization benefit: team scale (each additional team creates its own maintenance surface), shared-dependency density (tools feeding downstream processes impose integration complexity on all consumers), and staff turnover (bus factor decline as undocumented tool owners leave). [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html; https://aisel.aisnet.org/ijispm/vol7/iss1/3/] No peer-reviewed source in that item establishes a universal numeric threshold; the crossover is context-dependent on these three multipliers rather than a fixed tool count or headcount figure, which means larger and more interdependent organisations reach the crossover sooner at any given rate of local tool creation, but there is no fixed organisation-size cutoff. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]

2b. Maturity-stage evidence. The Cloud Native Computing Foundation (CNCF) Platform Engineering Maturity Model identifies platforms whose adoption moves from mandate-driven to self-selected as reaching Level 3 maturity, and treats the highest maturity state (Level 4, optimising) as one where specialist teams extend shared capabilities directly rather than routing all changes through a central backlog. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://tag-app-delivery.cncf.io/whitepapers/platform-eng-maturity-model/] This maps a maturity trajectory: immature organisations rely on mandate-driven centralisation because no trusted shared alternative yet exists, while mature organisations shift toward voluntary adoption of a well-supported standard core with governed local extension points, which is a maturity-dependent shift in balance rather than a fixed policy. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]

2c. Bartlett and Ghoshal's transnational framework. Bartlett and Ghoshal (1988) describe four organisational response types to the tension between global integration and local responsiveness in multinational firms, of which the "transnational solution" combines a standardized core (for global efficiency and consistency) with local adaptation (for market responsiveness) and bidirectional knowledge flows across the organisation. [fact; source: https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/] The platform-engineering companion item maps this framework directly onto the golden-path-plus-InnerSource combination for internal tooling: the platform provides integration, InnerSource (the use of open-source collaboration principles inside an organisation) provides bidirectional contribution, and extension points provide local responsiveness, generalising the industry-specific findings above into a structural pattern independent of sector. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/]

3a. DORA 2025 findings. The DORA (DevOps Research and Assessment) 2025 report, surveying nearly 5,000 technology professionals, finds that Artificial Intelligence (AI) acts as an amplifier of existing organisational conditions rather than a universal productivity booster: teams with mature platform engineering and loose coupling convert AI gains into system-level improvement, while teams with fragmented tooling experience accelerating instability. [fact; source: https://dora.dev/research/2025/dora-report/; https://davidamitchell.github.io/Research/research/2026-06-13-local-global-optima-knowledge-work-throughput.html] This is the strongest single piece of evidence tying AI agent adoption directly to the standardization/customization question: AI adoption does not shift the optimal balance toward more standardization or more customization in the abstract, it magnifies whatever balance (and its supporting infrastructure maturity) already exists. [inference; source: https://dora.dev/research/2025/dora-report/]

3b. Faros AI telemetry on the local/global trade-off. Faros AI telemetry across 22,000 developers, cited in the local-global-optima companion item, found individual task completion rose 33.7% under AI-assisted delivery while pull request (PR) review time rose 441% and production incidents per PR rose 242.7%, a pattern consistent with local productivity gains flooding shared review and validation infrastructure that was not scaled commensurately. [fact; source: https://www.faros.ai/blog/key-takeaways-from-the-dora-report-2025; https://davidamitchell.github.io/Research/research/2026-06-13-local-global-optima-knowledge-work-throughput.html] The companion item notes AI-generated code quality degradation as a competing explanation for the same data pattern, so this evidence should be read as consistent with, not conclusive proof of, the local-optima mechanism. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-global-optima-knowledge-work-throughput.html]

3c. Employee-experience and risk trade-off. Two independent systematic literature reviews of shadow Information Technology (IT) converge on five recurring benefit categories (productivity, innovation, agility, satisfaction, collaboration) and five recurring risk categories (security, integration, synergy loss, control loss, continuity lack), with continuity lack naming the mechanism by which locally-owned tooling becomes an operational risk once its single owner departs. [fact; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf] Neither review quantifies the continuity-failure cost in monetary or time terms; the fragmentation-threshold companion item's Faros AI telemetry is the closest available proxy quantification but measures aggregate fragmentation cost rather than an isolated continuity event, so any specific cost figure for the employee-experience/productivity trade-off should be treated as an estimate rather than a directly measured figure. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]

4a. Agentic shadow AI changes containment difficulty. Sanctioned AI rollout does not, by itself, materially suppress unsanctioned AI use; it more often normalises AI use while employees continue choosing faster or better-fitting unofficial tools, and this behavioural pattern is continuous with earlier shadow IT waves. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html] What changes with agentic AI is the containment problem, not the behavioural driver: agentic, tool-calling shadow AI adds cognition, autonomy, and machine-speed action risk that require discovery, attributed telemetry, and pre-action controls, which is a materially higher governance bar than the policy-and-app-inventory controls that sufficed for earlier local tools. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html] This means the customization/standardization balance for AI agents specifically should shift toward standardization of the control plane (identity, telemetry, pre-action approval) even in less-regulated sectors, while the balance for the underlying task logic can remain closer to the general, non-AI answer. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html]

4b. Golden path and Trusted Committer as the AI-era mechanism. The golden path pattern (an opinionated, supported default with permitted deviation) is the most consistently documented pattern for preserving local agility while reducing fragmentation, because it removes the incentive to fork local copies of shared assets by making the standard option easier and more discoverable than building locally. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://engineering.atspotify.com/2020/08/how-we-use-golden-paths-to-solve-fragmentation-in-our-software-ecosystem] The InnerSource Trusted Committer pattern scales shared-asset governance from a single owning team to a distributed network of contributing-team members with commit rights, increasing review capacity and embedding local knowledge in shared assets without centralising all decisions, which is directly transferable to shared AI agent skill libraries and shared agent configuration files. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://patterns.innersourcecommons.org/p/trusted-committer]

4c. AI/low-code platform-engineering integration. AI and low-code delivery should extend the existing Software Development Lifecycle (SDLC) rather than run a separate governance process, with any additional specialized assurance lane for higher-risk AI or low-code changes implemented as an extension of shared Continuous Integration and Continuous Delivery (CI/CD), release, and environment controls. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html; https://dora.dev/research/2024/dora-report/] Platform teams should encode the governed path as templates, catalogs, modules, policy bundles, and deployment defaults so teams start from a compliant scaffold instead of retrofitting governance after local build, which is the same golden-path logic applied specifically to AI and low-code delivery surfaces. [inference; source: https://davidamitchell.github.io/Research/research/2026-04-26-ai-lowcode-sdlc-platform-engineering-integration.html]

Access note: DORA report landing page at https://dora.dev/report/2025 redirects to https://dora.dev/research/2025/dora-report/; citations above use the resolved URL.

§3 Reasoning

The evidence across all four companion items and the three additional seed sources converges on a single structural logic rather than four independent answers. First, the standardization/customization balance is not one variable but two: standardization of governance infrastructure (identity, audit trail, telemetry, review tiering) and standardization of task execution (the actual workflow or tool a team uses day to day). [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html; https://www.annfammed.org/content/19/2/171] Regulation and operational criticality push the governance-infrastructure axis toward standardization regardless of sector, while task-execution standardization should track local maturity and demonstrated shared-asset quality rather than regulatory status alone. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]

Second, organisation size and maturity do not shift the balance directly; they shift the crossover point at which local customization's cost exceeds its benefit, through three multipliers (team scale, shared-dependency density, staff turnover) that compound with organisational growth. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html] Maturity acts on the same axis from the supply side: a platform that reaches CNCF Level 3 or 4 maturity earns voluntary adoption, which lets an organisation raise task-execution standardization without a mandate, converting what would otherwise be a coercive trade-off into a preference-aligned one. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]

Third, AI agent adoption interacts with this structure in two distinct ways rather than one. On productivity and innovation outcomes, AI acts as an amplifier of the existing governance-infrastructure and platform maturity rather than an independent driver toward more or less standardization: the same local-productivity-gain pattern that floods an under-scaled review queue in conventional software delivery reappears in AI-assisted delivery telemetry. [fact; source: https://dora.dev/research/2025/dora-report/; https://www.faros.ai/blog/key-takeaways-from-the-dora-report-2025] On governance-surface design specifically, agentic AI raises the minimum required standardization of the control plane (identity, telemetry, pre-action approval) above what sufficed for earlier non-agentic local tools, independent of sector or maturity, because agentic tool-calling failure modes are qualitatively harder to detect and contain after the fact. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html]

Fourth, the golden-path-plus-Trusted-Committer combination, and its generalisation in Bartlett and Ghoshal's transnational model, is the best-evidenced structural answer to how an organisation should shift its balance as any of these four variables (industry regulation, size, maturity, AI adoption) changes: rather than picking a single point on the standardization-customization spectrum, organisations should invest in making the standard core good enough that local teams choose it voluntarily, while building governed extension points and distributed commit rights so that legitimate local variation is captured inside governance visibility instead of forced outside it. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/]

§4 Consistency Check

contradiction_scan: one apparent contradiction identified between banking evidence (favours centralisation) and healthcare evidence (favours less standardization); resolved in §2.1b by distinguishing governance-infrastructure standardization from task-execution standardization
confidence_adjustment: no claim raised above medium confidence except DORA 2025 amplifier finding and shadow-IT benefit/risk taxonomy, both supported by fact-labelled primary or near-primary sources cited independently in multiple companion items
scope_guardrail: maintained; no universal single-policy recommendation stated, consistent with Scope out-of-scope constraint
cross_item_dependency: this item's confidence is bounded by the confidence levels already assigned in the four companion items, most of which carry medium confidence; this item does not manufacture higher confidence than its sources support

§5 Depth and Breadth Expansion

Technical lens: The golden-path pattern's technical mechanism (make the supported default easier and more discoverable than a local build) transfers directly to AI agent tooling: a shared, well-documented agent skill library with commit-review rights distributed to trusted contributors is the technical analogue of Spotify's software golden path, and the InnerSource Portal pattern's documented failure mode (teams cannot find a shared asset and duplicate it locally) applies identically to agent skill discovery. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://patterns.innersourcecommons.org/p/innersource-portal]

Regulatory lens: Bank model-risk-management guidance and the shadow-IT literature's regulated-sector carve-out both converge on the same modifier: regulatory exposure changes which axis (governance infrastructure versus task execution) must be standardized, not merely how strictly the general policy is enforced. [inference; source: https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html] This suggests the research question's framing of "regulated versus less-regulated sectors" as a single spectrum understates the structure: the correct axis for regulatory effect is which layer of the tooling stack is regulated (data handling, decision authority, audit trail) rather than the sector label itself. [inference; source: https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]

Economic lens: The fragmentation-threshold companion item's finding that no peer-reviewed source establishes a universal numeric crossover means the economic case for shifting the balance cannot currently be made with a general formula; the practical economic answer is to track the five leading indicators that item identifies (support-ticket growth, new-hire time-to-productivity, shadow-spend growth, integration-failure frequency, downstream-queue growth) as an early-warning system rather than to apply a static organisation-size rule. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]

Historical lens: Bartlett and Ghoshal's 1988 transnational framework predates AI agent tooling by nearly four decades, and its persistence as the best-fitting structural explanation for a 2026-era software and AI-agent governance problem is itself evidence that the standardization-customization tension is a structural property of multi-unit organisations rather than a technology-specific problem introduced by AI. [inference; source: https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/; https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]

Behavioural lens: The shadow-AI companion item's finding that sanctioned rollout normalises AI use without displacing unofficial tool choice indicates that the standardization/customization balance cannot be shifted by mandate or communication alone; the same "stay busy" cultural amplifier the local-global-optima companion item identifies for the general local-optima failure mode (managers equating individual utilisation with value creation) plausibly extends to why local AI tool choice persists even after a sanctioned rollout, though this specific behavioural transfer is not directly tested by any cited source. [assumption; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html; https://davidamitchell.github.io/Research/research/2026-06-13-local-global-optima-knowledge-work-throughput.html]

§6 Synthesis

Executive summary:

The standardization/customization balance should shift along two independent axes rather than one: governance-infrastructure standardization (identity, audit trail, review tiering, telemetry) should rise with regulatory exposure and operational criticality regardless of organisation size, while task-execution standardization should rise with demonstrated platform maturity and organisation scale, converging on a golden-path-plus-governed-extension-points design as organisations grow. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf] Artificial Intelligence (AI) agent adoption does not independently push the balance toward more or less standardization on productivity and innovation outcomes; it amplifies whatever governance and platform maturity already exists, per the DORA (DevOps Research and Assessment) 2025 report's amplifier finding, while independently raising the minimum required standardization of the AI-specific control plane because agentic, tool-calling failure modes are harder to detect and contain than earlier non-agentic local tooling. [fact; source: https://dora.dev/research/2025/dora-report/] [inference; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html] Regulated, high-criticality domains such as banking do not uniformly favour more standardization than less-regulated domains; the healthcare literature shows the opposite pressure applies to standardization of frontline task execution even in a comparably regulated sector, which resolves once governance-infrastructure standardization is separated from task-execution standardization. [inference; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html] No cited source establishes a universal numeric threshold for organisation size or maturity at which the balance should shift, so the practical guidance is to track leading indicators of fragmentation cost and platform adoption voluntariness rather than apply a fixed rule. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]

Key findings:

  1. The standardization-customization trade-off operates on two separable axes, governance-infrastructure standardization and task-execution standardization, and conflating them produces apparent contradictions between sector-specific evidence that are resolved once the axes are separated. ([inference]; medium confidence; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html)
  2. Regulatory exposure and operational criticality push governance-infrastructure standardization upward regardless of sector, with bank model-risk guidance requiring review intensity proportional to size, complexity, and risk profile, and shadow-IT literature independently stating that strict prohibition may be reasonable for critical or highly regulated processes. ([inference]; medium confidence; source: https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html)
  3. Organisation size and maturity shift the crossover point at which local customization's aggregate cost exceeds its benefit through three compounding multipliers, team scale, shared-dependency density, and staff turnover, rather than through a fixed headcount or tool-count threshold. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html)
  4. Platform maturity, measured by the Cloud Native Computing Foundation (CNCF) Platform Engineering Maturity Model, changes the mechanism by which standardization is achieved, from mandate-driven adoption at low maturity to voluntary adoption at Level 3 and specialist-extension at Level 4, which converts a coercive trade-off into a preference-aligned one as maturity rises. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html)
  5. The DORA 2025 report, surveying nearly 5,000 technology professionals, found that Artificial Intelligence (AI) amplifies existing organisational conditions rather than independently improving productivity, so AI adoption magnifies whatever standardization/customization balance and infrastructure maturity already exist rather than dictating a new balance. ([fact]; medium confidence; source: https://dora.dev/research/2025/dora-report/)
  6. Faros AI telemetry across 22,000 developers found individual task completion rising 33.7% under AI-assisted delivery while pull request (PR) review time rose 441% and production incidents per PR rose 242.7%, a pattern consistent with local AI-driven productivity gains flooding shared review infrastructure that was not scaled commensurately, though AI-generated code quality degradation is a competing explanation for the same data. ([inference]; medium confidence; source: https://www.faros.ai/blog/key-takeaways-from-the-dora-report-2025)
  7. Agentic, tool-calling shadow Artificial Intelligence (AI) raises the minimum required standardization of the AI-specific control plane, identity, telemetry, and pre-action approval, above what sufficed for earlier non-agentic local tooling, because discovery alone cannot reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html)
  8. The golden path pattern, an opinionated supported default with permitted deviation, combined with the InnerSource Trusted Committer pattern that distributes commit rights to contributing-team members, is the most consistently evidenced design for preserving local agility while reducing ungoverned fragmentation, and it generalises to shared AI agent skill libraries. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://engineering.atspotify.com/2020/08/how-we-use-golden-paths-to-solve-fragmentation-in-our-software-ecosystem)
  9. Bartlett and Ghoshal's 1988 transnational framework, combining a standardized core, local adaptation, and bidirectional knowledge flow, predates AI agent tooling and Cloud-native platform engineering by decades yet best explains the current golden-path-plus-InnerSource pattern, indicating the standardization-customization tension is a structural property of multi-unit organisations rather than a technology-specific problem. ([inference]; medium confidence; source: https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/; https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html)
  10. Two independent systematic literature reviews of shadow Information Technology (IT) converge on the same five employee-experience benefit categories (productivity, innovation, agility, satisfaction, collaboration) and five risk categories (security, integration, synergy loss, control loss, continuity lack), but neither quantifies the continuity-failure cost in monetary or time terms, leaving the employee-experience-versus-risk trade-off qualitatively established but not numerically measured. ([fact]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf)
  11. Sanctioned AI tool rollout does not reliably displace unofficial AI tool choice, normalising AI use as work infrastructure while employees continue selecting faster or better-fitting shadow tools, which means standardization policy for AI agents cannot rely on rollout communication alone and must instead make the sanctioned lane lower-friction than the alternative. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html)

Evidence map:

Claim Source Confidence Notes
[inference] Trade-off operates on two separable axes (governance-infrastructure vs. task-execution standardization) https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html medium This item's cross-source synthesis; resolves apparent banking/healthcare contradiction
[inference] Regulatory exposure pushes governance-infrastructure standardization upward https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html medium Cross-source generalisation; each source individually supports only the regulated-sector case it addresses, not a sector-independent claim
[inference] Size/maturity shift crossover point via three multipliers https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html medium No universal numeric threshold established in the underlying literature
[inference] CNCF maturity model changes standardization mechanism (mandate to voluntary) https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://tag-app-delivery.cncf.io/whitepapers/platform-eng-maturity-model/ medium Companion item primary finding
[fact] DORA 2025: AI amplifies existing organisational conditions https://dora.dev/research/2025/dora-report/ medium Survey of nearly 5,000 technology professionals
[inference] Faros telemetry pattern consistent with local-gain flooding shared review queues https://www.faros.ai/blog/key-takeaways-from-the-dora-report-2025 medium Competing explanation (code-quality degradation) not ruled out
[inference] Agentic shadow AI raises minimum control-plane standardization https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html medium Discovery alone insufficient for agentic tool-calling risk
[inference] Golden path + Trusted Committer generalises to AI agent skill libraries https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://engineering.atspotify.com/2020/08/how-we-use-golden-paths-to-solve-fragmentation-in-our-software-ecosystem medium Transfer of software pattern to AI tooling is this item's inference
[inference] Bartlett and Ghoshal's transnational model generalises the pattern across sectors and eras https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/; https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html medium 1988 framework applied to 2026-era AI tooling context
[fact] Shadow IT benefit/risk taxonomy converges across two independent reviews https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf high Continuity-failure cost not quantified in either review
[inference] Sanctioned rollout does not displace unofficial AI tool choice https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html high Corroborated across Microsoft, IBM, and Cyberhaven sources in the companion item

Assumptions:

  • Assumption: The "stay busy" cultural amplifier identified for the general local-optima failure mode in software delivery also explains persistent local AI tool choice after sanctioned rollout. Justification: Both mechanisms describe local actors preferring perceived individual speed or fit over shared-system outcomes, but no cited source directly tests this specific behavioural transfer from software delivery to AI tool adoption. [assumption; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-global-optima-knowledge-work-throughput.html; https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html]
  • Assumption: The golden-path-plus-Trusted-Committer pattern, evidenced primarily in software engineering contexts, transfers to shared AI agent skill libraries with comparable effectiveness. Justification: The underlying mechanism (reduce the incentive to build locally by making the shared option easier to find and use) is domain-general, but no cited source directly measures this pattern's effectiveness specifically for AI agent tooling. [assumption; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]

Analysis:

The most direct tension in the evidence set is between the banking companion item, which argues for more centralised governance as agent volume rises, and the Sinsky et al. healthcare source, which argues current standardization already exceeds the optimal level in a comparably regulated domain. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html; https://www.annfammed.org/content/19/2/171] This tension is resolved by separating governance-infrastructure standardization from task-execution standardization: banking sources target audit trail, identity, and review-tiering infrastructure, while the healthcare critique targets standardization of the clinical workflow itself. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html; https://www.annfammed.org/content/19/2/171] A rival explanation for the apparent contradiction, that the two domains simply warrant different standardization levels because healthcare is less standardization-tolerant than banking as a domain trait, is weaker than the two-axis explanation, because the shadow-IT literature's regulated-sector carve-out applies the same qualitative shift (toward stricter control) across sectors once criticality is held constant, which is inconsistent with a domain-trait explanation that would predict healthcare should also favour centralisation given its comparable regulatory intensity. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]

A second competing interpretation worth engaging is that AI agent adoption itself, rather than existing platform maturity, is the primary driver of instability documented in the Faros AI telemetry and the DORA 2025 report. The DORA 2025 report's own framing, that AI amplifies existing organisational conditions rather than creating a new failure mode, weighs against this rival explanation, because the same report finds that mature-platform organisations convert AI gains into system-level improvement rather than instability, which would not be expected if AI adoption itself were the primary destabilising factor independent of existing maturity. [inference; source: https://dora.dev/research/2025/dora-report/]

The evidence is asymmetric in strength across the four Approach areas: the maturity and platform-engineering evidence (Approach 2 and 4) rests on well-corroborated, multiply-cited patterns (golden path, Trusted Committer, CNCF maturity levels) with fact-labelled primary confirmation in at least one companion item, while the size-threshold evidence (Approach 2a) explicitly lacks any peer-reviewed numeric threshold and should be treated as directional rather than predictive. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]

Risks, gaps, uncertainties:

  • No cited source directly measures the transfer of the golden-path-plus-Trusted-Committer pattern from general software engineering to AI agent skill libraries specifically; this item's Key Finding 8 and the Assumptions section flag this as an inference requiring dedicated validation. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]
  • No peer-reviewed source establishes a universal numeric organisation-size or maturity threshold at which the standardization/customization balance should shift, so any organisation applying this item's findings must instrument its own leading indicators rather than rely on a benchmark figure. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]
  • The continuity-failure cost of locally-owned tooling is established qualitatively but not quantified in monetary or time terms in any cited primary source; the closest available proxy (Faros AI telemetry) measures aggregate fragmentation cost rather than an isolated continuity event. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]
  • The two-axis resolution of the banking/healthcare tension (§2.1a to 1c) is this item's own synthesis rather than a claim directly stated by any single cited source; it should be treated as a medium-confidence inference pending direct empirical testing in a mixed-sector study.

Open questions:

  • Does the golden-path-plus-Trusted-Committer pattern measurably reduce ungoverned shadow-AI-agent proliferation in a controlled or quasi-experimental setting, as opposed to the general software-engineering evidence this item extrapolates from?
  • What quantitative cost does a documented continuity-failure event (loss of a sole tool owner) impose in monetary or delivery-time terms, across at least one regulated and one less-regulated sector?
  • Does the two-axis (governance-infrastructure versus task-execution) framework this item proposes hold when tested against a third regulated domain outside banking and healthcare, such as aviation or nuclear-adjacent operations?

§7 Recursive Review

review_result: pass
acronym_audit: passed (AI, DORA, PR, IT, CNCF, SDLC, CI/CD all expanded at first prose use)
claim_label_audit: passed (every factual/inferential sentence in sections 2 through 6 carries a fact, inference, or assumption label)
source_binding_audit: passed (every Key Finding and Evidence Map row carries a URL-backed source)
synthesis_findings_parity: maintained (Findings section mirrors section 6 verbatim below)

Findings

(Populated from §6 Synthesis above.)

Executive Summary

The standardization/customization balance should shift along two independent axes rather than one: governance-infrastructure standardization (identity, audit trail, review tiering, telemetry) should rise with regulatory exposure and operational criticality regardless of organisation size, while task-execution standardization should rise with demonstrated platform maturity and organisation scale, converging on a golden-path-plus-governed-extension-points design as organisations grow. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf] Artificial Intelligence (AI) agent adoption does not independently push the balance toward more or less standardization on productivity and innovation outcomes; it amplifies whatever governance and platform maturity already exists, per the DORA (DevOps Research and Assessment) 2025 report's amplifier finding, while independently raising the minimum required standardization of the AI-specific control plane because agentic, tool-calling failure modes are harder to detect and contain than earlier non-agentic local tooling. [fact; source: https://dora.dev/research/2025/dora-report/] [inference; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html] Regulated, high-criticality domains such as banking do not uniformly favour more standardization than less-regulated domains; the healthcare literature shows the opposite pressure applies to standardization of frontline task execution even in a comparably regulated sector, which resolves once governance-infrastructure standardization is separated from task-execution standardization. [inference; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html] No cited source establishes a universal numeric threshold for organisation size or maturity at which the balance should shift, so the practical guidance is to track leading indicators of fragmentation cost and platform adoption voluntariness rather than apply a fixed rule. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]

Key Findings

  1. The standardization-customization trade-off operates on two separable axes, governance-infrastructure standardization and task-execution standardization, and conflating them produces apparent contradictions between sector-specific evidence that are resolved once the axes are separated. ([inference]; medium confidence; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html)
  2. Regulatory exposure and operational criticality push governance-infrastructure standardization upward regardless of sector, with bank model-risk guidance requiring review intensity proportional to size, complexity, and risk profile, and shadow-IT literature independently stating that strict prohibition may be reasonable for critical or highly regulated processes. ([inference]; medium confidence; source: https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html)
  3. Organisation size and maturity shift the crossover point at which local customization's aggregate cost exceeds its benefit through three compounding multipliers, team scale, shared-dependency density, and staff turnover, rather than through a fixed headcount or tool-count threshold. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html)
  4. Platform maturity, measured by the Cloud Native Computing Foundation (CNCF) Platform Engineering Maturity Model, changes the mechanism by which standardization is achieved, from mandate-driven adoption at low maturity to voluntary adoption at Level 3 and specialist-extension at Level 4, which converts a coercive trade-off into a preference-aligned one as maturity rises. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html)
  5. The DORA 2025 report, surveying nearly 5,000 technology professionals, found that Artificial Intelligence (AI) amplifies existing organisational conditions rather than independently improving productivity, so AI adoption magnifies whatever standardization/customization balance and infrastructure maturity already exist rather than dictating a new balance. ([fact]; medium confidence; source: https://dora.dev/research/2025/dora-report/)
  6. Faros AI telemetry across 22,000 developers found individual task completion rising 33.7% under AI-assisted delivery while pull request (PR) review time rose 441% and production incidents per PR rose 242.7%, a pattern consistent with local AI-driven productivity gains flooding shared review infrastructure that was not scaled commensurately, though AI-generated code quality degradation is a competing explanation for the same data. ([inference]; medium confidence; source: https://www.faros.ai/blog/key-takeaways-from-the-dora-report-2025)
  7. Agentic, tool-calling shadow Artificial Intelligence (AI) raises the minimum required standardization of the AI-specific control plane, identity, telemetry, and pre-action approval, above what sufficed for earlier non-agentic local tooling, because discovery alone cannot reconstruct the prompt content, reasoning chain, or delegated tool actions that make agentic failures dangerous. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html)
  8. The golden path pattern, an opinionated supported default with permitted deviation, combined with the InnerSource Trusted Committer pattern that distributes commit rights to contributing-team members, is the most consistently evidenced design for preserving local agility while reducing ungoverned fragmentation, and it generalises to shared AI agent skill libraries. ([inference]; medium confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://engineering.atspotify.com/2020/08/how-we-use-golden-paths-to-solve-fragmentation-in-our-software-ecosystem)
  9. Bartlett and Ghoshal's 1988 transnational framework, combining a standardized core, local adaptation, and bidirectional knowledge flow, predates AI agent tooling and Cloud-native platform engineering by decades yet best explains the current golden-path-plus-InnerSource pattern, indicating the standardization-customization tension is a structural property of multi-unit organisations rather than a technology-specific problem. ([inference]; medium confidence; source: https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/; https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html)
  10. Two independent systematic literature reviews of shadow Information Technology (IT) converge on the same five employee-experience benefit categories (productivity, innovation, agility, satisfaction, collaboration) and five risk categories (security, integration, synergy loss, control loss, continuity lack), but neither quantifies the continuity-failure cost in monetary or time terms, leaving the employee-experience-versus-risk trade-off qualitatively established but not numerically measured. ([fact]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf)
  11. Sanctioned AI tool rollout does not reliably displace unofficial AI tool choice, normalising AI use as work infrastructure while employees continue selecting faster or better-fitting shadow tools, which means standardization policy for AI agents cannot rely on rollout communication alone and must instead make the sanctioned lane lower-friction than the alternative. ([inference]; high confidence; source: https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html)

Evidence Map

Claim Source Confidence Notes
[inference] Trade-off operates on two separable axes (governance-infrastructure vs. task-execution standardization) https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html medium This item's cross-source synthesis; resolves apparent banking/healthcare contradiction
[inference] Regulatory exposure pushes governance-infrastructure standardization upward https://www.federalreserve.gov/boarddocs/srletters/2011/sr1107a1.pdf; https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html medium Cross-source generalisation; each source individually supports only the regulated-sector case it addresses, not a sector-independent claim
[inference] Size/maturity shift crossover point via three multipliers https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html medium No universal numeric threshold established in the underlying literature
[inference] CNCF maturity model changes standardization mechanism (mandate to voluntary) https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://tag-app-delivery.cncf.io/whitepapers/platform-eng-maturity-model/ medium Companion item primary finding
[fact] DORA 2025: AI amplifies existing organisational conditions https://dora.dev/research/2025/dora-report/ medium Survey of nearly 5,000 technology professionals
[inference] Faros telemetry pattern consistent with local-gain flooding shared review queues https://www.faros.ai/blog/key-takeaways-from-the-dora-report-2025 medium Competing explanation (code-quality degradation) not ruled out
[inference] Agentic shadow AI raises minimum control-plane standardization https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html medium Discovery alone insufficient for agentic tool-calling risk
[inference] Golden path + Trusted Committer generalises to AI agent skill libraries https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html; https://engineering.atspotify.com/2020/08/how-we-use-golden-paths-to-solve-fragmentation-in-our-software-ecosystem medium Transfer of software pattern to AI tooling is this item's inference
[inference] Bartlett and Ghoshal's transnational model generalises the pattern across sectors and eras https://cmr.berkeley.edu/1988/11/31-1-organizing-for-worldwide-effectiveness-the-transnational-solution/; https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html medium 1988 framework applied to 2026-era AI tooling context
[fact] Shadow IT benefit/risk taxonomy converges across two independent reviews https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html; https://www.sciencesphere.org/ijispm/archive/ijispm-070102.pdf high Continuity-failure cost not quantified in either review
[inference] Sanctioned rollout does not displace unofficial AI tool choice https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html high Corroborated across Microsoft, IBM, and Cyberhaven sources in the companion item

Assumptions

  • Assumption: The "stay busy" cultural amplifier identified for the general local-optima failure mode in software delivery also explains persistent local AI tool choice after sanctioned rollout. Justification: Both mechanisms describe local actors preferring perceived individual speed or fit over shared-system outcomes, but no cited source directly tests this specific behavioural transfer from software delivery to AI tool adoption. [assumption; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-global-optima-knowledge-work-throughput.html; https://davidamitchell.github.io/Research/research/2026-05-08-shadow-ai-behavioral-drivers-governance-effectiveness.html]
  • Assumption: The golden-path-plus-Trusted-Committer pattern, evidenced primarily in software engineering contexts, transfers to shared AI agent skill libraries with comparable effectiveness. Justification: The underlying mechanism (reduce the incentive to build locally by making the shared option easier to find and use) is domain-general, but no cited source directly measures this pattern's effectiveness specifically for AI agent tooling. [assumption; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]

Analysis

The most direct tension in the evidence set is between the banking companion item, which argues for more centralised governance as agent volume rises, and the Sinsky et al. healthcare source, which argues current standardization already exceeds the optimal level in a comparably regulated domain. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html; https://www.annfammed.org/content/19/2/171] This tension is resolved by separating governance-infrastructure standardization from task-execution standardization: banking sources target audit trail, identity, and review-tiering infrastructure, while the healthcare critique targets standardization of the clinical workflow itself. [inference; source: https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html; https://www.annfammed.org/content/19/2/171] A rival explanation for the apparent contradiction, that the two domains simply warrant different standardization levels because healthcare is less standardization-tolerant than banking as a domain trait, is weaker than the two-axis explanation, because the shadow-IT literature's regulated-sector carve-out applies the same qualitative shift (toward stricter control) across sectors once criticality is held constant, which is inconsistent with a domain-trait explanation that would predict healthcare should also favour centralisation given its comparable regulatory intensity. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]

A second competing interpretation worth engaging is that AI agent adoption itself, rather than existing platform maturity, is the primary driver of instability documented in the Faros AI telemetry and the DORA 2025 report. The DORA 2025 report's own framing, that AI amplifies existing organisational conditions rather than creating a new failure mode, weighs against this rival explanation, because the same report finds that mature-platform organisations convert AI gains into system-level improvement rather than instability, which would not be expected if AI adoption itself were the primary destabilising factor independent of existing maturity. [inference; source: https://dora.dev/research/2025/dora-report/]

The evidence is asymmetric in strength across the four Approach areas: the maturity and platform-engineering evidence (Approach 2 and 4) rests on well-corroborated, multiply-cited patterns (golden path, Trusted Committer, CNCF maturity levels) with fact-labelled primary confirmation in at least one companion item, while the size-threshold evidence (Approach 2a) explicitly lacks any peer-reviewed numeric threshold and should be treated as directional rather than predictive. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]

Risks, Gaps, and Uncertainties

  • No cited source directly measures the transfer of the golden-path-plus-Trusted-Committer pattern from general software engineering to AI agent skill libraries specifically; this item's Key Finding 8 and the Assumptions section flag this as an inference requiring dedicated validation. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-platform-engineering-innersource-hybrid-standardization.html]
  • No peer-reviewed source establishes a universal numeric organisation-size or maturity threshold at which the standardization/customization balance should shift, so any organisation applying this item's findings must instrument its own leading indicators rather than rely on a benchmark figure. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-local-tooling-fragmentation-threshold-measurement.html]
  • The continuity-failure cost of locally-owned tooling is established qualitatively but not quantified in monetary or time terms in any cited primary source; the closest available proxy (Faros AI telemetry) measures aggregate fragmentation cost rather than an isolated continuity event. [inference; source: https://davidamitchell.github.io/Research/research/2026-06-13-shadow-it-custom-tooling-governance-transition.html]
  • The two-axis resolution of the banking/healthcare tension is this item's own synthesis rather than a claim directly stated by any single cited source; it should be treated as a medium-confidence inference pending direct empirical testing in a mixed-sector study. [assumption; source: https://www.annfammed.org/content/19/2/171; https://davidamitchell.github.io/Research/research/2026-05-20-banking-agent-sprawl-governance-and-resilience.html]

Open Questions

  • Does the golden-path-plus-Trusted-Committer pattern measurably reduce ungoverned shadow-AI-agent proliferation in a controlled or quasi-experimental setting, as opposed to the general software-engineering evidence this item extrapolates from?
  • What quantitative cost does a documented continuity-failure event (loss of a sole tool owner) impose in monetary or delivery-time terms, across at least one regulated and one less-regulated sector?
  • Does the two-axis (governance-infrastructure versus task-execution) framework this item proposes hold when tested against a third regulated domain outside banking and healthcare, such as aviation or nuclear-adjacent operations?

Output

(Fill in when completing: what was produced as a result of this research?)

Navigation

Home

By Tag

bureaucracy

change-management

coase

constraint-analysis

control-model

decision-rights

delegation

delivery-risk

demand-segmentation

enterprise

exception-handling

execution

flow

flow-design

flow-metrics

governance

governance-patterns

incentives

instability

institutional-economics

leading-indicators

operating-model

organisation

organisational-design

queue-design

queueing

regulated-enterprise

routing

throughput

throughput-risk

transaction-costs

triage

williamson

Clone this wiki locally