The Software Efficiency Report · From the Founder's Desk
The Software Efficiency Report | 2025 Week 52
Measuring Engineering Productivity Without Breaking Trust
Welcome to the Fifth edition of the Stonetusker Newsletter.
As the year winds down, many engineering leaders are taking stock of more than delivery milestones and roadmap completion. 2025 reinforced a hard-earned lesson. Sustainable velocity does not come from urgency or heroics, but from well-designed systems that make good work easier and risky work rarer.
Late December offers a rare pause. Release calendars thin out, incident volume drops, and there is space to reflect on how work actually flowed this year. Many organizations indeed schedule global maintenance windows, patch cycles, and infrastructure freezes during late December to minimize disruption and prepare for Q1 operations. The teams entering 2026 with confidence are those that invested in platform maturity, reduced cognitive load, and treated productivity as a system property rather than an individual metric.
This Christmas week edition focuses on exactly those themes. Platform signals that quietly shape delivery outcomes, productivity measures that strengthen trust instead of eroding it, and security practices that scale without exhausting teams. It is a look at what holds up when the pressure is on, and what is worth carrying forward into the new year.
- Deep dive
- Measuring Engineering Productivity Without Breaking Trust
Industry Signals This Week
Cloud and Platform Updates
For GCP news, refer: Google Cloud Blog – What’s New : Source
Alphabet (Google) Acquires Intersect for $4.75B Major deal to accelerate AI data center build-out (e.g., $40B investment in Texas through 2027), focusing on scalable, energy-efficient facilities-key for enterprises modernizing legacy setups for AI workloads and performance gains. Source
Latest AWS News:
AWS Launches ECS Express Mode for Simplified Deployments Amazon ECS Express Mode simplifies deploying containerized web apps and APIs by automating ancillary requirements like IAM roles, load balancers, and scaling in a single step. Source
AWS Introduces Regional NAT Gateway Availability AWS launched regional NAT Gateways for high availability across AZs in a VPC, simplifying network management without needing zonal subnets or manual routing. Source
Open-Source Ecosystem
Linux Foundation Newsletter: Agentic AI Foundation & Ecosystem Momentum
The December 2025 Linux Foundation Newsletter (published ~December 17) recaps key progress, including the Agentic AI Foundation formation (with contributions like MCP, goose, and AGENTS.md), collaborations (e.g., AgStack + OpenAgri), and upcoming 2026 events focused on open-source innovation:Source
OpenSSF Newsletter & 2025 Annual Report Released
The Open Source Security Foundation (OpenSSF) published its December 2025 Newsletter and 2025 Annual Report, highlighting achievements in education, tooling, vulnerability management, and global collaboration. It emphasizes practical security baselines (OSPSB) for maintainersSource
DevOps and SRE
Google Launches Agent Development Kit for TypeScript Google released an open-source Agent Development Kit (ADK) for TypeScript and JavaScript, enabling developers to build autonomous AI agents using familiar code-first workflows, simplifying integration into DevOps pipelines. Source
AWS Debuts DevOps Agent for Automated Incident Response AWS announced the public preview of AWS DevOps Agent, an autonomous “frontier agent” that acts as an always-on engineer, integrating with observability tools to accelerate incident triage and improve reliability. Source
Security
WatchGuard Firebox Critical RCE Vulnerability Actively Exploited CVE-2025-14733, an out-of-bounds write in Fireware OS, allows unauthenticated remote code execution and is under active attack; CISA added it to KEV catalog. Source
12 Months of Supply Chain Attacks in 2025 Summarized A month-by-month review of 2025’s supply-chain cyber incidents highlights escalating threats, urging stronger vendor monitoring and zero-trust approaches. Source
Critical n8n Workflow Automation Vulnerability CVE-2025-68613 (CVSS 9.9) enables arbitrary code execution on exposed instances patch to safeguard automation pipelines critical for modern DevOps/SRE workflows. Source
Weekly Cyber Recap: Firewall Exploits & More Highlights ongoing FortiGate attacks, React vulnerabilities, and new KEV additions. Source
AI/ML
When AI Acts Alone: Managing Risks in Autonomous AI A new report warns organizations of emerging risks as agentic AI agents handle critical operations, urging better governance for SRE and AIOps to ensure reliability in autonomous systems. Source
Agentic AI Empowering Autonomous SRE in Observability New research shows agentic AIOps platforms enabling self-healing Kubernetes workloads and proactive outage prevention, with enterprises reporting 3x faster MTTR and significant SRE cost savings. Source
Embedded Systems
Forlinx FCU3011 NVIDIA Jetson Orin Nano Industrial Computer Forlinx released the fanless FCU3011 edge AI system with Jetson Orin Nano (up to 67 TOPS), 4x GbE, and optional cellular connectivity for industrial applications. Source
Toradex Luna SL1680 SBC Launched Raspberry Pi-like board with Synaptics SL1680 Edge AI SoC (8 TOPS NPU), targeting pro-consumer and light industrial applications. Source
CrowPanel Advanced 7-inch ESP32-P4 HMI Review Begins Hands-on with the AI-capable touchscreen display running LVGL firmware for embedded prototyping. Source
Deep Dive Insight Article
Measuring Engineering Productivity Without Breaking Trust
Measuring engineering productivity in a way that builds trust is now a core leadership capability, not a reporting exercise. Executives who use metrics to guide capital allocation, manage risk, and retain talent tend to see compounding returns. Those who use them primarily for control often undermine the very performance they are trying to improve.
The difference is not the metrics themselves. It is how leaders frame them, discuss them, and act on them.
Why Productivity Measurement Matters More Now
Modern software organisations are capital intensive, platform heavy, and increasingly dependent on a relatively small pool of experienced engineers. In that context, productivity measurement has shifted from a nice-to-have into a board-level concern.
Several forces are converging:
- Boards and CEOs want clearer evidence that engineering spend translates into durable business outcomes, not just busy backlogs.
- High-performing organisations consistently ship changes faster and with greater stability, and the gap between them and the rest of the field continues to widen.
- Developer experience and psychological safety have emerged as leading indicators of retention and sustainable delivery, not soft cultural signals.
In this environment, the question is no longer whether to measure productivity, but how to do it without damaging trust, morale, or long-term delivery capacity.
From Individual Output to System Flow
The organisations that get this right treat engineering as a system, not a collection of individuals to be ranked.
Frameworks such as DORA provide a small but powerful set of signals: deployment frequency, lead time for changes, change failure rate, and time to restore service. Together, these metrics describe how effectively the organisation turns ideas into reliable customer impact.
The most important leadership shifts look like this:
- From “who is slow?” to “what makes work slow?” Long lead times usually point to friction in CI pipelines, approvals, dependencies, or architecture, not a lack of effort.
- From local optimisation to global flow. Measuring isolated team throughput often drives counterproductive behaviour. System-level flow reveals where platform investment or architectural change will have the greatest leverage.
- From speed alone to overall health. Many organisations now combine DORA with frameworks like SPACE to capture satisfaction, collaboration, and cognitive load, producing a more realistic picture of engineering health.
This system-oriented view allows executives to invest in removing constraints rather than pushing teams harder.
Using Metrics as Investment Signals, Not Surveillance
The same metrics can either unlock performance or quietly destroy trust. The difference lies in intent and behaviour.
Leaders who succeed tend to follow three consistent principles:
- Treat metrics like a portfolio dashboard. Use delivery and DevEx signals the way finance uses ratios, to decide where to invest in CI reliability, platform engineering, or incident response capability.
- Avoid individual scorecards. Ranking engineers or teams on raw activity metrics such as commits or tickets consistently reduces psychological safety and discourages early risk disclosure.
- Insist on narrative, not just numbers. A spike in lead time may reflect intentional work such as modernising a core service or onboarding a new team. Metrics without context lead to the wrong conclusions.
When used this way, metrics guide where to invest rather than who to blame.
An Executive Playbook: Metrics That Improve Flow
A trusted productivity measurement approach can be summarised in a short, executive-ready playbook:
- Start with outcomes, not activity. Measure flow, stability, and recovery as proxies for value delivery, not hours worked or tickets closed.
- Use a small, balanced set. DORA metrics, complemented by a small number of DevEx or SPACE indicators, are sufficient to start.
- Instrument systems, not people. Pull data automatically from Git, CI/CD, incident management, and observability platforms to reduce manual reporting and gaming.
- Review trends, not snapshots. Direction over quarters tells a far more accurate story than week-to-week variance.
- Pair metrics with structured dialogue. Discuss metrics within existing operating rhythms, always alongside input from teams closest to the work.
- Allocate investment based on signals. Use insights to fund automation, platform improvements, and technical debt reduction rather than asking teams to simply “go faster”.
This keeps measurement intentionally narrow while tying it directly to the levers executives actually control.
Tooling Snapshot: Where Executive-Grade Metrics Come From
Executives do not need more dashboards. They need a coherent view built from data the organisation already produces.
- Lead time and deployment frequency Sourced from Git and CI/CD tooling such as GitHub, GitLab, Bitbucket, Jenkins, GitHub Actions, and Argo CD.
- Change failure rate and time to restore service Derived from incident and release systems like PagerDuty, Opsgenie, ServiceNow, and progressive delivery tools.
- Flow efficiency and work in progress Visible through issue tracking systems such as Jira, Linear, Azure Boards, and GitHub Issues.
- Reliability and customer impact Informed by observability platforms using OpenTelemetry, Prometheus, Grafana, Datadog, or New Relic. It is also possible to integrate various SDLC tools with Python based APis pulling data to a time series or NoSQL DB, later this data can be processed and presented.
- Developer experience and well-being Captured through lightweight DevEx surveys and SPACE-aligned feedback mechanisms.
The governing principle is simple: measurement should reduce friction, not introduce a new reporting burden.
The Strategic Edge: Trust as an Asset
The strongest engineering organisations will be defined less by how much they demand from teams and more by how intelligently they measure and improve work.
The emerging pattern among top performers is consistent:
- They combine delivery, reliability, and DevEx signals into a single narrative about system health.
- They frame productivity as an outcome of platform quality, architecture, and culture, all areas leadership can shape.
- They treat trust as an asset. Metrics exist to surface constraints early, fund the right improvements, and protect the conditions under which skilled engineers do their best work.
Leaders who align measurement with learning, investment, and safety will see faster delivery, stronger retention, and more resilient systems. Those who continue to use metrics primarily for control will find it increasingly difficult to scale either performance or trust
Thought Leadership Corner
Over the next year, the most successful engineering organisations will differentiate themselves by how they measure and improve work, not how much work they demand. Leaders who treat productivity metrics as instruments for learning will unlock faster delivery, stronger retention, and better system reliability. Those who use metrics for control will struggle to scale trust and performance. ”What gets measured and monitored tends to improve.”
Tools, Resources and Community
Open source platform framework: Backstage provides a foundation for internal developer portals, centralising service ownership, templates, and documentation. It matters because it reduces cognitive load and enables consistent delivery paths across teams.Source Source
Open source tool OpenTelemetry continues to grow as a standard for collecting metrics, traces, and logs, providing foundational visibility into delivery and runtime performance.Source Source
Commercial tool LinearB offers engineering metrics and workflow insights that focus on team level flow rather than individual surveillance.Source
Commercial security platform Snyk focuses on developer friendly security across code, dependencies, containers, and infrastructure as code. As supply chain risk increases, this approach helps shift security left without slowing teams down.Source
Learning resource and community Platform Engineering Playbooks are emerging as practical guides for real world platform adoption, focusing on operating models rather than tools. In parallel, the CNCF Platform Engineering Working Group offers shared patterns, case studies, and lessons from organisations building platforms at scale.Source Source
Summary
- Sustainable engineering velocity comes from well-designed platforms and systems, not constant urgency or heroics.
- Cloud providers are embedding governance, automation, and policy-as-code deeper into managed platforms, reducing operational friction at scale.
- Agentic AI is moving from experimentation into DevOps and SRE workflows, with early gains in incident response and recovery, alongside new governance risks.
- Security pressure remains high, with active exploitation of infrastructure, automation, and supply chain components reinforcing the need for zero-trust assumptions.
- Leading organisations measure productivity at the system level, focusing on flow, stability, and recovery rather than individual output.
- Trusted metrics are used to guide investment in platforms, automation, and technical debt reduction, not to rank teams or individuals.
- Developer experience and psychological safety continue to prove essential for retention, resilience, and long-term delivery performance.
- Engineering leaders entering 2026 with confidence are those who treated trust, platform maturity, and measurement discipline as strategic assets.
Christmas Note
As this edition goes out on December 24, we wish you and your teams a calm and restful Christmas. Thank you for the work you do throughout the year to keep systems reliable, teams supported, and customers served. We hope the holidays bring space to recharge and reflect.
If your organisation is struggling with delivery predictability, productivity debates, or trust around metrics, it may be time to modernize how work is measured and enabled. Contact Stonetusker at contact@stonetusker.com to strengthen your engineering systems, platforms, and delivery pipelines.
