The Software Efficiency Report · From the Founder's Desk
The Software Efficiency Report | 2026 Week 21
Why More Engineering Activity No Longer Means More Delivery – And What Elite Teams Do Instead
A Note on This Issue
Engineering organisations have never been busier. More pull requests, more deployments, more AI-generated code, more automation. And yet, meaningful delivery outcomes are not scaling at the same pace.
That gap – between activity and effectiveness – is the lens through which I’ve reshaped this newsletter.
Starting this week, every issue is built for platform engineers, DevOps teams, SREs, cloud architects, and engineering leaders who care about operational outcomes. Less noise, more signal. Each issue of the newsletter takes more than half a day for me to prepare this, however, I am enjoying this learning and it is worth spending.
New additions this week:
- Software Efficiency Metric of the Week – with context, not just a number
- Reader poll – my take first, then yours
- Expanded platform engineering and DevSecOps coverage
- Curated tools and ecosystem updates with editorial commentary
Would love your feedback on the new format.
- Deep dive
- Why More Engineering Activity No Longer Means More Delivery – And What Elite Teams Do Instead
Software Efficiency Metric of the Week
18%
Microservice-based automotive embedded platforms improved startup time by up to 18% during software-defined vehicle architecture testing. Source
Why it matters for platform teams: Startup latency in embedded systems is the equivalent of cold-start problems in cloud-native services – and the same microservice decomposition principles are driving gains in both worlds. If your team is wrestling with slow environment spin-up or heavy monolith boot times, the architectural patterns coming out of the automotive SDV space are worth watching closely.
Reader Poll
Would You Allow AI Agents to Execute Production Remediation Without Human Approval?
My take: Not yet – and not because the technology isn’t ready. Most organisations haven’t defined clear blast-radius boundaries, rollback guarantees, or observability hooks required to trust autonomous remediation. Until those guardrails exist in your system, autonomous production actions are a confidence problem, not just a tooling problem.
What’s your stance? Vote in the comments:
- A) Yes, fully autonomous
- B) Only low-risk actions
- C) Human approval required
- D) Not in production, ever
Technology Ecosystem Digest
Ten trends shaping how engineering organizations operate and what each means in practice.
1. Platform Engineering & IDPs Companies are replacing fragmented DevOps toolchains with self-service internal developer platforms. The measurable result: environment setup times dropping from days to minutes, and up to 40% fewer inbound infrastructure tickets.
2. Agentic AI Infrastructure AI agents are beginning to manage cloud resources, trigger modernisation workflows, and self-optimise infrastructure costs. AWS Transform hitting 4.5 billion lines of processed code in one year signals this is no longer experimental.
3. Adaptive Security-as-Code Security policies are moving from spreadsheets into version-controlled, executable code integrated directly into deployment pipelines. Static point-in-time checks are becoming a liability.
4. AI Code Safety Nets As AI-generated code volume grows, teams are adding CI/CD gates specifically designed to catch security issues that AI assistants introduce. This is no longer optional for teams running Copilot or Claude at scale.
5. Predictive AIOps & Observability AI-powered observability platforms can now predict failure patterns and trigger pre-emptive fixes. The shift from reactive alerting to predictive intervention is the single biggest reliability improvement available to most SRE teams right now.
6. Pre-Deployment FinOps Cloud cost validation is moving left – into Infrastructure as Code workflows – before resources are provisioned. Catching cost anomalies post-deployment is expensive; catching them pre-deployment is just discipline.
7. Ephemeral Testing Environments Short-lived, on-demand test environments are replacing expensive persistent staging systems. The payoff is both cost and cognitive load reduction.
8. Software Supply Chain Integrity SBOMs, image signing, and supply chain verification are becoming standard practice following a string of high-profile supply chain incidents. If your organisation hasn’t done a supply chain audit in the past six months, the CISA credential leak this week is a timely reminder.
9. Edge IoT & Embedded DevOps Cloud-native DevOps practices are expanding into IoT and edge AI hardware. The gap between cloud and embedded delivery workflows is closing faster than most enterprise architecture teams expect.
10. Forward-Deployed Engineering Embedded teams that build production systems directly alongside customers are outperforming centralised delivery models. The “throw it over the wall” era of consulting is ending.
Cloud and Platform Updates
- AWS Broadens Developer & Core Compute Reach: Amazon launched its new EC2 M3 Ultra Mac instances, giving Apple developers a massive upgrade with double the unified memory and neural engine cores to spin up parallel Xcode simulators. Alongside this, new Graviton-powered Amazon Redshift RG instances hit the market, promising data lake and warehouse processing up to 2.4x faster than previous generations. Source
- Multi-Cloud Networking Expansion: Cloud interoperability made progress this week with the preview launch of AWS Interconnect’s multicloud connectivity for Oracle Cloud Infrastructure (OCI). The service, already generally available for Google Cloud, uses an open specification to let engineering teams spin up scalable, private connections across different clouds without hitting vendor silos. Source
- HPE GreenLake Unveils Unified Control Plane: To help combat the sprawl of hybrid deployments, HPE introduced major updates to GreenLake. The rollout includes a unified private cloud management architecture featuring Kubernetes support natively running on HPE ProLiant Compute Gen 12, paired with high-performance file and object storage via the HPE Alletra Storage MP X10000. Source
- Microsoft Launches Cloud-Native Linux OS Upgrades: At the Open Source Summit, Microsoft announced the public preview of Azure Linux 4.0 for standard Virtual Machines and the general availability of Azure Container Linux. Built as an immutable, container-optimized system based on the Flatcar project, it’s stripped down to keep the attack surface tiny for cloud-native applications. Source
- Gemini 3.5 Family Rollout: Google launched the Gemini 3.5 model family, introducing Gemini 3.5 Flash and Gemini Omni Flash to developers. Engineered via purpose-built AI infrastructure, the models operate four times faster than previous systems and are optimized specifically for deep logic reasoning and heavy coding automation. Source
Open-Source Ecosystem and Linux Updates
- Linux Kernel Developers Debate a Hard “Kill Switch”: Prompted by a recent spike in sophisticated privilege-escalation vulnerabilities, upstream Linux kernel maintainers have actively begun discussing the introduction of an internal safety kill switch. The mechanism would allow system administrators to temporarily isolate or shut down vulnerable sub-components at runtime to limit exposure. Source
- Fedora Deploys “Hummingbird” for Container Environments: The Fedora Project announced Fedora Hummingbird, a container-centric host OS designed specifically for agentic and containerized workloads. It mirrors security and isolation policies identically between the host OS level and individual running containers, drastically simplifying policy enforcement for platform engineering teams. Source
- Microcks Moves to CNCF Incubating Status: The Cloud Native Computing Foundation Technical Oversight Committee officially voted to accept Microcks as an incubating project. As enterprise engineering teams shift deeper into decoupled microservices, Microcks is gaining rapid adoption as an open-source hub for mocking and testing APIs across REST, GraphQL, and asynchronous events. Source
- Global Open Source Communities Gather in Minneapolis: The Linux Foundation kicked off its highly anticipated co-located Open Source Summit and Embedded Linux Conference (ELC) North America. The key technical sessions are zeroing in on open-source supply chain mechanics, real-time performance optimizations, and the intersection of open standards within safety-critical industrial software systems.Source
DevOps, Platform Engineering and SRE
- AWS Transform Hits One-Year Milestone: Celebrating a year in production, AWS announced that its automated modernization service, AWS Transform, has now processed over 4.5 billion lines of code. The service has integrated its automated refactoring and language upgrade agents directly into popular developer interfaces like Cursor, Claude, and GitHub’s Kiro ecosystem.Source
- SRE and Performance Engineering Shifts in India: Modern enterprise demands have driven a major shift among Indian DevOps consulting firms, moving them past basic CI/CD automation. Market tracking shows a surge in dedicated SRE and performance engineering practices focused heavily on cloud optimization, real-time Kubernetes lifecycle monitoring, and latency reduction under peak traffic. Source
- Self-Healing Agentic CI/CD Workflows: Emerging as a major trend in platform architecture, teams are moving from static pipelines to self-healing CI/CD systems. Azure detailed infrastructure patterns demonstrating how automated data agents can intercept deployment failures and trigger localized rollbacks or fixes. Source
- Enterprise Internal Developer Platform (IDP) Adoption Booms: New industry data tracks the massive migration toward Internal Developer Platforms to reduce developer cognitive load. As engineering toolchains become more fragmented, companies are using structured IDPs to cut environment setup times from days down to a few clicks, stripping out up to 40% of standard inbound infrastructure tickets. Source
Security and DevSecOps Updates
- CISA Credential Leak via Public GitHub Repo: Security researchers at GitGuardian exposed a major operational oversight where a federal contractor accidentally left a repository named “Private-CISA” open to the public. The repository leaked administrative AWS GovCloud credentials, plaintext system passwords, and direct access tokens to internal DevSecOps environments like “LZ-DSO,” stressing the vital need for automated secrets-scanning in delivery pipelines. Source
- “Copy Fail” Kernel Exploit Shakes Cloud Environments: A critical privilege-escalation vulnerability (CVE-2026-31431), dubbed “Copy Fail,” has sent waves through major enterprise Linux vendors including Red Hat, Canonical, and SUSE. By taking advantage of how the kernel’s cryptographic subsystem interacts with system memory calls, a tiny 732-byte script can alter the page cache of privileged binaries, allowing unprivileged containers to break out and gain host root access. Source
- The Shift to Adaptive Runtime Security as Code: DevSecOps frameworks have fundamentally shifted away from static, point-in-time checks. Teams are discarding old manual compliance spreadsheets for version-controlled, executable security code that integrates directly into application logic. This trend relies on real-time application behavior tracing to catch anomalies that static analysis completely misses before production. Source
- Microsoft Anchors Open-Source Security Initiatives: Microsoft announced a secondary round of core funding directed at the Open Source Security Foundation (OpenSSF) and the Alpha-Omega project. The financial push is intended to deploy automated, AI-driven security testing pipelines across thousands of foundational, open-source projects to spot vulnerabilities before they ever enter downstream enterprise software builds. [1]\
AI/ML, Agentic AI Updates
- Anthropic’s Native Claude Platform Launches on AWS: Amazon announced the general availability of the native Claude Platform directly within standard AWS accounts. Engineering teams can now tap into Anthropic’s full suite of APIs, console toolsets, and early beta features natively, removing the friction of split billing, siloed access tokens, and detached account security management. Source
- Red Hat Expands Open Hybrid AI Infrastructure: At Red Hat Summit, the enterprise software giant rolled out major updates to its AI Enterprise and Inference portfolios. Positioned as an open alternative to proprietary stacks, the updates focus on giving engineers a flexible, hybrid platform to deploy automated agentic workflows, orchestrate heavy GPU-dependent workloads, and maintain data sovereignty across multiple clouds. Source
- Open Agentic Communication Protocols in Development: Tech leaders at the Open Source Summit laid out plans for universal Agent-to-Agent (A2A) communication protocols. Alongside an Open Agentic Stack framework, these open interfaces are designed to allow autonomous AI agents built by different vendors or running on different clouds to safely talk, hand off tasks, and coordinate work securely. Source
- Enterprise Multi-Agent Systems Outgrow Early Pilots: Enterprise AI development patterns show a definitive shift away from isolated, single-use chatbots. Global integrators like IBM (via its open-source BeeAI project) and Cognizant are heavily scaling multi-agent architectures that hook into enterprise RAG pipelines, backed by strict governance tools to manage model identity and access permissions. Source
Embedded Systems and IoT Updates
- Safety-Critical Linux Tracing in Avionics and Auto: The ELISA Project outlined its active working group tracks for integrating Linux and the Zephyr real-time operating system (RTOS) inside hypervisor setups like Xen. The primary focus centers on establishing provable functional safety baselines so open-source stacks can be deployed safely inside heavy industrial, automotive, and avionics systems. Source
- Firmware Hurdles in AI Camera and Smart Sensor Security: Engineering reports highlighting the growth of connected IoT devices show that smart cameras and environmental sensors are running incredibly complex firmware stacks. Developers face massive challenges balancing real-time edge processing and encrypted video feeds with strict battery constraints, while keeping false alarms low enough to maintain product usability. Source
- Canonical’s Redhound AI for IoT Firmware Hunting: To secure embedded systems, Canonical detailed its deployment of Redhound, an AI-driven auditing engine used to scan and hunt deep logic flaws within complex open-source IoT distributions and Ubuntu Core kernel modules before production deployment.Source
Deep Dive: Why More Engineering Activity No Longer Means More Delivery – And What Elite Teams Do Instead
Your engineering organisation is probably the busiest it has ever been.
More pull requests. More commits. More deployments. More AI-generated code. More dashboards. More tooling. More ceremonies.
But if you look closely, many teams are not delivering proportionally more business value.
This is becoming one of the biggest software delivery problems in modern engineering. Activity is increasing faster than effectiveness. The gap between being busy and creating meaningful impact is widening – and most engineering leaders are still measuring the wrong things.
The Illusion of Productive Busyness
As engineering teams grow, organisations typically start measuring activity because it is easy to track. Commits, pull requests, deployments, story points, ticket closures. The data is everywhere. The dashboards look impressive.
The problem is not that these metrics are useless. The problem is that organisations mistake activity for progress.
A team can look highly productive on paper while delivery problems accumulate underneath.
Consider what high numbers can actually hide:
- High commit volume sometimes signals fragmented work, excessive context switching, or AI-generated code pushed without adequate review.
- High deployment counts can mask low business impact – forty trivial changes is not the same as three meaningful improvements customers care about.
- High PR throughput under reviewer overload means reviews are rushed and engineers stop understanding changes properly.
- High ticket closure rates can reflect work broken into tiny units to improve burndown charts, not meaningful capability delivery.
- Story point velocity measures estimated effort completed, not value created. Two teams can report identical velocity while delivering completely different business outcomes.
This is the activity trap. It is attractive because the numbers are easy to collect and easy to present upward. But activity is not effectiveness.
What High-Performing Organisations Measure Instead
The best engineering organisations ask a different question.
Not: “How much engineering activity did we produce?”
But: “How effectively does our engineering system turn effort into business outcomes?”
That shift changes how teams measure success, what leadership reviews, and where organisations invest.
Here is what elite teams actually focus on.
1. Value Stream Flow Over Departmental Throughput
The biggest delivery constraint in most engineering organisations is not coding speed. It is waiting.
Work waits for approvals, security reviews, environment provisioning, QA validation, deployment windows, and dependency sign-offs. Even strong engineering teams end up with long delivery cycles because the system around them creates delays.
This is why flow efficiency matters – the ratio of productive active time to total elapsed time.
In many organisations that believe they move fast, flow efficiency sits between 5% and 15%.
Reducing wait states consistently creates more impact than hiring more engineers.
2. Toil Ratio – The Hidden Engineering Tax
Every organisation carries operational overhead: manual deployment fixes, on-call interruptions, environment setup requests, flaky test maintenance, security patching, pipeline troubleshooting.
Individually these look small. Together they consume enormous engineering capacity.
High-performing organisations measure how much time goes into operational maintenance versus customer-facing innovation – and they act on it. Once operational work crosses a threshold, delivery slows even if headcount keeps growing. More infrastructure creates more operational load. More services create more coordination overhead.
Adding engineers at that point does not increase delivery speed. It spreads the operational burden across more people.
3. Complexity Per Release – The Slow-Motion Risk
Many organisations optimise for deployment frequency while forgetting to track complexity growth.
Every release adds new dependencies, configurations, operational risks, monitoring requirements, and failure scenarios. The fastest teams are not simply shipping the most code – they are shipping consistently while keeping operational complexity under control.
Mature engineering organisations monitor dependency growth, configuration sprawl, blast radius, operational overhead, and observability gaps as first-class delivery metrics. Fast delivery that creates long-term operational drag is not real efficiency.
4. Business Throughput Alongside Engineering Throughput
This is the most common missing piece.
Teams can measure deployments, lead time, pull requests, and incidents. But many organisations still cannot clearly answer:
- How much engineering effort directly improved customer experience?
- How much work influenced revenue, retention, or adoption?
- How much engineering capacity went into projects that created no measurable business value?
Without this connection, organisations optimise engineering activity without understanding business impact.
Leading companies are closing this gap by connecting engineering metrics with product analytics and business data – mapping investments to outcomes, defining success criteria before implementation, and building tighter feedback loops between engineering, product, and leadership.
The Practical Playbook
Stop treating activity metrics as outcome metrics. Commits, PRs, deployments, and ticket closures are operational signals. They should help teams understand delivery operations, not define organisational success.
Map engineering work to business outcomes before it starts. What customer problem are we solving? What business metric should improve? How will success be measured? Without this, teams finish projects without knowing whether the work mattered.
Measure wait time across the full delivery system. Most delivery problems are coordination problems, not coding problems. Map the process from idea to production and identify where work sits idle. That is usually where the biggest improvements live.
Track toil regularly. Engineering teams should openly measure time spent on maintenance, support, operational troubleshooting, and repetitive tasks. This creates visibility into delivery friction and justifies platform investment.
Measure complexity growth. Dependency expansion, service sprawl, operational ownership gaps, configuration growth, and cognitive load are real costs that compound silently until delivery slows.
Connect DORA metrics to business throughput. Deployment speed alone does not guarantee meaningful outcomes. Engineering effectiveness requires linking delivery performance to business value.
Why Organisations Struggle to Make This Shift
Activity metrics are easy to collect. Most engineering tools provide them automatically. Many organisations still evaluate teams on visible throughput because it is simple to communicate upward. Measuring business outcomes is harder – it requires coordination across engineering, product, analytics, and leadership that many organisations are not yet structured to provide.
And activity creates the appearance of momentum. Large dashboards filled with commits and ticket counts make organisations feel productive even when strategic progress is slowing.
Changing this requires leadership maturity and better measurement systems. Both are learnable.
Where to Start: Assessing Your Engineering Maturity
Most engineering leaders already feel these problems. The challenge is knowing where the biggest gaps actually exist.
This is why we built TuskerGauge – a free DevOps and DevSecOps maturity assessment platform from Stonetusker Systems.
TuskerGauge evaluates engineering maturity across integration, testing, infrastructure, deployment, observability, security, leadership, SRE, engineering culture, innovation, and system design.
The assessment delivers:
- Overall maturity score and percentage
- Radar chart across assessment categories
- Detailed category breakdowns with tailored recommendations
- Downloadable PDF report for leadership review and planning
The assessment works best when engineering, operations, security, product, and leadership teams all contribute honestly – because the gaps are rarely where leadership expects them.
Where to Start: Assessing Your Engineering Maturity
Most engineering leaders already feel these problems inside their organ isations.
The challenge is understanding where the biggest gaps actually exist.
This is one of the reasons we built TuskerGauge.
TuskerGauge is a free DevOps and DevSecOps maturity assessment platform from Stonetusker Systems.
A detailed walkthrough is also available here: How to Use TuskerGauge for DevOps Maturity Assessment
References :
Project to Product by Mik Kersten
Google Site Reliability Engineering Book
Accelerate by Nicole Forsgren, Jez Humble, and Gene Kim
CNCF Platform Engineering Whitepaper
Tools, Resources and Community – Worth knowing
Open-Source Tool
- Envoy Proxy: A high-performance edge and service proxy designed for cloud-native applications. It is invaluable for setting up the ingress routing layers required during complex strangler-pattern migrations. Source
Commercial Tool
- HashiCorp Consul Enterprise: A service mesh and service discovery platform that secures and automates network connections across hybrid environments. It simplifies traffic management when splitting workloads between bare-metal legacy servers and modern public cloud clusters. Source
Learning and Community
- DevOps Toolkit is a practical learning resource covering Kubernetes, GitOps, CI/CD, and platform engineering workflows. Source
- OpenSSF is an industry-wide initiative focused on improving software supply chain security and open-source safety. Source
- Awesome DevOps is a well-curated collection of DevOps tools, platforms, learning resources, and best practices covering Kubernetes, CI/CD, Platform Engineering, Observability, Security, GitOps, SRE, and cloud-native infrastructure. Source
