Specifying AI-SDLC Processes: A Protocol Language for Human-Agent Boundaries

📅 Unknown Date
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the absence of a formal specification language that clearly delineates responsibility boundaries, approval checkpoints, and governance constraints between humans and AI agents throughout the software development lifecycle (SDLC). To this end, we propose a domain-specific protocol language tailored for AI-augmented SDLCs, which decouples policy intent from mechanistic implementation through a formal grammar, well-formedness conditions, operational semantics, and execution invariants to mitigate collaborative uncertainty. Our approach innovatively formalizes the principle of separation of duties as a 2+N team model and natively integrates Kleene closure with protocol self-consistency verification. Theoretical analysis demonstrates that structured execution reduces system failure rates to the weighted product of agent and verifier failure probabilities. A prototype implementation confirms the feasibility and effectiveness of the proposed method.
📝 Abstract
AI agents now participate as first-class team members across the software development lifecycle, yet no specification language exists for expressing the human-agent responsibility boundaries, approval gates, and governance constraints this collaboration requires. Existing approaches encode process in agent prompts (subject to drift), target adjacent domains (workflow management, business processes), or address only fragments (access control, approval gates). We propose a domain-specific language for specifying AI-SDLC processes as protocols, with formal syntax, well-formedness conditions, operational semantics, and enforcement invariants. The language distinguishes policy (declared intent) from mechanism (structural enforcement), enabling implementations to bound process non-determinism through primitives such as validation tokens and capability boundaries. Three results follow. A failure rate analysis shows that structural enforcement bounds system failure rates at a weighted product of agent and validator rates, while behavioral compliance permits cumulative or near-saturating growth. The 2+N team pattern (two human-in-control roles plus N specialized agent members) formalizes classical Separation of Duties for AI-SDLC. Kleene closure of orchestration loops and reflexive protocol-adherence validation emerge as design properties rather than special-case constructs. We position the contribution against multi-agent frameworks (MetaGPT), workflow specification (FlowAgent, BPMN extensions), and capability-based security (SAGA): the novelty lies in the specific integration, not any single primitive. A working implementation demonstrates feasibility; empirical evaluation is future work.
Problem

Research questions and friction points this paper is trying to address.

AI-SDLC
human-agent boundaries
specification language
governance constraints
responsibility boundaries
Innovation

Methods, ideas, or system contributions that make the work stand out.

AI-SDLC
protocol language
human-agent boundaries
structural enforcement
capability boundaries
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Y
Ylli Prifti
Birkbeck, University of London