Fortify · Sonatype · Jira · GitLab feed an agentic Scrum team that triages, fixes, and ships under policy. Built on LangChain DeepAgents with Git-versioned playbooks. Every screen is governed by secops-policy@v3.2.
OrderRepositoryDay 8 of Sprint 7. Alice has one ticket waiting for her final approval. Every screen points toward — or follows from — this single decision. The story enters at #07 Intake, reaches its crux at #19 Approval modal, and closes with the success toast at #21. Bordered cards below mark the 13 screens where SEC-1745 appears directly.
Urgent action in #13 → pending T4 rule in #16 → validated against Sprint 6 in #17 → v3.3 promoted in #21.
Promote action in #13 → green-bordered candidate card in #14 → 100% success in #15 → shadow T1 pilot done in #17.
spring-sql-injection@2.3 (T1, 12 uses) · spring-csrf ready for T1 promo.