Insights

The Bottleneck Isn’t Code. It’s Everything Around It.
September 29, 2026
Reading Time: 5 minutes

By Rujuta Waknis, Vice President, Digital Solutions and Munish Satia, Enterprise Architect, REI Systems

Federal agencies have invested heavily in modernizing how software gets built. They have adopted Agile delivery, established DevSecOps pipelines, moved workloads to the cloud, and some have even equipped developers with AI coding assistants that can complete in minutes what once took days.

Yet mission capabilities still take too long to reach users. Delivery schedules slip. Security and compliance reviews create late-stage disruption. Programs still spend significant time assembling documentation and evidence for audits and authorization decisions.

The problem is no longer primarily the speed of writing code. The larger constraint is coordination: the manual handoffs, disconnected tools, documentation requirements, security controls, governance reviews, and approvals that determine whether software can safely reach production.

AI-assisted development can accelerate code creation, but it does not automatically accelerate everything required to move that code into production. When development speeds up without corresponding improvements in testing, documentation, security review, and approvals, the downstream burden and modernization risks can grow.

This is more than a process problem. Poor coordination delays mission capabilities, consumes program capacity, extends security exposure, and slows an agency’s ability to respond to changing needs.

Why More AI Tools Do Not Solve the Problem

Many technology programs have adopted AI where it is most visible.

Developers use coding assistants. Documentation teams use generative AI. Security teams deploy AI-enabled scanning tools. Each will provide value within its own function.

But in many programs, these tools still operate independently. They may connect technically without sharing the context, policies, traceability, and approval logic required to coordinate delivery across the lifecycle. Value remains limited when:

  • Requirements are treated as a one-time handoff instead of a living thread that connects user needs, acceptance criteria, design decisions, test cases, and approvals.
  • Architecture decisions are captured in static documents, then drift from the code, configurations, interfaces, and operational constraints that teams implement.
  • Governance artifacts are assembled after the fact, requiring teams to reconstruct evidence, rationales, and control mappings instead of producing them continuously as work progresses.
  • Security and compliance reviews occur as point-in-time gates, surfacing issues late when fixes are more expensive, schedules are tighter, and release decisions carry greater risk.

AI accelerates individual tasks while leaving the larger coordination problem largely unchanged.

That is the challenge REI FORGE was designed to address. REI FORGE, or Factory for Orchestrated Rapid Guided Engineering, connects AI capabilities, development tools, policies, evidence, and human approvals across the software delivery lifecycle. Rather than adding another AI tool to the stack, FORGE helps the tools, people, and controls already involved in delivery operate as a coordinated system.

That coordination is especially important for governance. When AI tools operate independently, program leaders can lose visibility into where AI is being used, what it is producing, how outputs are validated, and which decisions require human review.

The risk extends beyond process. Programs need to know where AI work executes and what leaves the authorization boundary. Many AI development tools route source code and working state to vendor-operated services by default. In an authorized system, that is not simply a tooling choice; it can change the authorization boundary.

The Necessary Shift: From Assistance to Orchestration

The programs that advance furthest will not necessarily be those with the most AI tools. They will be those that can orchestrate AI, existing technologies, governance requirements, and human decisions across the delivery lifecycle. The successful ones will be programs that can rapidly produce trusted, reviewable, compliant, and mission-ready outcomes inside the constraints federal agencies actually operate under.

Orchestration means connecting specialized AI capabilities, delivery tools, policies, evidence requirements, and approvals through a governed workflow. Requirements, architecture, design, code, tests, security findings, compliance evidence, and decisions remain connected as work moves forward. Automation handles repeatable coordination and authorized people retain control over consequential actions. Approval gates are established at each step so human reviewers remain in the loop for validating AI-generated outputs, confirming evidence, and authorizing consequential decisions.

For example, an approved requirement change could automatically trigger updates to related artifacts, change user screens, generate revised test cases, identify affected controls, route evidence to reviewers, and preserve an auditable record of what AI produced and what a person approved.

The team no longer manages every handoff step manually. Repeatable workflows, controls, and evidence requirements are built into the delivery system.

Documentation can become a continuous by-product of delivery. Compliance evidence can remain current. Security findings can be mapped to controls and routed into remediation workflows. Changes can be traced from requirement through deployment.

The same pattern applies to modernization, where the constraint is understanding rather than construction. Legacy discovery – reading the code, reconstructing data flows, recovering business rules no one documented – regularly consumes months of senior engineering time and produces documents that go stale before the first sprint ends. AI can accelerate that analysis substantially, provided its output is treated as a proposal to be reviewed and signed rather than a finding to be trusted.

The mission value is significant: agencies can deploy capabilities faster, identify risk earlier, reduce rework, improve audit readiness, and shift scarce technical and program staff time from coordination overhead to service improvement. This is a change in what skilled staff spend time on, not a reduction in the need for them.  Quality and compliance roles move from transcribing requirements and rebuilding traceability matrices to reviewing what was designed and adjudicating what the evidence shows.

The Multiplication Effect

Orchestration does more than speed up delivery. It allows more people to contribute directly to the work while keeping the same controls in place.

A business analyst can make a simple interface change. A compliance analyst can assemble supporting evidence. A program manager can get an answer based on the current system rather than outdated documentation. They are not becoming developers; they are able to handle more work directly.

This is a change in what controls access. In most programs today, scarcity is the control: only developers can change a screen, so everyone else waits. Orchestration allows review to be the control instead, and review is the model agencies already use for delegated work. Changes still pass through the same approval gates, traceability requirements, and accountable experts before they take effect.

That expands capacity beyond the development team. Instead of using AI only to help developers work faster, governed orchestration enables more roles to contribute safely, adding capacity away from the code bottleneck.

What Federal Leaders Should Look For

Federal programs operate within agency SDLC policies and lifecycle governance (e.g., HHS EPLC), NIST Risk Management Framework and SP 800-53 security controls, Authority to Operate (ATO) requirements, acquisition constraints, and public accountability.  These considerations must be built into the workflow from the start. Federal leaders should look for four characteristics:

Governance by Design

Policies, controls, approvals, and evidence requirements should be embedded directly into delivery workflows. The system should know when work can proceed automatically and when an authorized person must intervene.

End-to-End Traceability

Requirements, code changes, tests, security findings, approvals, and evidence should remain connected. Programs must be able to explain what changed, why it changed, which controls applied, and who approved the result.

Toolchain Interoperability

Orchestration should connect tools agencies already use rather than force them to rebuild approved environments, and it should execute within those environments rather than routing work to vendor-operated services. Agencies should be able to replace individual tools without disrupting the broader workflow.

Meaningful Human Control

Human oversight must remain non-negotiable. Configurable approval gates should allow reviewers to inspect evidence, understand AI-generated recommendations, intervene while work is in progress, and override them when necessary. Automated tools should contribute evidence a reviewer reads, not a verdict the pipeline acts on. These controls are not a concession to bureaucracy. They are what make automation trustworthy.

From Faster Code to Faster Mission Impact

Federal agencies do not need another way to generate code faster. They need a better way to move from idea to production.

That means connecting requirements, development, testing, security, compliance, evidence, and approvals into one governed flow.

REI FORGE was built to make that possible. It orchestrates AI and existing delivery tools across the software lifecycle while preserving traceability, governance, and human control.

The opportunity is bigger than developer productivity. It is to remove the friction around software delivery itself. When that happens, AI stops being just a faster way to build software and becomes a faster way to deliver mission impact.

To learn how REI FORGE could apply to your program, contact REI Systems to schedule a conversation.