THE OPEN LEARNING LIBRARY

All lessons

Find the lesson that helps with your work. Filter by responsibility, level, or topic.

Search inside every lesson →

Lessons found: 50

Foundation11 min

Vibe coding: uses and limits

Help people explore ideas with AI. Use a banking prototype to understand why live data and API permissions need security evidence.

Understand AI development
Foundation8 min

Assistants, agents, and permissions

Distinguish an answer from an action. Identify the tools and permissions that change the consequences of a mistake.

Understand AI development
Foundation8 min

Choose a useful first AI task

Select a small task with clear inputs, visible results, and limited consequences.

Understand AI development
Foundation9 min

Measure useful progress

Measure completed work, review effort, and rework. Do not use generated code volume as a measure of value.

Understand AI development
Practitioner10 min

Choose a model with evidence

Compare models on representative tasks, acceptance criteria, cost, and the operating constraints of your team.

Understand AI development
Practitioner11 min

Use tests as evidence

Choose checks that can reject the wrong behavior. Review generated tests as carefully as generated implementation.

Build with intent
Practitioner12 min

Review AI-generated code

Inspect the actual change, its trust boundaries, and its evidence before you accept it.

Build with intent
Advanced11 min

Change an existing system safely

Preserve current contracts while you introduce a change. Account for old clients, data, and deployment order.

Build with intent
Practitioner10 min

Debug with testable hypotheses

Use an agent to compare explanations and collect evidence. Avoid repeated changes without a verified cause.

Build with intent
Foundation10 min

Define where your data can go

Trace data through the development tool, model, logs, and deployed service. Verify the boundary before using confidential information.

Make risk visible
Practitioner9 min

Limit an agent’s authority

Define allowed actions, resources, and conditions. Verify permissions outside the model and separate implementation from release.

Make risk visible
Practitioner10 min

Verify what enters the release

Inspect dependencies, build inputs, and artifact provenance. Connect the reviewed source to the software that reaches production.

Make risk visible
Foundation11 min

Connect obligations to evidence

Separate legal applicability, technical controls, and proof of operation. Build a record that a responsible reviewer can inspect.

Make risk visible
Foundation10 min

Connect the complete software lifecycle

Follow one feature from a user need to operation and feedback. Identify the decisions that code generation cannot settle by itself.

Develop and operate at enterprise scale
Practitioner10 min

Keep requirements traceable as software changes

Connect a user outcome to decisions, acceptance criteria, implementation, and evidence. Update the connections when assumptions change.

Develop and operate at enterprise scale
Advanced12 min

Platform engineering for AI development

Give people and agents supported ways to create, change, and operate services. Treat the platform as a maintained product.

Develop and operate at enterprise scale
Practitioner12 min

Define the infrastructure beyond a prototype

Assess identity, networks, data, recovery, and operation. Connect a generated deployment to the company’s actual infrastructure requirements.

Develop and operate at enterprise scale
Practitioner12 min

Design software for a cloud native environment

Connect repeatable infrastructure, replaceable processes, durable state, and observable behavior. Assess cloud native design beyond container packaging.

Develop and operate at enterprise scale
Practitioner12 min

Choose availability across zones and regions

Compare high availability, Multi-AZ, and multi-region designs. Trace the complete request path and test the failure each design must withstand.

Develop and operate at enterprise scale
Practitioner14 min

Set and test RTO and RPO

Define acceptable interruption and data loss. Compare recovery strategies and measure a complete recovery exercise against business requirements.

Develop and operate at enterprise scale
Advanced11 min

Coordinate AI development across teams

Manage shared contracts, review capacity, and change ownership. Measure the delivery system when many teams generate changes.

Develop and operate at enterprise scale
Practitioner9 min

Make a release decision with evidence

Check the version, target, remaining risk, and recovery method. Separate merge, deployment, and user exposure when the system requires it.

Develop and operate at enterprise scale
Practitioner10 min

Measure the delivery system

Combine delivery flow, instability, service outcomes, and effort. Use explicit definitions when evaluating AI’s effect.

Develop and operate at enterprise scale
Practitioner10 min

Own the service after deployment

Define useful service signals, incident decisions, recovery, and maintenance. Keep operational responsibility visible after code generation ends.

Operate and improve
Practitioner10 min

Maintain software throughout its useful life

Prioritize vulnerabilities, upgrades, configuration drift, and retirement. Follow a maintenance finding through to a verified production correction.

Operate and improve
Practitioner12 min

Keep finding and fixing vulnerabilities

Build a continuous process from vulnerability detection to verified production remediation. Understand the maintenance gap a successful prototype can hide.

Operate and improve
Practitioner11 min

Observe the service and its users

Connect metrics, logs, and traces to service objectives. Design alerts, data boundaries, and checks for missing telemetry.

Operate and improve
Advanced12 min

Connect delivery to the SOC and SIRT

Define security monitoring, incident handoff, evidence preservation, and recovery responsibilities. Keep security response connected to the software lifecycle.

Operate and improve
Advanced12 min

Set safe boundaries for self-healing

Automate known recovery actions with explicit authority, verification, and stop conditions. Separate runtime recovery from changing software.

Operate and improve
Advanced12 min

Close the loop with verified improvement

Turn production evidence into requirements, tests, controlled changes, and measured outcomes. Define what self-improving software can responsibly mean.

Operate and improve
Foundation10 min

Compare responsibilities before products

Compare an assistant, an internal delivery platform, and a software factory. Identify which work each option performs and which responsibilities remain.

Choose your operating model
Practitioner11 min

Compare complete operating costs

Include setup, retained work, runtime, integration, and change. Test assumptions instead of treating a single estimate as a forecast.

Choose your operating model
Practitioner10 min

Ask a supplier for evidence

Turn supplier claims into testable questions. Check scope, configuration, contractual terms, and the responsibilities your organization retains.

Choose your operating model
Practitioner10 min

Verify an exit before you depend on a service

Separate source-code ownership from operational portability. Test exports, independent builds, infrastructure access, and the evidence needed for a transition.

Choose your operating model
Foundation9 min

Write a decision you can review later

Record the problem, alternatives, evidence, accepted limits, and review triggers. Make a build-versus-buy decision understandable after the meeting.

Choose your operating model
Foundation11 min

Start a new product in Taiga

Prepare a bounded product, establish its context, and connect planning to your actual repository and environments.

Put Taiga to work
Practitioner11 min

Bring an existing codebase into Taiga

Review what Taiga derives from a repository. Separate current behavior from intended behavior and select the right response to an inaccurate document.

Put Taiga to work
Practitioner12 min

Review Discovery as a connected document set

Trace a requirement through the specification, architecture, data flow, and security documents. Handle revisions before planning depends on stale assumptions.

Put Taiga to work
Practitioner11 min

Turn an outcome into an initiative

Write intent that can become reviewable work. Inspect scope and dependencies before placing an initiative in the execution queue.

Put Taiga to work
Practitioner11 min

Choose where Taiga waits for a decision

Separate plan approval, build execution, merge permission, and deployment. Configure autonomy around the decisions your organization must retain.

Put Taiga to work
Practitioner11 min

Review a Taiga delivery with evidence

Connect the initiative, plan, run, diff, and checks. Verify the current change before accepting a merge or release decision.

Put Taiga to work
Practitioner10 min

Resolve a Needs you interruption

Diagnose why an initiative stopped. Choose continuation, replanning, restart, or a human setup action without losing the decision context.

Put Taiga to work