Service · Engineering teams

Claude Code, rolled out the way your security lead would want.

Your engineers are already using AI coding tools. The question is whether that happens inside a programme you can show to risk and audit, with the same review gates as any other change, or in the shadows. Airclerk helps engineering teams in regulated firms across New Zealand and Australia put the programme in place.

01 / At a glance
Who it's for
Engineering leads and platform teams in regulated financial and professional services firms, and the security lead who has to sign off before anyone points an agent at a repository.
What improves
Adoption you can see and measure rather than guess at. AI-assisted changes pass through the same or stricter review and test gates as everything else, their provenance is recorded, and you track throughput, defect rate and time-to-merge instead of seat counts.
What you get
Claude Code set up on your tenancy with repository and data boundaries defined; coding guidelines and policy your team helped write; review and approval gates for AI-assisted changes; a pilot team enabled and a rollout plan for the rest; and a measurement baseline to judge it against.
What you bring
An engineering lead who owns the rollout, your security lead for the boundaries, a pilot team willing to work in the open about what the tool does well and badly, and the software development lifecycle (SDLC) policies and review requirements you already have.
Timing and cost
A fixed fee and timeline, quoted in writing after a free introductory conversation with your engineering and security leads. Both are set by the number of teams and repositories in scope and how much of your SDLC needs to change. Claude Code licences are yours, under your own agreement with Anthropic. If your developers use GitHub Copilot or another coding assistant, the same rollout discipline applies; talk to us about that instead.
Afterwards
Handover of the guidelines, gates and measurement, and the support that follows, are written into the scope, so your team runs the programme without us. Widening it to further teams, or keeping the guidelines current as the tool changes, is a separate agreement.
02 / Why now

The tool is already in your codebase.

For a regulated engineering team the question is not whether your engineers will use AI coding tools. They already do. The question is whether that use is structured, bounded and visible to your secure development process, or happening on personal accounts with whatever the defaults allow.

Bringing it into the open changes what you can say to risk and audit: which repositories the agent can see, which environments it can touch, how its changes are reviewed, and what the team is getting for it. That is the programme we help you stand up.

03 / The rollout

Five steps, one pilot team first.

The order matters: boundaries before access, and a baseline before anyone claims a result.

01 · Set up and bound
TenancyRepo accessData boundaries

The engagement opens with the detailed design, agreed with your engineering and security leads. Then Claude Code on your tenancy: which repositories, which data and which environments it can reach, defined with your security lead rather than left to defaults, and the baseline measures taken. Secrets and permission boundaries written down.

02 · Pilot team
One teamReal backlog

One team, on its real backlog, for a defined period. They learn where the tool helps (test generation, understanding legacy code, first drafts of a change) and where it needs a shorter leash. What they find becomes the guidelines.

03 · Standards and gates
Coding guidelinesPR and approval gates

AI coding guidelines and policy your team helped write. Pull request and approval gates so AI-assisted code passes the same review and test discipline as human-authored code, or stricter. Provenance of AI-assisted changes recorded and reportable.

04 · Wider rollout
EnablementTraining

Where the scope includes it, the remaining teams brought on under the guidelines the pilot produced, with training that uses your codebase and your standards rather than a generic course.

05 · Measure
ThroughputDefect rateTime-to-merge

A baseline taken before the pilot and the same measures afterwards. Outcomes engineering leaders actually care about, not seat counts or prompts per day.

04 / What your security lead will ask

Boundaries, review and a record.

i.

Repository and data boundaries.

Which repositories, which data, which environments. Defined explicitly, per team where it matters, and not by default. Production credentials and customer data are kept out of the tool's reach by those boundaries, which your security lead signs off.

ii.

Review gates.

AI-authored code goes through the same review and test gates as human-authored code, or stricter ones. Nobody merges what an agent wrote without a person reading it.

iii.

Auditability.

For the repositories and teams in scope, the provenance of AI-assisted changes is recorded and can be reported to risk and audit: which changes had agent involvement, under which guidelines, reviewed by whom.

iv.

Adoption you can defend.

Measured against throughput, defect rate and time-to-merge, from a baseline you took before the pilot. We do not report vanity usage numbers as results.

Start here

Discuss Claude Code for your team.

A free introductory conversation with your engineering and security leads: the teams and repositories in scope, what your SDLC already requires, and what a good result would look like. If it is a fit, a written scope with a fixed fee follows.

Talk to us →
05 / Common questions

Common questions.

01What is Claude Code, and who is this service for?

Claude Code is Anthropic's agentic coding tool. Airclerk's Claude Code enablement helps engineering and platform teams in regulated financial and professional services across New Zealand and Australia adopt it safely and productively, with the secure development discipline regulated environments require.

02Why would a regulated engineering team need help adopting Claude Code?

In regulated organisations the question is not whether engineers will use AI coding tools, because they already are. It is whether that adoption is structured, governed and aligned with the secure development process, or happening in the shadows. Airclerk helps engineering leaders move it into a programme with boundaries, review gates and measurable outcomes.

03How does Airclerk handle source-code, data and security boundaries?

Airclerk sets explicit repository and data boundaries with your security lead: which repositories, which data and which environments, defined explicitly rather than by default. The rollout covers Claude Code setup on your tenancy, secure repository access patterns aligned with your SDLC, AI coding guidelines and policy, and secrets and permission boundaries.

04How is AI-authored code reviewed and made auditable?

AI-authored code passes through the same or stricter review and test gates as human-authored code, supported by coding standards, pull request and approval gates, and test-generation discipline. The provenance of AI-assisted changes is recorded and reportable to risk and audit.

05How do you measure whether adoption is working, and how do we get started?

Airclerk measures adoption against the outcomes engineering leaders care about, throughput, defect rate and time-to-merge, from a baseline taken before the pilot team starts, rather than against tool usage. To get started, contact us for a free introductory conversation with your engineering and security leads. If it is a fit, a written scope with a fixed fee follows, and Claude Code licences stay under your own agreement with Anthropic.