How Software Actually Gets Built — and What AI Just Changed
- Session 0 — free and open to all
- 75 min + a self-paced field study
- No enrolment, no setup, no cost
- See the industry as it really works
Software is a team sport run as a loop, and every era of the industry — waterfall to agile to DevOps to AI — exists because the previous era's feedback arrived too late. Session 0 is the free, open front door: in 75 minutes plus one GitHub field study, anyone can watch how real software ships, see what AI genuinely changed by mid-2026, and weigh the evidence honestly in both directions. The durable takeaway: typing was never the bottleneck — verification is the scarce skill, and there is a clear path to train it.
The whole session, narrated. Or read it as text below.
One idea at a time — when a card lands, hit Got it — next and the next one appears.
Films sell the lone genius in a hoodie; the industry runs relay teams. The Software Development Life Cycle — SDLC — is the loop every product you use runs on: plan what to build and why, design how it works, build it, test it, ship it, watch it in production, and go again. The banking app you tapped with this morning, Uber Eats, WhatsApp — each release is the work of dozens to hundreds of specialists, and the loop turns every week or two. Hold this loop in your head for the whole session. The next fifty years of history are the story of one industry learning to turn this wheel faster and with quicker feedback — and the AI section at the end is simply the newest, fastest turn of the same wheel.
In 1970, Winston Royce published the paper that gave us the waterfall diagram — requirements, design, code, test, ship, each phase finished before the next begins. The twist: in the same paper he called that exact approach 'risky and invites failure' and argued for doing phases twice with feedback loops. The industry adopted his diagram and ignored his warning — the most misread paper in software history. The bill arrived in the 1994 Standish CHAOS report: 16.2% of projects succeeded, 31.1% were cancelled outright, and the average cost overrun was 189%. The FBI's Virtual Case File is the poster child — scrapped in April 2005 after roughly US$170 million, because 700,000 lines of code met their users years too late. Waterfall's fatal flaw: feedback arrives after the money is gone.
February 11 to 13, 2001, the Lodge at Snowbird, Utah. Seventeen software rebels — Kent Beck, Martin Fowler, Jeff Sutherland among them — skied, argued, and wrote four values and twelve principles that fit on a single page: agilemanifesto.org. They rejected the label 'lightweight' because nobody wants to be a lightweight, and, per Jon Kern, 'we left our egos at the door.' The roots ran older — a 1986 Harvard Business Review paper about rugby-style product teams, the first Scrum at Easel in 1993. The payoff shows in Standish's later data: agile projects succeed around 42% versus roughly 13% for waterfall. Best redemption story: the FBI's Sentinel system floundered until 2010, then cut the team to about 45, adopted two-week sprints, and shipped bureau-wide on July 1, 2012 — under budget. Same bureau that lost $170 million; new loop.

June 2009, Velocity conference: John Allspaw and Paul Hammond of Flickr present '10+ Deploys per Day' — when the industry norm was quarterly releases. Patrick Debois watched remotely and ran the first DevOpsDays in Ghent that October; the word 'DevOps' exists because 'Agile System Administration' was too long for a Twitter hashtag. By Velocity 2011, Amazon revealed it deployed to production every 11.6 seconds on average. Why the obsession with automated pipelines? August 1, 2012: Knight Capital manually deployed to seven of eight servers, dead code woke up behind a reused flag, and $440 million evaporated in 45 minutes — the firm was sold by December. No automation, no kill switch. Yet DORA 2025 finds only 16.2% of organisations deploy on demand and 43.5% still take over a week. Elite practice is rare — that gap is your opportunity.
Let's slow the Knight Capital tape down, because the mechanics teach more than the number. Engineers hand-copied new routing code to eight servers over several days — and reached only seven. The rollout reused an old feature flag, 'Power Peg', still wired to a retired test routine built to buy high and sell low on purpose. At the market open on 1 August 2012, orders hitting the eighth server woke that dead code, firing millions of orders exactly backwards — and with no kill switch, the confusion ran 45 minutes. Map each failure to its fix and you get the DevOps checklist: scripted deploys that treat every machine identically, flag hygiene that deletes retired code, instant rollback, alerts tied to business metrics. Keep the list — 2025's Replit database deletion is the same failure class wearing AI clothes.
Every logo on this grid started as somebody's specific pain. Start with the one that is local: Sydney, 2002, two 22-year-olds fund Jira on about ten thousand Australian dollars of credit-card debt and name it after Gojira — Godzilla — as a jab at Bugzilla; Atlassian booked US$5.22 billion revenue in FY2025, built on a self-service model that famously grew for years with no traditional sales force. The board you will run your sprints on was built here in Australia. April 2005: the Linux kernel loses its free BitKeeper licence, so Torvalds starts Git on April 3 and it hosts itself by April 7 — about ten days to usable. Slack is the salvaged chat tool of a dead game; VS Code's ancestor Monaco had about 3,000 monthly users before the 2015 pivot — 75.9% of developers use VS Code today. And Octoverse 2025's headline: a new developer joins GitHub every second, and AI-assisted work pushed TypeScript to the number-one language on the platform.
Follow one feature through a real team. A product manager writes the ticket with acceptance criteria; a designer draws the Figma flow; you branch and code; a teammate reviews your pull request line by line; CI and QA prove it works; DevOps ships it behind a feature flag and dashboards watch it live. LinearB's 2025 benchmarks — 6.1 million PRs across 3,000 organisations — put elite review pickup under 7 hours and full PR cycle under 26, with small PRs the number-one velocity driver. Now the myth-buster: Microsoft's Time Warp study clocked the average developer week at roughly 12% meetings, 11% coding, 9% debugging. Atlassian's 2025 survey of 3,500 developers found half lose ten-plus hours a week to friction like hunting for information. Remember this when AI enters the story: typing was never the bottleneck.
Before tonight's field study, let's read one merged PR together so the timeline feels familiar. Every PR on GitHub has the same skeleton: a description at the top, then interleaved events — commits, review comments, CI check runs — ending in a merge. Walk this one: opened Tuesday morning with 'Fixes #212345', so the work is traceable to a reason; fourteen checks pass across three operating systems before any human looks; a reviewer pins a question to line 87 — comments only, never editing the author's code; the author pushes a fix; approved and merged Wednesday. That rhythm is exactly LinearB's elite band — pickup under 7 hours, cycle under 26. And a PR with no comments merged in three minutes tells you something too: solo maintainer or rubber stamp. Reading these threads is free practice in the reviewer's eye this era pays for.
Autocomplete is older than you — IntelliSense shipped in 1996. Kite built AI completion from 2014, reached 500,000 developers, and shut down on 21 November 2022; its founder said they were 'ten years too early' — nine days before ChatGPT launched. GitHub Copilot went GA in June 2022 at $10 a month, already writing about 40% of new code in enabled files. ChatGPT hit 100 million users in two months, and Stack Overflow's monthly questions have since collapsed by roughly three-quarters. February 2025: Karpathy's 'vibe coding' tweet became Collins' Word of the Year within nine months. Claude Code went GA in May 2025 and passed $1 billion annualized revenue in about six months; Cursor 2.0 now runs up to eight parallel agents. Thirty years from autocomplete to agent fleets — with the whole inflection packed into the last five.
Mid-2026, stage by stage: the loop from our second slide is intact, but every stage grew an agent. Planning: over 70% of product managers draft PRDs with AI daily. Design: Figma's 2026 survey has 72% of designers using generative AI. Coding: about 27% of production code industry-wide is now AI-authored, measured across 4.2 million developers — Microsoft says around 30%, Anthropic 70–90%. Review: 44% of teams run AI code review, and CodeRabbit, after 13 million PRs, finds AI-coauthored PRs carry about 1.7 times more issues. Operations: PagerDuty's SRE agent can literally join the on-call rota. One cautionary tale to keep: in July 2025 a Replit agent deleted a live production database during a code freeze. The human job moved from producing to specifying and verifying — with guardrails, always.
Both columns are true; the variable is context. February 2023, controlled trial: 95 developers building a greenfield HTTP server were 55.8% faster with Copilot. July 2025, METR's randomised trial: 16 experienced open-source developers, 246 tasks in codebases they knew deeply — 19% slower with AI, after predicting 24% faster, and they still believed afterwards they had been 20% faster. A February 2026 follow-up with 57 developers landed near zero — neither miracle nor catastrophe. You cannot feel your own productivity; measure it. Quality: Veracode found 45% of AI-generated code fails OWASP security tests, flat for two years; GitClear logged 2024 as the first year copy-pasted code exceeded refactored code. DORA 2025's verdict resolves the paradox: AI is an amplifier — teams with tests, CI and small batches compound the gains; weak teams ship accelerated chaos.
Straight numbers, no doom — and be honest that the best-measured numbers here are American, because that is where the payroll research exists. Stanford's payroll study found employment of 22-to-25-year-old US developers fell about 20% from the late-2022 peak while older cohorts stayed flat. We have no equivalent Australian payroll study, so treat that as an overseas signal and check the local picture yourself: Jobs and Skills Australia publishes occupation shortage analysis for software and applications programmers, and the ABS Labour Force release gives the underlying employment trend. That entry-level signal is also not the whole story: postings that ask for AI skills advertise a pay premium. The quotable premium figures circulating are overseas ones, so we are not going to put a number on the Australian premium — read the local ads and see for yourself. Whatever it turns out to be, it is paid on top of fundamentals, never instead of them. The new titles are real — AI Engineer, forward-deployed engineer (up 800%+), agent ops — and each decodes to an SDLC role wearing new clothes, not 'prompt typist'. One habit worth building tonight: take any two current graduate or associate-engineer ads — say one from a bank's technology division, one from a consultancy — and strip each into fundamentals, AI-workflow, evidence. Hiring managers open your GitHub before your resume. The seats moved. Follow them.

Give this ten minutes; there are no wrong answers. First: would you merge a pull request your friend generated entirely with AI — and what would you check before merging? Listen for verification instincts and connect them to CodeRabbit's finding that AI-coauthored PRs carry about 1.7 times more issues. Second: which era would you rather have started in — 1995, 2010, or now? Expect a real split: some crave the perceived purity of pre-AI coding, others the leverage of today. Third: what would you still learn deeply even though AI can generate it? Steer the close towards DORA's amplifier idea — fundamentals decide whether AI multiplies you or your mistakes. Non-CS students are welcome voices here: employers increasingly want domain knowledge plus AI skills, so a mechanical engineer who can verify AI output is exactly the new profile.
Run this as a show of hands or shout-outs — no marks, no gate, purely a pulse check. One: waterfall's fatal flaw in one word — feedback, arriving years too late. Two: what did Flickr do ten-plus times a day in 2009 that shocked the industry — deploy to production. Three: the METR trial — were experienced developers faster or slower with AI? Slower, by 19%, while believing they were 20% faster; anyone who confidently answered 'faster' has just demonstrated the perception gap live. Four: what fraction of a developer's week is actually spent coding — about 11%, per Microsoft's own Time Warp study. Anyone who got all four right can already explain this industry better than most of LinkedIn. If any question felt fuzzy, the recap on the next slide is your one-minute revision.
Four things to carry home. One: software is a loop — plan, design, build, test, ship, watch — run by a team, and the loop matters as much as the code. Two: every era fixed the previous era's feedback pain: agile shrank years to two weeks, DevOps shrank weeks to minutes, and the disasters — a $170 million scrapped FBI system, $440 million lost in 45 minutes at Knight Capital — are exactly why those practices exist. Three: AI, from Copilot in 2021 to agent teams in 2026, moved the developer's centre of gravity from typing to specifying and verifying — and typing was only ever 11% of the week anyway. Four: the best evidence says AI is an amplifier; your fundamentals and process decide whether it multiplies your output or your chaos. Verification is the scarce, hireable skill.
Close the loop by sending the room somewhere good tonight — pitch these as the primary sources behind today's stories, not as homework. Karpathy's 'Software Is Changing (Again)' keynote is the big-picture map behind our 'Then AI arrived' arc — the best forty minutes a curious student can spend this week. Fireship's hundred-second CI/CD video makes the yearly-releases-to-11.6-seconds jump click visually. Doug Seven's 'Knightmare' is the minute-by-minute Knight Capital retelling behind our anatomy slide. Dare them to read Royce's 1970 paper — page two alone proves the warning was real — and the Agile Manifesto takes two minutes at the source. DORA's site hosts the amplifier evidence. Tell everyone the full clickable list, with a why for each pick, lives on this session's LMS page — no scribbling URLs from the screen.
Predict first, then reveal — commit to a guess before you open each one; that struggle is what makes it stick.
Objective: Walk the full life of real software inside a major open-source repository — issue to pull request to review thread to CI checks to release cadence — spot AI-written code in the wild, and finish with a five-line then-vs-now field report comparing a 2015 workflow with mid-2026.
Tool: A web browser + a free GitHub account + any free AI chat (Claude, ChatGPT, or Gemini)
One product, built in parallel with the course — this is the milestone that matches this session.
Five real products — choose one and build it in parallel, session by session.
You've used the ideas — now see how they actually work. Worked examples and common errors, one dive at a time.
The deck told you a PR is where a team talks about code; here is what that conversation physically looks like, so tonight's field study feels familiar instead of foreign. Every merged PR on GitHub is a timeline with the same skeleton: a description at the top, then interleaved events — commits, review comments, requested changes, CI check runs — ending in a merge event. Reviewers do not edit the author's code; they leave comments pinned to exact lines, and the author pushes new commits in response. That back-and-forth, sometimes three or four rounds, is where most of a junior developer's real learning happens.
Below is a compressed but realistic timeline from a large open-source repo. Notice three things. First, the description links an issue ('Fixes #212345') so the work is traceable to a reason. Second, the bot activity: CI ran fourteen checks across three operating systems before any human clicked merge. Third, the clock — opened Tuesday morning, first review within five hours, merged Wednesday. That rhythm is exactly what LinearB's 2025 benchmarks call elite: review pickup under 7 hours, full cycle under 26.
When you run the field study, score your chosen PR against this skeleton. A PR with no linked issue, no review comments, and a merge two minutes after opening tells you something about that team's culture too — usually a solo maintainer or a rubber-stamp habit. Reading these timelines is a skill you can practise free, tonight, on the world's best engineering teams, and it is precisely the reviewer's eye the AI era pays for.
PR #213448 — Fix terminal scrollback loss on resize
─────────────────────────────────────────────────
[Tue 09:14] mia-dev opened this PR
"Fixes #212345. Scrollback buffer was cleared on
resize because rows were recomputed before restore.
Tested: manual resize + new unit test."
[Tue 09:15] CI: 14 checks queued (linux / macos / windows)
[Tue 09:41] CI: all checks passed ✓
[Tue 13:52] reviewer-anna commented on line 87:
"Why recompute here and not in onResize()?
Suggest moving it — see snippet."
[Tue 15:10] mia-dev pushed 1 commit: "move recompute to onResize"
[Tue 15:34] CI: all checks passed ✓
[Wed 10:02] reviewer-anna approved these changes ✓
[Wed 10:05] Merged into main · issue #212345 auto-closed
The deck gave you the headline — $440 million in 45 minutes. The mechanics are more instructive than the number. Knight's engineers were rolling out new order-routing code called SMARS to eight servers, by hand, over several days. They reused an old feature flag — a switch named 'Power Peg' that had activated a long-retired test routine designed to buy high and sell low on purpose. The deployment reached only seven of the eight servers. When markets opened on 1 August 2012, orders hitting the eighth server woke the dead code, which began firing millions of orders exactly backwards.
Now map each failure to the practice invented to prevent it. Manual copy-to-servers → automated, scripted deployment that treats all machines identically, so 'seven of eight' cannot happen. Reused flag over dead code → code hygiene plus feature-flag lifecycle rules: retired code is deleted, not left armed. No kill switch → deployment systems with instant rollback; Amazon's Apollo could roll back in seconds even in 2012. Forty-five minutes of confusion → monitoring and alerting tied to business metrics, not just server health. None of this is exotic — it is the DevOps checklist, written in someone else's losses.
The uncomfortable 2026 echo: the deck's Replit incident — an AI agent deleting a production database during a code freeze — is the same failure class. Automation without guardrails just makes the mistake faster. The lesson students should carry into the AI section is that the safety practices born from Knight Capital (protected environments, staged rollouts, kill switches, humans reviewing before things go live) are precisely the guardrails now being retrofitted around AI agents. History is not background colour here; it is the requirements document for the AI era.
Henrico Dolfing — The $440 Million Software Error at Knight Capital
The deck's headline — entry-level developer employment measurably down in Stanford's US payroll data, while postings that ask for AI skills advertise a pay premium — makes sense once you learn to read job ads as data. Both halves come from overseas measurement; there is no equivalent Australian payroll study, so treat them as a signal to check rather than a local fact, and use Jobs and Skills Australia's occupation shortage analysis and the ABS Labour Force release for the Australian picture. Take any current Australian ad for 'Associate AI Engineer' or 'Graduate Software Engineer'. Strip the buzzwords and the requirements cluster into three buckets: fundamentals (Git, APIs, SQL, one language done properly), AI-workflow skills (prompting an agent, reviewing AI-generated code, writing evals or tests for model output), and evidence (a GitHub profile with real merged PRs, not certificates). That third bucket is new — hiring managers now open your GitHub before your resume.
The new titles decode the same way. 'Forward-deployed engineer' (postings up 800%+) means an engineer who sits with a customer and ships working software against messy real requirements — verification plus communication. 'Agent ops' means keeping fleets of AI agents productive and safe — the on-call discipline from the DevOps era pointed at new machinery. 'Context engineer' means curating what an LLM sees so it performs — a librarian's rigour applied to prompts and codebases. Every one of these is an SDLC role wearing new clothes; none of them is 'prompt typist'.
Practical move for a third-year student in Australia: pick two real ads this week — one from a large employer's in-house technology team (a bank, an insurer, a health or mining group all run big engineering functions here), one from a consultancy or product company — and bucket every listed requirement into fundamentals / AI-workflow / evidence. You will find the fundamentals bucket is still the largest, which is why this residency spends its first weeks on Git, Agile and the terminal before touching agents. Whatever premium AI skills carry in the ads you read, it is paid on top of fundamentals, never instead of them.
One atomic fact per card — try to answer before you flip. If it comes before the flip, it's yours.
One question at a time — commit to an answer to move on, then submit at the end. Grading happens on the server and returns an explanation for every question; 80% passes (and counts toward this session's progress); retakes are free and your best score sticks.
This take-home belongs to everyone in the room — enrolled or not. Work through it after the session, alongside the free GitHub field study. Nothing here needs a paid account or any code; it turns tonight's stories and numbers into your own honest picture of the industry you are about to enter.
Videos, articles and docs chosen for this session — the things a good mentor would actually send you.
Writing the Agile Manifesto — history page (Snowbird, Feb 2001)
IEEE Spectrum — Who Killed the Virtual Case File?
Henrico Dolfing — The $440 Million Software Error at Knight Capital
Werner Vogels — The Story of Apollo, Amazon's Deployment Engine
GitHub Octoverse 2025 — a new developer joins GitHub every second
Microsoft Research — Time Warp developer-productivity study (2024)
Atlassian — State of Developer Experience 2025
LinearB — 2025 Engineering Benchmarks (6.1M PRs)
METR — Measuring the impact of early-2025 AI on experienced developers
Google Cloud — DORA 2025: State of AI-assisted Software Development
Stack Overflow Developer Survey 2025
Veracode — GenAI Code Security Report (Jul 2025)
Stanford Digital Economy Lab — Canaries in the Coal Mine (Aug 2025)