Handing this work to a machine raises a fair question: how far does it go on its own?
Autonomy, stated honestly
The only vendor that says where its autonomy stops is the only one a CISO can defend before a committee. The level comes down to one question: who sets the objective?
L3
Baseline
Your engineers set a technical objective; the factory derives the plan and executes it, across every tooled scope.
L4
Demonstrated on security
On broad-mandate DevSecOps scopes, the factory derives remediation objectives itself, within the frame set by your rules.
L5
Not claimed
L5 is not claimed: its authors describe it as a conceptual stage, not a deliverable state.
Each autonomy tier is contracted scope by scope, with the human approval points chosen for your environment. It is reversible, and the factory's configuration belongs to you and can be exported.