Use cases / Knowledge and engineering
AI Coding
Faster engineering without giving agents the keys to production.
01
Problem
Developers already use AI tools, often unmanaged. Source code reaches unapproved models and agents can push changes nobody reviewed.
02
AI capability
Read a codebase, propose changes, write and run tests in a sandbox, and open pull requests for human review.
03
Data
The agent works from the context you connect, not from the open internet by default.
- Source repositories (scoped)
- Issue tracker
- Build and test logs
- Internal engineering docs
04
Agent
Coding Agent
Implements scoped tickets in a sandbox and opens reviewable pull requests.
05
Workflow
- 1. Pick up ticket
- 2. Read relevant code
- 3. Plan change
- 4. Implement and test in sandbox
- 5. Open pull request
- 6. Human review
- 7. Merge by a person
06
Governance
Governance runs inside the agent at runtime: policy changes what it can actually do.
Can
- Read repositories it is granted
- Run tests in a sandbox
- Open pull requests and comment
- Use approved models only
Cannot
- Merge to protected branches
- Read secrets or production data
- Deploy
- Change its own permissions
Requires approval
- Dependency additions
- Changes to CI or infrastructure files
- Access to a new repository
Records
Agent identity, Data accessed, Model used, Output, Tools called, Policy applied, Decision, Approval, Action, Outcome.
Suggested starting autonomy: L2 Approve
Start at L2: the agent proposes, a reviewer approves every change. Consider L3 for narrow, well-tested chores such as dependency bumps.
07
Outcome
What you measure, so the agent earns more autonomy on evidence:
- Pull request cycle time
- Review rejection rate for agent changes
- Test pass rate on first submission
- Escaped defects traced to agent changes
Questions
Can the agent deploy to production?
No. Deployment is outside its allowed actions; merges stay with people and existing release controls.
Which models see our code?
Only models listed as approved in the agent Trust Profile.