← All brands

AI-assisted software delivery workflows · PUBLIC RESEARCH BRIEF

GitLabWhich AI suggestion belongs inside the software delivery workflow?

GitLab's current Duo Agent Platform page describes specialized agents and flows across planning, coding, security analysis, code review and CI/CD, with project context, policy controls and traceability. This brief studies where an AI suggestion helps a software team and where a maintainer should retain explicit control.

Sources checked 2026-09-25 · Simulation results not yet generated

CHANGE ONE THING. LEARN WHAT MATTERS.

Three questions for the GTM team.

01

For a GitLab merge request, would an AI code-review suggestion with linked repository context or a concise patch proposal lead maintainers to catch more relevant issues without accepting unsupported changes? Use a sandbox repository and independently seeded cases.

Set up this study →
02

When GitLab Duo analyzes a vulnerability, would showing source evidence and uncertainty before remediation or a draft fix with expandable evidence produce better security-review decisions? Include false-positive and insufficient-context cases.

Set up this study →
03

For a failed GitLab CI/CD pipeline, should an agent stop at root-cause explanation, open a draft merge request or propose a full flow? Compare reviewer corrections, traceability and safe no-action choices under fixed permissions.

Set up this study →

PROPOSED AUDIENCE

Who should weigh in?

North American software teams evaluating or using GitLab across planning, code review, security and CI/CD. Include developers, maintainers, security reviewers, platform engineers and engineering managers across different repository and deployment permissions. Recruit authorized adult employees. Proposed audience; no velocity, quality or security outcome is implied.

TWO TIME HORIZONS

Trial today. A habit tomorrow?

Near term · 0–90 days

Over 0–90 days, run controlled planning, review, security and pipeline tasks in a sandbox repository with versioned fixtures and fixed approval rules. Measure relevant findings, false positives, reviewer edits, source inspection, safe abstention and time to an independently verified resolution. Do not merge or deploy generated changes.

Longer term · 3–12 months

Over 3–12 months, follow approved teams across stable repositories and workflow policies. Examine defect escape, review depth, alert fatigue, pipeline recurrence, permission drift, agent maintenance and whether maintainers continue to verify suggestions. Velocity, quality and security claims require observed outcomes over comparable work.

What would make the result actionable?

Use nonproduction repositories, seeded and independently adjudicated cases, current roles, pinned tool and model versions and complete flow logs. Protect source code and secrets, restrict agent permissions and require human approval for merges and deployments. Simulated acceptance is not proof of correctness, security or engineering productivity.

A Gather simulation returns hypothetical customer reactions. Quantifying revenue, traffic or retention needs actual business inputs and validation against observed behavior.

Public sources

GitLab Duo Agent Platform overview for agents, flows and governance ↗Current product page; checked 2026-09-25