Changelog: Trust for Agentic Engineering

Daniel Liszka

Engineering is going agentic. Agents plan, write, and ship code. Engineers move up the stack: design, review, decide what merges. Last month we shipped a set of features to help your team operate that shift with trust and traceability. Each gets its own deep-dive. Here’s what landed and why it matters.

Reviews on AI-Generated Pull Requests

Whether you build with agents, with AI assistance, or just yourself, you push the code. Chainloop gives you the insight in your CI/CD: an AI Score on every PR, a dashboard for the platform team, alerts in Slack when something needs eyes now.

Every PR now shows which AI agents contributed, the percentage of AI versus human work, the model version, tokens, cost, and session duration. We also run policies to make sure the quality, security and compliance of AI coding environment, to use only allowed skills, to avoid leaking personal data or secrets in your specs. Your reviewer sees what to look at, what to enforce, and what to block, live in the PR, not on a dashboard somewhere else.

Connect your GitHub repo to get started. Install the Chainloop CLI for session-level provenance: prompt, model, diff, line-level attribution. Either way, review of the AI’s work moves at the speed your team can pay attention.

Read the AI Coding Sessions guide.

AI Risk Assessment: Drafts Instead of Backlogs

Triage queues are the most-disliked work in security. Scanners surface thousands of vulnerabilities across teams and projects, and somebody has to read each one, decide if it applies to your code, write the assessment, and chase the fix.

AI Risk Assessment flips that. Hand Chainloop the backlog, and an agent prepares a draft assessment for each finding by reading your code and the evidence graph. You don’t open thousands of CVEs. You open thousands of drafts that are ready to accept, edit, or reject. When the fix is mechanical, the agent opens a PR with the patch.

Reviewers see the queue in Slack. Auto-remediation closes the loop on the easy ones. The team still owns the approve button. These are drafts, not autonomous merges.

Today the workflow runs on CVE findings. Coming next: SAST, SBOM quality issues, custom policies. Anything you can express as a policy and policy violations, an agent can draft an assessment for.

AI Risk Assessment drafts list with reviewer comments and approval state

Read the vulnerability management guide.

Ask Chainloop

For users inside the platform, we shipped a conversational interface. Hit Cmd+K and ask in plain English. Same questions you would send to a teammate, answered against your live evidence graph.

Things people ask in the first session:

  • “Are we ready to push the latest version?”
  • “What do we have running in production?”
  • “Do we have axios in any of our projects?”
  • “Show me everything that failed compliance this week.”
  • “Draft a policy that blocks containers from untrusted registries.”

We use it internally most often for release readiness, impact analysis, and drafting policies the team would otherwise procrastinate on. The answers are only as good as the evidence flowing in, so the more you instrument your CI, the sharper they get.

Ask Chainloop conversational interface in the platform via Cmd+K

Read the Ask Chainloop guide.

Enterprise Foundations

The platform also shipped foundations the rest of these features lean on:

SAML SSO. Top of the enterprise wishlist, live now. Native Slack and GitLab apps. First-class integrations, no more webhook glue. Project Security v2. Active-finding filters and summary tiles for faster triage. Keyless GitHub Attestations. No API tokens to rotate. UI refresh. Grid-based policies page, cleaner sidebar navigation, updated forms across the platform.

Full changelog at docs.chainloop.dev/changelog.

What’s Next

Each of these features will get its own post over the next few weeks: how the agents work under the hood, and how to grade your team’s agentic maturity against a model. Subscribe on LinkedIn to catch them.

Let’s Talk

We will be in Vienna for OWASP Global AppSec EU, June 22 to 26. If you are around, reach out. Always happy to grab coffee and hear what you are working on.

Continue Reading

; ---