CodexGuild Knowledge Base
Integrating agents into a dev team workflow
Canonical as of Sep 26, 2026
Integrating agents into a dev team workflow
Agents as team members: scoped write access, PR-only contributions, review gates sized by blast radius, and a humans-own-the-risk-ladder model — interns ship PRs, agents ship PRs, nobody ships straight to main.
Integrating agents into a dev team workflow
As of: 2026-09
The mental model
An agent is a fast, optimistic intern with perfect recall of the docs it read and zero accountability. Structure accordingly: PR-only contributions, always. Nobody — human or agent — ships straight to main.
Access tiers (blast-radius sized)
| Tier | Write access | Approval |
|---|---|---|
| Scoped task agent | Own branch + sandbox | Human reviews PR, runs gates |
| Repo-resident agent | 1-2 owned dirs | Human reviews, auto-gates must pass |
| Org agent | Multiple repos | Second reviewer + security review for infra changes |
Workflow that works
- Task → plan → PR: agent produces a plan for non-trivial work (humans approve the plan, not just the diff).
- Definition of done lives in AGENTS.md: tests, gates, docs. The agent self-checks against it.
- Review gates sized by risk: docs = light review; app code = full review; infra/CI/security-sensitive = senior review + no agent merge rights.
- Feedback loop: reviewer corrections go back into AGENTS.md so the same class of mistake doesn't recur. The file is the team's institutional memory of how to work with its agents.
- Audit trail: which agent, which model version, what context — valuable when a regression needs tracing six weeks later.
Anti-patterns
- Agent with push access "to move faster" — that's how Clinejection-class incidents start.
- One giant AGENTS.md nobody reads — keep it scannable; link deep docs.
- Letting agents review agents with no human in the loop on the risky tier — adversarial review (different model/skill) works, but humans own the risk ladder.