insomnia.club back to site
[ playbook · engineering ]

An AI code review agent that clears the easy findings before a human looks

The agent reviews every pull request within minutes: it reads the diff in the context of the surrounding code, checks it against the rules your team enforces, and leaves specific line-level comments. Senior engineers still approve the merge, without spending that approval on missing null checks.

who owns it

Engineering manager or tech lead who owns review standards for the repository

what starts it

A pull request is opened, or new commits are pushed to an open one

01the problem and who owns it

Review is the bottleneck nobody budgets for. Pull requests wait a day for the two people who know the payments module, and half their comments are about naming, missing tests, or an unhandled error path. The design questions only they can answer get a skim.

The tech lead owns review standards, but they live in their head and in old pull request comments. A linter catches formatting; it cannot notice that a new endpoint skips the authorization helper, or that a migration locks a large table during business hours.

02what the AI does, step by step

  1. Collect the diff and its contextA CI job or app webhook hands the agent the diff, full changed files, the pull request description, the linked ticket, and nearby callers and tests. A diff reviewed without its surroundings produces confident, wrong comments.
  2. Load the team's written rulesThe agent reads a review guide kept in the repository: architecture boundaries, required auth and logging helpers, migration rules, and banned patterns. Changing the guide is a pull request, so the rules stay versioned.
  3. Review for correctness and riskThe model looks for unhandled errors, missing authorization checks, unsafe input handling, race conditions, unscalable queries, and tests that assert nothing. Each finding cites exact lines and the failure it would cause.
  4. Filter before postingA second pass drops low-confidence findings, merges duplicates, and removes nits the linter already enforces. Fewer, better comments are what keep people from muting the tool.
  5. Post inline comments and a summaryFindings land as inline comments with a suggested change where obvious, plus a short summary of where a human should look hardest. The agent comments; it never approves or merges.
  6. Learn from resolutionsDismissed or unhelpful comments are logged, and a monthly review of them drives edits to the guide or filter, not silent prompt tweaks.

03systems it connects to

04human checkpoints

05what to measure

06risks and guardrails

07build vs buy

Off-the-shelf AI review apps install in minutes and handle generic correctness and style well. For a small repository with conventional patterns, start there and see what reviewers keep.

A custom agent pays off when the valuable rules are yours: internal frameworks, domain invariants, migration policies, and cross-service contracts a generic tool cannot know. On Pinned Golf, AI automation in the engineering process is part of how the engineering need went from five engineers to one, with review discipline keeping it safe.

Browse every engineering playbook or the full library.

want this running in your business?

We write your review guide with your tech lead, wire the agent into CI on one repository, and tune what it posts against real pull requests before it touches the rest.

See how we deliver it: ai coding orchestration.

book a call drop your number

info@insomnia.club