- Ali-Reza Adl-Tabatabai said some teams now write rules that decide when an agent approves and merges a code change, instead of a person reading each one.
- He said teams reach that point in steps as trust grows. He sells the product, and the excerpts give no accuracy figures.
Ali-Reza Adl-Tabatabai co-founded Gitar, which is now part of Sonar. He argued that some teams now let an agent make the final call on merging a code change. In his account, the human job becomes writing the rules for when that is allowed. He made the case in a talk on the AI Engineer show.
What was said
His starting point is volume. A pull request (PR) is a proposed code change waiting for review. He said AI is producing more of them, and bigger ones. He put it this way: "You've got a lot of PRs now being generated, more PRs than before, thanks to AI, and bigger PRs, all of which can have defects."
His answer is to automate the checking too. Gitar's agent reviews each PR and summarizes why automated tests failed. It spots flaky tests, meaning tests that fail at random. It can also keep fixing problems until the PR passes.
The last step is the one he stressed. Users can set rules and conditions for when the agent approves and merges a PR. He said users get there in stages. They start with reviews. Then they let the agent block PRs, then auto-fix, and only then set merge rules. As he put it: "So over time, as they build trust in the system, they unlock more levels of automation."
Why it matters
Our reading: the skill being asked for changes shape. Reading every change is one kind of work. Deciding in advance which changes may merge unseen, and on what evidence, is another. Someone must own those rules, because they now stand in for a reviewer.
His staged path is also a usable pattern for buyers. Start with review only. Check whether the findings are accurate. Then widen the agent's powers one step at a time. He added that the same data helps platform teams, who can see which CI failures (failed automated checks) come up most often.
The other side
Adl-Tabatabai sells this product, and he ended the talk by inviting people to a booth demo. The excerpts give no figures on how accurate the agent is. They also give no count of incidents it prevents or lets through. He described a trend among his own users, not across the industry. He called merge rules a leap that is only now beginning.
He said he expects agents combined with traditional program analysis to beat either one alone. That is his opinion, and he offered no test results.
The excerpts leave two questions open. Who is accountable when an auto-merged change fails? And how do engineers build judgment if they stop reading most changes?
Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.
The conversation this talking point comes from
- AI Engineer: AI Writes More PRs. Who Validates Them? — Ali-Reza Adl-Tabatabai, Sonar (2026-10-09)





