Capability 03 of 04 · Development

Code Review & Quality

How AI-generated code is reviewed, validated, and approved before merging. Model upgrades do not buy security: the average GenAI security pass rate held flat year on year at 56%, and coding-specialised models scored no better than general-purpose ones.

5
maturity levels
15
practices
15
guides
L2 · Stage 02Delegated
L3 · Stage 03Systematic
L4 · Stage 04GovernedMost teams aim here
L5 · Stage 05Self-improving
Criteria - what to measure
  1. 01Agent fleet self-reviews code (error-fix-converge loop) before submitting for merge
  2. 02Human review is limited to Red-classified PRs (architectural decisions only)
  3. 03Continuous auto-refactoring runs in background without human initiation
  4. 04Agent self-review catches 90%+ of issues that would be found by human review
  5. 05Auto-refactoring PRs are tracked separately and have their own quality metrics

Which level is your team at in Code Review & Quality?

The criteria above are what we check in a facilitated assessment. Run it yourself to place this capability, see which gates you have passed, and compare it against the other 3 in Development.

Start the assessment →