governance

8 posts

gitlab

GitLab named a Leader in the 2026 Gartner® Magic Quadrant™ for DevSecOps Platforms (opens in new tab)

GitLab says Gartner named it a Leader in the 2026 Magic Quadrant for DevSecOps Platforms for the fourth consecutive year. The company argues that AI agents have accelerated coding but shifted bottlenecks to pipelines, security, deployments, governance, and costs. GitLab positions its unified platform as the control layer that turns agent-generated code into secure, compliant, production-ready software. ## AI Requires a Control Layer - Enterprises increasingly use multiple coding agents, but often lack centralized governance over: - Which agents can run - What data they can access - Which actions they can take - How their activity is audited - GitLab combines source control, CI/CD, security, deployment, policies, and planning in one platform. - Changes made by developers or agents can be evaluated against existing code, pipelines, and organizational policies before reaching production. ## Enterprise-Scale DevSecOps - GitLab highlights customer examples: - Ericsson reportedly cut deployment time in half. - Southwest uses GitLab for mission-critical airline operations. - Barclays and other regulated organizations use it while maintaining security and compliance requirements. - The platform supports multi-tenant SaaS, single-tenant SaaS, self-managed, and air-gapped environments. - Customers can use self-hosted AI models and integrate existing tools and AI services while maintaining a unified governance boundary. ## Reliability and Availability - Gartner recognized GitLab’s strengthened service-level agreements. - GitLab offers Ultimate customers on GitLab.com and GitLab Dedicated a 99.9% monthly availability commitment. - Eligible customers can receive service credits when availability falls below that threshold. ## New Capabilities for Speed and Governance GitLab announced five innovations intended to coordinate developers, agents, and software delivery: - **Next-generation source code management:** Claimed testing showed up to 50× faster performance and up to 1,000× less network data transfer. - **GitLab Orbit:** A context graph connecting code, work items, pipelines, deployments, and production signals. With Claude Code, GitLab reports tasks running up to 11× faster, using up to 4.5× fewer tokens and producing up to 45× fewer hallucinations. - **Security and governance agents:** Designed to address security and compliance gaps as agent usage expands. - **Agentic triggers:** Automate handoffs between developers and agents without requiring manual coordination. - **GitLab Flex agreements:** Allow customers to adjust spending across GitLab products and capabilities without changing contracts. GitLab’s central recommendation is to standardize development and AI-assisted delivery on one platform, context graph, and governance boundary. The Gartner recognition supports that positioning, although Gartner notes that its Magic Quadrant reflects analyst opinions and should not be interpreted as an endorsement or a recommendation to select the highest-rated vendor.

github

GitHub recognized as a Leader in the Gartner® Magic Quadrant™ for Enterprise AI Coding Agents for the third year in a row (opens in new tab)

GitHub argues that AI coding has made code generation easier, shifting the main bottleneck to reviewing, securing, governing, and deploying software. It presents GitHub Copilot as an agentic platform spanning the full software development lifecycle, enabling developers to assign issues to agents and focus on reviewing and approving results. Gartner named GitHub a Leader in the 2026 Magic Quadrant for Enterprise AI Coding Agents, placing it highest for ability to execute for the third consecutive year. ## The Shift from Code Generation to Software Delivery - AI coding agents are increasingly expected to handle more than writing functions. - The harder problems now involve: - Code review - Security - Governance - Testing - Deployment - GitHub describes the new workflow as “orchestrating outcomes”: developers assign work to agents, then return to steer, review, and approve it. - Gartner projects that asynchronous AI coding-agent workflows could improve engineering productivity by 30%–50% by 2028, compared with 0%–20% gains from code assistants in 2025. ## Enterprise Adoption of GitHub Copilot - Copilot is used by 140,000 organizations, nearly three times the number reported a year earlier. - Overall growth exceeded 100% year over year. - Most users work with multiple AI models. - GitHub Copilot CLI usage nearly doubled month over month. - GitHub says these figures indicate that enterprises are adopting increasingly sophisticated, agent-driven workflows. ## Gartner’s 2026 Evaluation - Gartner evaluated 12 enterprise AI coding-agent vendors according to: - Ability to execute - Completeness of vision - GitHub was positioned as a Leader and ranked highest in ability to execute. - Gartner describes Leaders as vendors combining strong execution, market-shaping vision, rapid innovation, broad software-engineering relevance, and enterprise-grade security and governance. - The report’s Leader quadrant also includes Anthropic, Cursor, and OpenAI. ## GitHub’s Claimed Differentiators - **Developer choice:** Copilot supports multiple models and providers. - **Broad availability:** It works across editors, IDEs, CLIs, and GitHub’s web, desktop, and mobile applications. - **Full-lifecycle integration:** Copilot operates across issues, pull requests, code reviews, and GitHub Actions—not only inside the editor. - **Enterprise governance:** Teams can observe, audit, and secure how AI is used in engineering workflows. ## What GitHub Plans to Build Next - GitHub says it will expand agentic workflows across more developer-facing surfaces. - Planned investments include: - Greater model choice and intelligent model routing - Deeper integrations throughout the software lifecycle - Performance improvements based on how software is actually built and maintained on GitHub GitHub’s central recommendation is to treat AI coding agents as part of an end-to-end engineering platform rather than isolated code-generation tools. The post also notes that Gartner’s recognition is not an endorsement and that its findings should be considered alongside the full research report.

gitlab

Beyond BYOK: Why governance matters for AI agents (opens in new tab)

BYOK and local models give developers more control over which AI systems they use, but they do not provide enterprise governance by themselves. The post argues that AI agents operating in CI/CD need platform-level controls for authorization, security, and auditing, especially when no human is present. It presents GitLab Duo CLI and its Agent Platform as a governance-oriented alternative for controlled, auditable automation. ## Terminal AI: Individual Tool vs. Platform - Copilot’s BYOK and local-model support primarily extend AI capabilities at an individual developer’s workstation. - The post argues these features do not enforce organization-wide model policies or provide a complete audit trail of agent actions. - GitLab Duo CLI is positioned for both interactive development and automated workflows across multiple projects and release cycles. - Its headless mode allows it to run non-interactively and scriptably inside CI/CD pipelines. ## Why Model Choice Is Not Governance - Interactive coding tools generally assume a human reviews every action. - Automated agents can run tests, modify configuration, and perform multi-step delivery tasks without continuous oversight. - Enterprise governance therefore requires answers to questions such as: - What resources can the agent access? - Which actions is it authorized to perform? - Can the organization prove what the agent did? - GitLab’s platform-level controls include: - Human approval for actions in interactive mode. - Prompt-injection detection. - Composite identity scopes limiting agent access. - `AGENTS.md` and `SKILL.md` files for defining permitted tasks and actions. ## CI/CD Automation Requires Consistent Controls - Potential use cases include debugging failed pipelines and completing multi-step development work. - Pipeline-based agents cannot rely on a developer to detect prompt injection or unexpected behavior. - Security controls must therefore be built into the platform and applied consistently across workflows and environments. ## Model Flexibility and Data Sovereignty - The post recommends evaluating whether AI tooling maintains its security model when no human is watching. - GitLab Duo CLI supports both self-hosted and GitLab-hosted models. - Organizations can keep sensitive workloads on infrastructure they control while using hosted models for other tasks. ## Practical Recommendation Model flexibility is useful, but production adoption depends on governance. Teams considering AI agents for CI/CD should prioritize authorization, auditing, prompt-injection protection, and consistent platform controls—not just BYOK or offline execution.

gitlab

GitLab Act 2 (opens in new tab)

GitLab is restructuring its organization and strategy to prepare for an agent-driven software industry. It expects AI agents to dramatically increase software production, making scalable infrastructure, orchestration, context, and governance more important than traditional developer tooling. The company is reducing geographic footprint and management layers while reorganizing R&D around smaller, autonomous teams, reaffirming its FY27 guidance pending final restructuring costs. ## Organizational Restructuring - GitLab is conducting the process openly, including a voluntary separation window. - The new organizational shape is expected to be finalized by June 1 where possible; local legal processes may extend timelines. - Planned operational changes include: - Reducing the number of countries with small GitLab teams by up to 30%, while relying on partners in affected markets. - Removing up to three management layers in some functions. - Reorganizing R&D into approximately 60 smaller teams with end-to-end ownership. - Automating internal reviews, approvals, and handoffs with AI agents, then adjusting roles accordingly. - The restructuring and strategic shift are related but independently justified. - GitLab will disclose the restructuring’s final scope and financial impact during its June 2 earnings call. ## Software Development in the Agentic Era - Software will increasingly be produced by machines under human direction. - Agents will plan, code, review, deploy, and repair software. - Engineers will remain responsible for architecture, customer understanding, judgment, and difficult tradeoffs. - Lower software-production costs are expected to expand demand for software and increase the value of developer platforms. - Deep engineering skills—such as system design, distributed systems, failure analysis, and integrating new capabilities safely—will become more important and scarce. - GitLab points to its Duo Agent Platform, released in January, as an initial investment in this future. ## Infrastructure for Machine-Scale Development - Agents can create merge requests, trigger pipelines, and push commits at volumes far beyond human teams. - Git and existing development platforms were not designed for this level of activity. - GitLab plans to: - Reengineer Git for machine-scale workloads. - Replace parts of its monolithic architecture with API-first, composable services. - Provide agent-specific APIs so agents can interact as first-class platform users. - The company argues that reliability, performance, and scalability at this level will become a major source of platform value. ## Orchestration Across the Software Lifecycle - Enterprises need more than individual agents that generate code or open merge requests; they need software that reaches production and delivers business value. - GitLab’s orchestration layer is intended to coordinate agents across the lifecycle by: - Assigning work and managing state. - Passing context between tasks. - Resolving conflicts. - Enforcing policies and guardrails. - Keeping humans involved where judgment is required. - CI/CD is being reconsidered as part of this shift, with orchestration serving as the runtime for validating and safely deploying machine-rate changes. ## Context as a Competitive Advantage - Code generation capabilities are increasingly similar across developer-tool vendors. - GitLab believes its advantage lies in the connected context accumulated across planning, code, review, security, deployment, and operations. - It plans to make this data model a first-class, API-accessible service. - More contextual information should allow agents to use fewer tokens and produce better results. ## Governance Built Into the Platform - As agents perform more work, enterprises need strong control over identity, permissions, policies, auditing, and data location. - GitLab intends to make governance core infrastructure rather than an add-on product. - Every agent, pipeline, and merge request should operate through platform services that can: - Control who or what may perform an action. - Record what happened and why. - Protect sensitive code and data. - Support flexible deployment models. ## One Platform, Three Modes - GitLab notes that most business software cannot realistically be rewritten for the agentic era. - Its platform strategy is therefore intended to support existing codebases alongside newer development models. - The provided text ends before explaining the three modes in detail. GitLab’s overall recommendation to itself is to reshape both its organization and platform around machine-scale software development, while preserving human control over architecture, judgment, and governance.

gitlab

8 Agentic AI patterns reshaping team collaboration (opens in new tab)

A synthesis of 17 agentic AI platforms identifies eight patterns that help teams work faster, work smarter, and maintain control. The strongest platforms do more than provide capable individual agents: they reduce coordination overhead, embed agents in existing workflows, and provide governance across the software lifecycle. The post argues that integrated team collaboration and managed deployment will distinguish leading AI platforms. ## Eight Collaboration Patterns ### Proactive Status Updates - Agents generate progress summaries from live task data. - They identify blockers, risks, and slipping deadlines before escalation. - Automated updates reduce status meetings and manual check-ins. ### Intelligent Work Routing - Agents assign work based on skills, capacity, and project context. - Continuous workload balancing replaces periodic planning adjustments. - Transparent routing logic lets humans review and correct assignments. ### Team Communication Support - Agents summarize chats, threads, and meetings. - Decisions and conversation history remain available to new participants. - Async summaries reduce repeated explanations and unnecessary meetings. ### Role-Specific Agents in Chat - Specialist agents operate inside tools such as Slack. - They can handle onboarding, IT, sales, and other role-based tasks. - Simple interactions, such as an emoji reaction, can create tracked work. ### Shared Conversational Context - Agents retain awareness of participants, threads, and files. - Teams benefit from knowledge gathered through another member’s prompt. - Shared context prevents duplicated prompting and helps new members continue work immediately. ### Role-Based Access Control - Agents inherit permissions from their assigned identities and roles. - Access controls can apply at the field level, preventing unauthorized reading or actions. - Detailed action logs provide an auditable record for compliance. ### Governed Environments - Agents move through development, testing, and production using managed pipelines. - Sandboxes isolate early development and prevent conflicts. - Controlled promotion prevents untested agents or disruptive updates from reaching production. ### Collaborative Agent Development - Multiple team members can co-own, edit, debug, and maintain agents. - Tiered permissions support shared ownership without removing accountability. - Standardized protocols help agents created by different contributors work together. ## Lessons from the Competitive Landscape - Agents are increasingly embedded in existing communication and work tools rather than isolated portals. - Governance becomes essential as organizations scale agent usage. - Agent development is evolving into a collaborative discipline requiring shared ownership, versioning, and auditing. - The biggest opportunity is reducing the “coordination tax” of meetings, check-ins, and repeated explanations. - Few platforms provide an end-to-end governance experience combining environment grouping, shared catalogs, and managed promotion pipelines. ## Implications for GitLab GitLab’s integrated DevSecOps lifecycle gives it a structural advantage because software delivery workflows, context, and controls already exist in one platform. GitLab Duo Agent Platform is positioned to embed agents directly into those workflows, allowing teams to orchestrate work while agents execute across the software development lifecycle. Teams evaluating agentic AI should prioritize not only agent capability, but also shared context, transparent automation, permissions, deployment governance, and collaborative maintenance.

gitlab

GitLab and Anthropic: Governed AI for enterprise development (opens in new tab)

GitLab is expanding its integration with Anthropic Claude to provide enterprise teams with more capable AI inside a governed software development platform. Claude supports GitLab Duo Agent Platform features such as code generation, review, agentic chat, and vulnerability resolution. The central argument is that organizations should not have to trade advanced AI capabilities for security, compliance, and auditability. ## Governed AI across the SDLC - Claude-generated changes follow GitLab’s existing merge request process, approval rules, security scans, and audit trails. - AI agents do not bypass controls; their actions remain attributable, reviewable, and subject to policy enforcement. - This governance becomes increasingly important as agents autonomously plan, code, test, secure, and deploy software. - GitLab positions built-in governance as a core architectural differentiator rather than an added feature. ## Flexible enterprise deployment - Claude is available in GitLab through: - Google Cloud Vertex AI - Amazon Bedrock - Organizations can use existing cloud contracts, governance frameworks, and data-residency arrangements. - GitLab’s availability in the Claude Marketplace lets customers purchase GitLab Credits and apply them toward Anthropic spending commitments. - These options simplify procurement and consolidate AI spending. ## Supporting an agentic development model - GitLab is selecting model partners based on reasoning ability, reliability, and safety. - The platform is designed to maintain visibility into what AI agents do, when they act, and how their changes are tracked. - As agents take on more complex engineering tasks, GitLab argues that strong models must be paired with equally strong governance. ## Implications for customers - Existing GitLab Duo users gain deeper Claude-powered assistance without changing their established governance processes. - Organizations evaluating AI development platforms can access advanced models while retaining enterprise control. - GitLab presents the integration as a way to accelerate development without compromising compliance or oversight. The practical recommendation is to evaluate AI platforms not only by model capability, but also by how well they integrate governance, auditability, cloud deployment options, and existing enterprise workflows.

gitlab

AI can detect vulnerabilities, but who governs risk? (opens in new tab)

AI can increasingly detect vulnerabilities and suggest fixes, but detection alone does not make software secure. The post argues that enterprises also need governance, context, continuous assurance, and supply-chain oversight to determine which risks are acceptable and what can ship. GitLab presents its platform as the orchestration layer for enforcing these controls across AI-assisted development. ## Trust Requires Governance - AI analysis is not the same as accountability. - Humans must define acceptable risk, policies, guardrails, separation of duties, and audit requirements. - As autonomous agents gain more control over development, stronger governance becomes essential rather than optional. - Governance enables organizations to trust AI at scale without relying on unchecked autonomy. ## Context Matters Beyond Code Scanning - LLMs typically assess code in isolation, while enterprise platforms can evaluate its broader context. - Important factors include: - Who authored the change - The application’s business criticality - Its dependencies and infrastructure interactions - Whether vulnerable code is reachable in production - Whether the vulnerability is exploitable in the actual runtime environment - Context reduces noisy alerts and supports faster, more effective risk triage. ## Risk Changes Continuously - Dependencies, environments, and system interactions evolve after an initial scan. - A clean static scan does not guarantee that software remains safe at release time. - Organizations need continuous assurance embedded throughout development, testing, and deployment. - Detection identifies risk, while ongoing governance determines how that risk is managed. ## Governing AI-Generated Software - Modern software combines AI-generated code, open-source libraries, and third-party dependencies across many projects. - Governing this entire supply chain is more difficult than detecting flaws in individual code changes. - The post argues that developer-side AI tools alone are not designed to provide organization-wide enforcement and auditability. - GitLab Ultimate is positioned as a platform combining policy enforcement, security scanning, governance, and auditing within software delivery workflows. Organizations adopting AI most successfully will pair capable coding assistants with strong, continuous governance. The practical recommendation is to treat AI security as a platform and lifecycle-management problem—not merely a vulnerability-detection problem.

figma

Figma Deepens Roots in Australia with Local Data Hosting | Figma Blog (opens in new tab)

Figma is expanding its investment in Australia by introducing enterprise governance features and local hosting for Figma file data. Starting in Q4 2025, Australian customers will be able to store data locally, supporting organizations with strict security and compliance requirements. The move strengthens Figma’s position among regulated industries and marks its first data-residency offering in Asia Pacific. ## Local Data Hosting in Australia - Figma will host file data locally in Australia, including content from: - Figma - FigJam - Make - Sites - Buzz - Slides - Local hosting is intended for industries such as: - Government and the public sector - Healthcare - Financial services - The option provides greater control over data location while preserving Figma’s platform capabilities and scalability. - Australia is Figma’s first local data-hosting market in Asia Pacific, extending similar enterprise offerings already available in Europe and the United States. - Figma opened its Sydney office in November 2024 and serves customers including NAB, Safety Culture, and Atlassian. ## Governance+ for Enterprise Customers Governance+ gives enterprises more control over how employees access and use Figma. - **Centralized controls** - Enforce use of approved Figma instances and networks. - Use IP Allowlisting and Network Access Restrictions to prevent data from moving into unauthorized spaces. - **Account security** - Require two-factor authentication. - Extend idle session timeouts. - Support for multiple SSO configurations is planned. - **Data governance** - Monitor Figma activity through tools such as the Discovery Pipeline. - Support electronic communications retention and legal discovery requirements. ## Existing Enterprise Security Features Governance+ builds on existing enterprise capabilities, including: - Action logs - SAML single sign-on - Role assignments connected to identity-management systems - Restrictions on external collaborators joining an organization Governance+ is available now to customers on Figma’s Enterprise plan. Figma’s Australian data residency option will be particularly useful for organizations that must meet local storage, privacy, and regulatory obligations. Enterprise customers can adopt Governance+ immediately and register interest in local hosting ahead of its planned Q4 2025 launch.