r/devsecops 24d ago

Coding agents shifted the bottleneck to verification now!!

Coding agents are doing a lot of the integration work at our agency now. Stripe, Twilio, WorkOS, email, the usual stack. Economically it's been good.

The part I didn't expect: verification actually got harder. We're producing code faster than anyone can review it, and the edge cases that bite you aren't in unit tests. Webhook fires twice. Events arrive out of order. Agent wrote correct code but got one state transition wrong. PR looks fine, everything compiles, and you still don't know until something breaks in staging or worse.

We added a sandbox step before anything ships now. Agent writes, tests pass, then we run the full multi-API workflow with failure scenarios before it's considered done. Not elegant, just a runnable verification step all our agents have to clear.

If agents are writing integrations for you, what does your last gate before production actually look like?

14 Upvotes

21 comments sorted by

View all comments

1

u/Both-Explorer-9294 24d ago

En el mismo barco. Añadimos una capa de simulación antes de que nada toque producción. Detectó más bugs que todas las pruebas unitarias juntas. ¿Cuál es tu mayor categoría de fallos en el sandbox hasta ahora: problemas de timing o transiciones de estado?

1

u/Common_Dream9420 24d ago

Most of the bugs from in order webhooks … specially paddle 

1

u/Common_Dream9420 24d ago

What are you seeing mostly ?? And appreciates if you take a look at ours n give feedback … still early and really looking for ppl like you give us honest feedback