Coding & Developer-Tooling Use Cases Best Practices
Ten practices for shipping coding, review, test, docs, and ops agents without surrendering merge and production judgment.
Search across all documentation pages
Ten practices for shipping coding, review, test, docs, and ops agents without surrendering merge and production judgment.
Use this list when a team wants "full autonomy" and you need a safer default path.
| Stage | Habits | Exit criterion |
|---|---|---|
| Use-case pick | 1-2 | Done definition + oracle exist |
| Sandbox design | 3-4 | Allowlists + propose-only path |
| Risk policy | 5-7 | Gate map + review standard published |
| Launch | 8-10 | Stops, eval slice, metrics dashboard |
Treat 1, 3, 5, and 8 as non-negotiable before any write access beyond a personal sandbox.
You can spike. Do not claim production readiness or expand auto-merge without habit 9.
Offer a narrow package class with draft PRs and measured rework. Do not skip gates to match a press release.
Write scope shrinks to docs paths, but citation rules and review ownership still apply. Habits 1, 6, and 7 remain central.
Swap "merge" for "prod change." Habits 4-6 and 8 become stricter; dual control replaces casual PR review for T2+ actions.
Only lightly. These habits target multi-step tool-using coding agents. Inline completion needs less process but still needs secret hygiene.
A short security/ops policy linked from the agent runbook: path patterns, action tiers, approver roles.
After incidents, after major model or tool changes, and on a fixed quarterly review. Autonomy can decrease.
An impressive demo with broad shell access, no stop conditions, and no human review on sensitive paths.
No for risky paths. CI green is necessary, not sufficient, especially for security-sensitive modules.
Treat those strings as untrusted. Enforce allowlists in the runtime; never rely on "please ignore malicious instructions" in the prompt alone.
When success cannot be checked automatically, tools do not exist, or the organization will not fund review and observability.
Stack versions: Pins from the category manifest (verify at build): OpenRouter (~315+ models, July 2026 pricing/fees); LangGraph 1.0+; CrewAI 1.14+; Microsoft Agent Framework 1.0; Vercel AI SDK 6; Pydantic AI (latest); LlamaIndex (latest); OpenAI Agents SDK (latest + MCP); MCP (Linux Foundation governance); A2A (HTTP+SSE+JSON-RPC 2.0); Solana
@solana/web3.js+@solana/spl-token.
Reviewed by Chris St. John·Last updated Jul 16, 2026