Inspiration
AI agents can now do substantial work after code is written, but release authority should not silently move from humans to models. BOLT Release Guardian explores a supervised post-code workflow where GitLab Duo can execute a multi-step implementation task while a human retains final merge and deployment authority.
What it does
BOLT Release Guardian evaluates release readiness from pipeline status, tests, security findings, coverage and change risk. It produces one of three outcomes: READY, APPROVAL_REQUIRED, or BLOCK.
For the hackathon, we created a real GitLab issue asking for an auditable release-verdict report. GitLab Duo Developer was triggered with Implement, worked against the repository context, created a branch and merge request, added the requested feature and tests, and reported the result back to the issue.
How we built it
The project is a new GitLab repository created for Life After Code. It contains a deterministic Node.js release-policy engine, automated tests and GitLab CI. The real Duo session operated from issue #2 and produced merge request !1. GitLab CI passed on the generated change. After reviewing the result, the merge request was marked ready and merged into main by a human.
Why supervised autonomy
The agent can inspect context, implement a bounded change, run tests and create a merge request without asking for approval at every internal step. The consequential boundary remains explicit: the human reviews the outcome and decides whether to merge.
Evidence
- Real GitLab Transcend workspace
- Real GitLab Duo Developer session triggered from an issue
- Duo-generated merge request
- Passing GitLab CI pipeline
- Human-reviewed final merge
- Two-minute demo showing the complete workflow
What we learned
The useful boundary is not AI versus no AI. It is reasoning and execution versus authority. Agents can automate a large part of the post-code lifecycle while preserving a clear human control point for consequential actions.
What's next
Extend the same supervised control pattern to security remediation, release packaging, staging validation and monitored deployment while keeping production-impacting actions behind explicit policy and human authority.
Built With
- ai-agents
- automation
- ci/cd
- devsecops
- gitlab
- gitlab-duo
- governance
- node.js
Log in or sign up for Devpost to join the conversation.