In scope
Defensive, bounded evaluation
One authorized repository, one finding class and a clear review boundary. Evaluate both the proposed correction and the ability to refuse a consequential action.
Cyber / defensive workflows
A proposed integration path for defensive security work: scope the finding, prepare a change, validate it and keep consequential execution behind explicit authority.
Governed remediation
A model can produce a plausible remediation. Tests can add evidence about its technical behavior. Neither, on its own, establishes the right to change a production system.
The proposed pilot separates change preparation from authorization, using an agreed repository scope and a non-production validation environment.
Named owner, selected repository and allowed task.
An AI-assisted proposal, not an automatic production change.
Agreed checks and explicit coverage limits.
Permission before any agreed merge or deployment step.
Conceptual pilot workflow. No model-provider partnership, approved integration or production deployment is implied.
In scope
One authorized repository, one finding class and a clear review boundary. Evaluate both the proposed correction and the ability to refuse a consequential action.
Out of scope
No automatic merge, deployment or third-party testing is part of this proposed pilot scope. Access and any external action need their own explicit authorization.
For security teams & technical partners
Start with one workflow
Define the action, name the authority and agree what evidence would demonstrate control.