Code review
Why it matters
An AI coding agent writes code quickly and with confidence, including the wrong code. Review is the gate that catches the cut corner, the leftover placeholder or the test that passes without checking anything real. A green build only proves the code ran. It does not prove that it does what the business wanted. Without review, a broken billing rule or a leaked customer record can reach production looking perfectly normal.
A non-engineer can still review well by checking behaviour, not syntax. Ask the agent to explain the change in plain words, run it, and try the awkward cases.
How to apply it
- Read the diff with the same scepticism a junior colleague's first week of work would deserve.
- Ask specifically about security, duplicated logic and leftover placeholders, not only whether it runs.
- Check that each test asserts a real value rather than merely running the code.
- Keep changes small. A review of twenty lines is thorough, and a review of two thousand is a rubber stamp.
- Turn every real problem into a tracked follow-up, so it does not vanish in a comment thread.
- Write the review questions down as a checklist, so the check is repeatable.
What it is
A person, or another program, reads the exact lines that changed, called the diff, and decides whether the change should go in. The questions are practical. Does it do what was asked? Does it break anything that worked before? Is the same logic now written in two places? Does it expose private data? The review usually happens on a pull request, and the reviewer can approve it or ask for changes.
Common mistakes
- Approving because the automated checks are green.
- Letting the same agent that wrote the code be its only reviewer.