Company
About Tomosu Our Team
Platform
Platform & Agents Indexes How it works Solutions Pricing
Get Started
MCP Server Integrations · GitHub App Integrations · CodeRabbit MCP Integrations · VS Code — Plugin Installation Integrations · Scan Your Repo Guide FAQ
Free Tools
Governance Impact
Resources
Blogs News Book a call →
Field notes

Notes from the merge gate.

Research, observations, and design partner conversations
Review · Automation

Code Review Automation Fixed the Wrong Problem

Time remaining in code review is up 441.5% year over year and PRs merged with no review at all are up 31.3%. Automating a comment is not the same as automating a review — and the constraint was never the comment.

Read
Integrations · Observability

The Code Review Observability Checklist Most Teams Skip

Pulling production signal into a PR comment is a good instinct. The pitfalls show up after the demo — stale service maps, one-way sync, alert-shaped noise, attribution collisions in a monorepo. Six things to verify before you turn the integration on.

Read
Review · AI Code

AI-Generated Code Needs a Different Kind of Pre-Screening

Code review assumed a human wrote it. AI-generated code fails differently — confident, clean, and plausible right up until it isn't. What pre-screening has to catch, why it's a different job from review, and why the teams getting this right review unevenly on purpose.

Read
Reliability · Metrics

MTTR Is the Wrong Number to Stare At

MTTR tells you how long an incident lasted, not why it happened or whether the fix addressed the cause. Faster rollbacks make the dashboard look great while the same class of bug keeps resurfacing. What automated root cause analysis has to do to be worth anything — and the metric that beats MTTR: recurrence.

Read
Validation · Supabase

Stop Having Your Customer Find Your Bugs

A validated study on the open-source Supabase repository: Tomosu produced 114 reliability findings, and 59 corresponded to defect classes already documented in public GitHub issues. Cron was the most failure-concentrated feature — three merged fixes for one header-handling bug over three months. Evidence that blast radius, not line count, should decide what a change must prove before it merges.

Read
New Category · AI Era

The Missing Layer in Modern Software Engineering: AI Governance

Every wave of software delivery removed a bottleneck — cloud, CI/CD, observability, AI coding. AI removed the last one. What is left is the confidence to govern the output. Software Governance is the new category above the pipeline: it orchestrates every tool's intelligence into one production decision.

Read
Governance · Strategy

A Signal Is Not a Gate

Harness acquired Codecov to turn coverage into enforceable decisions. The problem: a signal and a gate are structurally different objects, and no acquisition closes the gap. The next decade of software delivery hinges on getting clear about which is which.

Read
Industry · Observability

New Relic May See It. Tomosu Will Decide It.

New Relic launched AI Coding Observability and confirmed what the merge-gate category has been arguing for a year. Visibility is half the answer. Tomosu has been building the other half.

Read
Operations · Leadership

Production Resilience Is the Thing You Stopped Buying When You Bought Velocity

The velocity dashboard looks great. The on-call rotation is on fire. These two things are now happening at the same time in roughly every enterprise that has adopted autonomous coding agents at scale.

Read
Architecture · Strategy

When the Agent Has an OS and Production Has No Gate, the Gate Is the Product

RTX Spark and Bedrock AgentCore ship substrate governance. The harder problem is what governs the artifact after it crosses a boundary. Every substrate converges at one universal layer: the merge gate you own.

Read
Research · Risk

The Verification Debt Nobody Put on the Balance Sheet

AI agents now initiate 96% of the work in collaborator-driven repos. Almost none of it is governed by anything other than a human glancing at a diff. The gap between those two numbers is where risk quietly accumulates.

Read
Research

The Agency-Governance Split Is Real, and the Audit Trail Wasn't Designed for It

Agentic pull requests now constitute a substantial share of code authoring. Terminal merge approval remains almost exclusively human. The audit infrastructure most enterprises rely on was built before that split existed.

Read
Architecture

Two Halves of a Merge Gate, and the Layer That Sits On Top

Credo AI argues for policy-as-code upstream. Qodo argues for diff-aware analysis at the gate. Both are right. Neither captures the human governance decision itself, and that layer needs its own infrastructure.

Read
Strategy

Shift Left, Shift Right, and the Governance Layer Between Them

AI compressed both ends of the software lifecycle. The governance layer that holds the middle has not caught up. What that means for engineering, product, marketing, sales, and support in a SaaS company, and why the TCO case favours planning it in now.

Read
Governance Thinking

The Merge Decision Has a Half-Life

A merge gate governs one moment. Drift measures how far production has walked from the gate since. Every merge decision has a half-life — and making that aging visible is the next layer of governance.

Read