Start where you already work. Connect the MCP server to your assistant, install the editor plugin, or point the scanner at a repository. Each path lands in the same place: a Production Reliability Index you can act on before a change merges.
Three ways in. They are not alternatives to each other — most teams end up running the plugin locally and the MCP server inside their assistant, with scans wired into CI behind both.
Connect Tomosu to the tools your changes already flow through — the pull request, and the review agent reading it.
Install the GitHub App and get PR reviews in under two minutes: installation steps with screenshots, what the review comment contains, the PRI score table, permissions, and how to manage or uninstall.
Connect Tomosu MCP to CodeRabbit in under two minutes: step-by-step OAuth setup with screenshots, the 8 tools CodeRabbit gains access to, and how they enrich PR reviews.
The pages that answer “what exactly does this do,” rather than “why does it matter.”
Install, authenticate, and the full tool and prompt surface: seven tools, three prompts, streamable HTTP with in-client OAuth.
What runs where: the analysis agents, the governance lane they feed, and the merge decision at the end of it.
PRI, Fragility, Drift, Governance Compliance, Runtime Signals, Code Volatility, Deployment Velocity and Escalation — what each one measures and how it is scored.
The end-to-end loop, from a change entering the lane to evidence written back after it ships.
Model the cost side: engineering hours, support spend, and what governance changes about both.
How the same layer is deployed for platform teams, engineering leadership, and regulated environments.
Background reading for the decisions the product is making on your behalf. These are the arguments behind the defaults.
What changed when code generation stopped being the bottleneck, and why review capacity became the constraint instead.
Why AI-generated code fails differently from human-written code, and why pre-screening is a separate job from review rather than a faster version of it.
A three-line change to a shared boundary outranks a 300-line change to a leaf component. Reach is the variable the diff does not contain.
Why the metric worth tracking is whether the same root cause comes back, not how fast the incident was closed.
Questions that come up before a first scan are collected in the FAQ. Anything else — a deployment question, a self-hosted requirement, an evaluation you want help scoping — goes to contact@tomosu.ai, or book time directly.