Use cases / Compliance and security
An audit trail for regulated teams
Evidence that a person reviewed what mattered, and which code a model wrote.
The problem
Auditors ask how changes are reviewed. “Someone clicked approve” does not answer it for code written by an AI.
What visualdiff does
- Every review is stored with its verdict, the policy in force and where the policy came from.
- Provenance records which commits were agent-authored and whether a human followed.
- Protected paths (auth, migrations, pipelines) leave a warning or a block on the record.
Reports and policy sources are kept per workspace and exportable through the API.
Related
- Reviewing pull requests written by agentsAgents open pull requests faster than anyone can read them. Read the 10% that decides whether it is safe.
- Large refactors that hide a behaviour changeA refactor is supposed to change nothing. Find the one line that does.
- Stopping hallucinated dependenciesSlopsquatting: attackers register the package names models invent. Catch them at review.
- Seeing which running systems a change reachesThe diff says rds.tf. The map says orders-db, the API in front of it, and the queue behind it.