
Tech • AI • Robotics • Game
Qodo is building an AI code review and governance layer that feeds organizational knowledge into coding agents, checks changes against system-wide risk, and aims to reduce how often humans must intervene before software reaches production.
Qodo, led by CEO Itamar Friedman, positions its product as a companion to Codex and similar coding agents. The system gathers engineering context beyond the code itself, injects that context into generation and review, and helps produce cleaner pull requests from the start. The longer-term goal is a governance layer that maps software systems and tracks how they drift over time.
The company draws a distinction between intelligence and wisdom. Code alone captures implementation, but not the accumulated experience of an engineering organization: what failed before, which dependencies are brittle, where operational risk lives, and which patterns are safe at scale. That experience, often held as tribal knowledge, is treated as a key input for both code generation and review.
A recurring issue in software development is that a change can appear correct in isolation while creating a downstream failure elsewhere. Friedman cited customers serving millions of small and medium businesses, where flexible systems can expose database-related changes to outsized risk. In such cases, a locally sound edit can still trigger a major outage when viewed across the broader system, a class of problem that is difficult for both humans and coding agents to catch without a software-wide map.
The company describes a progression from prompt engineering in 2023, to flow engineering in 2024, and now to swarm engineering. Prompting fit early question-answering workflows, while flow engineering modeled the steps a developer would take across a task. Swarm engineering goes further by assigning multiple agents distinct goals, tools, guardrails, and policies, rather than letting agents recursively create sub-agents and workflows on their own.
Friedman argued that autonomous agent systems are still early and can become wasteful if left unconstrained. For products that must earn trust, outputs need to be grounded in evidence, with review systems designed to show why a conclusion was reached. That grounding is especially important when coding agents and adversarial review agents disagree.
A practical metric for AI-assisted review is how often a human developer must step in. The aim is for coding and review agents to settle most issues while code is being written, instead of surfacing long lists of findings only on a pull request page. By that measure, an effective review system reduces the number of times a developer must be prompted to achieve a high-quality pull request.
The company’s view is that reasonable agents with the same information should converge on the same answer. If they do not, the likely cause is different context. A human reviewer still matters when agents conflict, but the process improves if every judgment is tied to shared evidence and system knowledge rather than isolated code snippets.
Even if coding agents, review agents, developers, and reviewers all agree, errors can still reach production. The proposed answer is continuous learning: incidents, bugs, and post-release failures should be captured and recorded into a knowledge base, or “wisdom base,” so the same mistake is not repeated. Friedman argued that AI makes this codification of lessons learned more feasible than it was before.
One example involved a large Southeast Asian financial institution with hundreds of repositories and many microservices. In such environments, critical knowledge about what works safely at scale may reside with a handful of senior developers, some of whom have already left. Qodo’s approach includes scanning years of discussions across tools such as GitHub, GitLab, Bitbucket, Slack, and Teams to reconstruct that knowledge and connect service changes to downstream effects, including non-obvious data flows.
As models improve, the company expects software teams to redefine what counts as a task. Instead of treating a pull request as the main unit of work, teams may shift to end-to-end capabilities or features spanning multiple pull requests and repositories. Qodo said it plans to launch work package triage, a feature designed to show how multiple pull requests connect to a larger task and to review them as a whole.
The central bet is that AI code review will become less about checking syntax and style and more about encoding institutional memory, system context, and operational risk. If that works, human oversight shifts from line-by-line review to policy, exception handling, and continuous learning.
Ask a question