Solutions · AI code review
Use AI code review without handing over your repos.
A review bot needs the pull requests it is reviewing. It does not need your customer list, your chat or every other repo. Let it work through qbrin and it sees only the sources you pick. Before an AI merges anything, qbrin checks the proof.
- Merge checks: live
- Source scope: early access
- A receipt for every decision
Scope
Give the bot the code. Not the company.
Most AI tools ask to read everything, because saying yes is easy. With qbrin, the tool asks qbrin instead, and qbrin hands over only the sources its job needs.
What it usually gets.
- Read access to every repo, granted once when the app is installed.
- Whatever else its key can reach, because nobody set a limit.
- A key that never expires and has no owner who remembers it.
- No check between its idea to merge and the merge itself.
What this job needs.
- Pull requests and code from your code host.
- No chat, tickets, customer files or finance sheets.
- A key with a name, an owner and an off switch.
- A merge that waits for approval and passing CI.
- Code hostPull requests and codeAllowed
- Team chatNot shared
- TicketsNot shared
- Customer recordsNot shared
- Finance sheetsNot shared
- A review app with its own code-host loginqbrin cannot narrow a login it does not hold. It shows up as residual exposure, so you can see it.Not narrowed
How a limit works.
qbrin narrows what passes through qbrin: its own agents, and keys that call qbrin’s MCP or API.
- You pick the sources a job needs. A source you did not name is left out.
- For agents, a preview shows what the limit would have cut from the last 30 days.
- A login that qbrin does not hold is shown as exposure, not hidden.
Check
Check the merge before it happens.
The AI proposes the merge. qbrin checks the proof against what is true now, then answers go, hold or ask a person. We ran five merge attempts through a real LangGraph tool node, with and without qbrin.
What gets checked.
- Did a person approve it, and did CI pass?
- Is that proof about this repository?
- Is the proof recent, and is the agent from your account?
- GoThe proof checks out. The action runs.
API: allow - HoldNot enough proof. It stops and nothing happens.
API: hold - Ask a personThe owner decides. Nothing happens until then.
API: escalate
4
unsafe merges without qbrin
A plain LangGraph tool node ran all 5 calls. Four had missing, wrong-repo, old or other-account proof.
0
unsafe merges with qbrin
The one valid merge still ran.
The AI wants toMerge a pull request
- Passed: A person approved it
- Passed: Required checks passed
- Passed: The proof is about this repo and is fresh
A real LangGraph ToolNode, the same five calls run twice. No model judges the result, and the effects are simulated. Read the proof
Know
See every key and agent that can act.
One list of the people, AI agents, API keys and connections that can touch your code and data, each scored, with the fix named. The review bot gets a row like everyone else.
- Review bot key API keyToken never expiresFix: Set an expiry and rotate it.Medium
- Coding agent AI agentCan act without sign-offFix: Require a person’s sign-off.High
- Release helper AI agentNo explicit policyFix: Write a policy so the rules are yours.Low
- Summary app Unmanaged toolTool in use but not managedFix: Bring it under management or remove it.Medium
What you will see.
- Keys with full access, no expiry or no use are flagged.
- Tools in use that qbrin does not manage show up too.
- Revoke a key or require sign-off in one step.
Review with AI. Keep control.
See your own tools in the inventory, and watch a merge get checked.