team & governance

Powerful automation, with the controls to match.

CodeReviewer can merge code, apply fixes and scan your infrastructure. So admins decide who can do what, on which project, and which domains can be actively tested.

Member permissionsCheckout app
  • Merge pull requestson
  • Apply AI fixeson
  • Trigger AI runson
  • Manage test suitesoff
  • Database accessoff
the problem

Automation without guardrails doesn't get approved.

Tools that can merge and push need clear limits before a security review will sign off.

Agencies and larger teams need people to see some projects and not others.

Active security testing without ownership checks is a liability.

how it works

From trigger to result.

Organise into projects

Each project has its own repositories, specs, suites and members.

Invite your team

Send email invites and assign admin or member roles.

Set permissions

Choose what members can do: merge, fix, run AI, manage suites and more.

Verify your domains

Prove ownership to switch on active security scans for the domains you control.

capabilities

What you get.

Multi-project workspace

Keep clients, products or teams separate, each with its own repos, scope and members. Switching between them is quick.

Admin and member roles

Admins manage the workspace; members work in the projects they're invited to.

Granular permissions

Decide who can merge PRs, apply fixes, trigger AI runs, manage test suites, QA, database connections, scope, repos and projects.

Domain verification

Prove ownership with a DNS TXT record or a well-known file. Domains are re-checked automatically.

Overview dashboard

Open bugs, failing suites, Explorer findings, spec gaps, PRs reviewed and features in flight. One screen per project.

Notifications and search

In-app alerts for failed replays, broken budgets and scan findings, plus global search and a keyboard command palette.

Least privilege, by default

Every powerful action in CodeReviewer (merging, applying fixes, triggering AI runs, connecting a database) is its own permission. Admins can give a contractor review access without merge rights, or let QA manage suites without touching repositories. Nothing requires an all-or-nothing choice.

Built for many projects

Agencies and multi-product teams need clean separation. Each project has its own repositories, specs, test suites and members, and people only see the projects they belong to. Switching between them is a keystroke away.

faq

Questions, answered.

Can we restrict who is allowed to merge?

Yes. Merging pull requests is a separate permission from applying fixes or triggering AI runs, and each is set per member.

Can a member see every project?

Only if you add them. Membership is per project, which suits agencies and teams with separate products.

Why do we have to verify domains?

Active security scans and similar tests send real traffic at a site. Verification makes sure they can only be run against domains you control.

Do you support single sign-on?

Single sign-on and an audit trail are on the Enterprise roadmap. Talk to us if they're a requirement.

Give every PR the review it deserves.

Start your 15-day free trial. We onboard a few teams every week.