[{"data":1,"prerenderedAt":21},["ShallowReactive",2],{"blog-post-en-ai-agents-software-development-lifecycle":3},{"slug":4,"lang":5,"title":6,"description":7,"heading":8,"translationKey":9,"date":10,"keywords":11,"readingMinutes":17,"html":18,"alternates":19},"ai-agents-software-development-lifecycle","en","AI Agents in the Software Development Lifecycle","Where AI agents help in planning, documentation, code review, data and communication, and which controls each stage of the software lifecycle needs.","AI agents in the software development lifecycle: where they help and where control is needed","sdlc-pillar","2026-06-26",[12,13,14,15,16],"AI agents in the software development lifecycle","AI in software development","agentic SDLC","AI agent governance","MCP gateway",7,"\u003Cp>Most engineering teams started with AI in one place: a coding assistant in the editor. That is\nchanging. Assistants such as Claude Code or Cursor can now reach beyond the editor and act in the\ntools around the code, for example by creating Jira tickets, commenting on pull requests, updating\nConfluence pages or posting a summary in Slack. The technical enabler for this is the Model Context\nProtocol (MCP), an open standard that lets an AI client call tools in other systems.\u003C\u002Fp>\n\u003Cp>This changes the question a team has to answer. It is no longer only &quot;which assistant do we use?&quot;,\nbut &quot;what may this assistant do in each of our systems, and how do we know what it did?&quot;. This\narticle walks through the stages of the software development lifecycle (SDLC), describes where\nagents are useful in each stage, and names the control that matters most there. Each stage links to\na more detailed article in this series.\u003C\u002Fp>\n\u003Ch2>Why the lifecycle view matters\u003C\u002Fh2>\n\u003Cp>An agent that writes code in a local branch has a limited blast radius. An agent that can also\nclose tickets, merge pull requests, edit documentation and send email has a much larger one. The\nrisk does not come from a single tool; it comes from the sum of access across tools, usually\ngranted through personal API tokens that carry the full rights of the person who created them.\u003C\u002Fp>\n\u003Cp>In practice, this leads to two typical outcomes. Either the organisation blocks agents outside the\neditor, and the productivity gain is lost, or individual developers connect agents on their own,\nand nobody can say which agent can reach which system. Neither is a good baseline. A more useful\napproach is to decide per stage which operations an agent needs, grant exactly those, and record\nevery call.\u003C\u002Fp>\n\u003Cfigure class=\"post-figure\">\n\u003Csvg viewBox=\"0 0 760 326\" xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" role=\"img\" aria-labelledby=\"sdlc-map-title\">\n  \u003Ctitle id=\"sdlc-map-title\">Five lifecycle stages, the tools each one touches and the control that matters most there, with one audit trail across all of them.\u003C\u002Ftitle>\n  \u003Cpath class=\"fig-flow\" d=\"M20 22 H740\"\u002F>\n  \u003Cpath class=\"fig-head\" d=\"M740 17 L750 22 L740 27 Z\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"10\" y=\"40\" width=\"140\" height=\"56\" rx=\"10\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"80\" y=\"60\" text-anchor=\"middle\">01\u003C\u002Ftext>\n  \u003Ctext class=\"fig-t\" x=\"80\" y=\"80\" text-anchor=\"middle\">Plan\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"10\" y=\"106\" width=\"140\" height=\"86\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h\" x=\"22\" y=\"123\">TOOLS\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"80\" y=\"140\" text-anchor=\"middle\">Jira\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"80\" y=\"158\" text-anchor=\"middle\">Azure Boards\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"80\" y=\"176\" text-anchor=\"middle\">Trello\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--muted\" x=\"10\" y=\"202\" width=\"140\" height=\"64\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"22\" y=\"219\">CONTROL\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"80\" y=\"238\" text-anchor=\"middle\">project scope\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"80\" y=\"255\" text-anchor=\"middle\">no raw JQL\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M80 266 V284\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"160\" y=\"40\" width=\"140\" height=\"56\" rx=\"10\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"230\" y=\"60\" text-anchor=\"middle\">02\u003C\u002Ftext>\n  \u003Ctext class=\"fig-t\" x=\"230\" y=\"80\" text-anchor=\"middle\">Document\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"160\" y=\"106\" width=\"140\" height=\"86\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h\" x=\"172\" y=\"123\">TOOLS\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"230\" y=\"140\" text-anchor=\"middle\">Confluence\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"230\" y=\"158\" text-anchor=\"middle\">Azure DevOps Wiki\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"230\" y=\"176\" text-anchor=\"middle\">Notion\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--muted\" x=\"160\" y=\"202\" width=\"140\" height=\"64\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"172\" y=\"219\">CONTROL\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"230\" y=\"238\" text-anchor=\"middle\">space and page\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"230\" y=\"255\" text-anchor=\"middle\">version check\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M230 266 V284\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"310\" y=\"40\" width=\"140\" height=\"56\" rx=\"10\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"380\" y=\"60\" text-anchor=\"middle\">03\u003C\u002Ftext>\n  \u003Ctext class=\"fig-t\" x=\"380\" y=\"80\" text-anchor=\"middle\">Code &amp; review\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"310\" y=\"106\" width=\"140\" height=\"86\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h\" x=\"322\" y=\"123\">TOOLS\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"380\" y=\"140\" text-anchor=\"middle\">GitHub\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"380\" y=\"158\" text-anchor=\"middle\">Azure Repos\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--muted\" x=\"310\" y=\"202\" width=\"140\" height=\"64\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"322\" y=\"219\">CONTROL\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"380\" y=\"238\" text-anchor=\"middle\">per operation\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"380\" y=\"255\" text-anchor=\"middle\">merge off\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M380 266 V284\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"460\" y=\"40\" width=\"140\" height=\"56\" rx=\"10\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"530\" y=\"60\" text-anchor=\"middle\">04\u003C\u002Ftext>\n  \u003Ctext class=\"fig-t\" x=\"530\" y=\"80\" text-anchor=\"middle\">Data\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"460\" y=\"106\" width=\"140\" height=\"86\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h\" x=\"472\" y=\"123\">TOOLS\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"530\" y=\"140\" text-anchor=\"middle\">Databricks\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--muted\" x=\"460\" y=\"202\" width=\"140\" height=\"64\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"472\" y=\"219\">CONTROL\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"530\" y=\"238\" text-anchor=\"middle\">read only\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"530\" y=\"255\" text-anchor=\"middle\">column allowlist\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M530 266 V284\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"610\" y=\"40\" width=\"140\" height=\"56\" rx=\"10\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"680\" y=\"60\" text-anchor=\"middle\">05\u003C\u002Ftext>\n  \u003Ctext class=\"fig-t\" x=\"680\" y=\"80\" text-anchor=\"middle\">Communicate\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"610\" y=\"106\" width=\"140\" height=\"86\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h\" x=\"622\" y=\"123\">TOOLS\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"680\" y=\"140\" text-anchor=\"middle\">Slack · Teams\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"680\" y=\"158\" text-anchor=\"middle\">Gmail · Outlook\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--muted\" x=\"610\" y=\"202\" width=\"140\" height=\"64\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"622\" y=\"219\">CONTROL\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"680\" y=\"238\" text-anchor=\"middle\">channel scope\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"680\" y=\"255\" text-anchor=\"middle\">recipient rules\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M680 266 V284\"\u002F>\n  \u003Crect class=\"fig-box fig-box--primary\" x=\"10\" y=\"284\" width=\"740\" height=\"36\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"26\" y=\"306\">ONE AUDIT TRAIL ACROSS ALL STAGES\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"734\" y=\"306\" text-anchor=\"end\">append-only · hash-chained\u003C\u002Ftext>\n\u003C\u002Fsvg>\n\u003Cfigcaption>The five stages covered below, the tools each one uses and the control that matters most in it. One audit trail runs underneath all of them.\u003C\u002Ffigcaption>\n\u003C\u002Ffigure>\n\n\u003Ch2>Planning: backlog, sprints and work items\u003C\u002Fh2>\n\u003Cp>Planning work is repetitive and text heavy, which makes it a good fit for agents. Typical tasks are\ndrafting tickets from a meeting note, grooming the backlog, moving issues into the next sprint or\nsummarising what changed during the last one. The relevant systems are Jira, Azure DevOps Boards\nand Trello.\u003C\u002Fp>\n\u003Cp>The main control here is scope. An agent that plans sprints for one team should see that team&#39;s\nJira project and nothing else, and it should be able to move issues between backlog and sprint\nwithout being able to delete projects. In Vordix, Jira access is scoped by project key, with finer\nallowlists for issue types, boards and sprints. Before every sprint or board operation, Vordix\nchecks that the board or sprint really belongs to an approved project, and search accepts only\nstructured filters instead of raw JQL, so an agent cannot widen its own query. The details are in\n\u003Ca href=\"\u002Fblog\u002Fai-agent-jira-sprint-planning\">letting an AI agent plan Jira sprints\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Documentation: Confluence and wikis\u003C\u002Fh2>\n\u003Cp>Documentation tends to fall behind the code. Agents can help by drafting release notes, updating\na runbook after an incident or keeping an architecture page in line with the repository. The\nrelevant systems are Confluence, the Azure DevOps wiki and, for some teams, Notion.\u003C\u002Fp>\n\u003Cp>The control that matters is which spaces an agent may write to, and whether it can delete. Reading\na whole Confluence instance is often acceptable; rewriting pages in the HR space is not. Vordix\nscopes Confluence by space and page, and the Azure DevOps wiki rejects an update that is based on\nan outdated page version, so an agent cannot silently overwrite a colleague&#39;s edit. See\n\u003Ca href=\"\u002Fblog\u002Fai-documentation-confluence-azure-devops-wiki\">AI documentation in Confluence and the Azure DevOps wiki\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Code and review: GitHub and Azure DevOps Repos\u003C\u002Fh2>\n\u003Cp>This is where most teams already use AI, and where the stakes are highest. Reviewing a pull\nrequest needs read access to files and diffs and the right to comment. Merging, pushing to a\nprotected branch or triggering a deployment workflow are different operations with a different\nrisk profile.\u003C\u002Fp>\n\u003Cp>The control here is least privilege per operation. In Vordix every operation is a separate\npermission: an agent can be allowed to read pull requests and post review comments, while merging\nstays switched off. Access is scoped per repository, with allowlists for branches. For operations\nthat should only run with a human decision, an admin can attach an approval policy, for example to\nmerging a pull request; the call is then held until a reviewer approves it. This is configured per\noperation and is not on by default. More in\n\u003Ca href=\"\u002Fblog\u002Fai-code-review-permissions-github-azure-devops\">permissions for AI code review on GitHub and Azure DevOps\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Data: Databricks and the warehouse\u003C\u002Fh2>\n\u003Cp>Agents become more useful when they can answer questions with real numbers, for example the error\nrate of a service after a release. That requires access to the data platform, which often contains\npersonal data.\u003C\u002Fp>\n\u003Cp>The controls are table and column scope, and what happens to sensitive values in the result. The\nDatabricks integration in Vordix is read only and accepts structured queries instead of raw SQL,\nwith columns allowlisted per table. Data policies can mask, pseudonymise or remove values such as\nemail addresses or IBANs before the result reaches the model. See\n\u003Ca href=\"\u002Fblog\u002Fai-agents-databricks-data-access\">giving AI agents access to Databricks\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Communication: Slack, Teams and email\u003C\u002Fh2>\n\u003Cp>The last step of many workflows is telling people about it: a release summary in a Slack channel,\na status message in Microsoft Teams, an email to a customer. Communication tools are sensitive\nbecause a message leaves the team, and in the case of email, often the company.\u003C\u002Fp>\n\u003Cp>The controls are channel scope for chat and recipient rules for mail. Vordix scopes Slack by\nchannel and Teams by team and channel. For Gmail and Outlook, admins can restrict recipients to an\nallowlist or to internal domains, limit the number of recipients and disallow BCC. The same rules\nalso filter what the agent can read, so mail outside the policy never reaches the model.\u003C\u002Fp>\n\u003Ch2>Across all stages: one audit trail\u003C\u002Fh2>\n\u003Cp>Each stage has its own risk, but one requirement is shared: when something goes wrong, the team has\nto reconstruct what happened. If every tool logs agent activity in its own way, or not at all, this\nbecomes a manual search across systems.\u003C\u002Fp>\n\u003Cp>A central gateway can record every call in one place, including the calls it denied and why. In\nVordix the audit log is append only and hash chained, so later edits are detectable, and it can be\nexported or streamed to a SIEM (security information and event management) system. A log kept\noutside the AI vendor also has a different evidential weight than the vendor&#39;s own records. This is\ndiscussed in \u003Ca href=\"\u002Fblog\u002Fai-agent-audit-trail-eu-ai-act\">what an audit trail for AI agents should contain\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>One control point instead of many\u003C\u002Fh2>\n\u003Cp>The stages above describe one pattern: agents need access to many systems, and each system needs a\ndifferent kind of limit. Configuring these limits separately in every tool is possible, but the\nresult is hard to review, because the answer to &quot;what can this agent do?&quot; is spread across a dozen\nadmin consoles.\u003C\u002Fp>\n\u003Cfigure class=\"post-figure\">\n\u003Csvg viewBox=\"0 0 760 290\" xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" role=\"img\" aria-labelledby=\"sdlc-hub-title\">\n  \u003Ctitle id=\"sdlc-hub-title\">AI clients connect to one gateway; its organisation, project and workspace rules decide each call to every stage, and every call lands in one audit log.\u003C\u002Ftitle>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M136 80 C200 80 200 128 260 128\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"16\" y=\"60\" width=\"120\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"76\" y=\"79\" text-anchor=\"middle\">Claude Code\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"76\" y=\"93\" text-anchor=\"middle\">MCP\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M136 140 C200 140 200 128 260 128\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"16\" y=\"120\" width=\"120\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"76\" y=\"139\" text-anchor=\"middle\">Cursor\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"76\" y=\"153\" text-anchor=\"middle\">MCP\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M136 200 C200 200 200 128 260 128\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"16\" y=\"180\" width=\"120\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"76\" y=\"199\" text-anchor=\"middle\">CI job\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"76\" y=\"213\" text-anchor=\"middle\">REST\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M440 128 C500 128 500 41 548 41\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"548\" y=\"20\" width=\"200\" height=\"42\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"560\" y=\"38\">Plan\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"560\" y=\"54\">Jira · Boards · Trello\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M440 128 C500 128 500 91 548 91\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"548\" y=\"70\" width=\"200\" height=\"42\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"560\" y=\"88\">Document\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"560\" y=\"104\">Confluence · Wiki · Notion\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M440 128 C500 128 500 141 548 141\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"548\" y=\"120\" width=\"200\" height=\"42\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"560\" y=\"138\">Code &amp; review\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"560\" y=\"154\">GitHub · Azure Repos\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M440 128 C500 128 500 191 548 191\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"548\" y=\"170\" width=\"200\" height=\"42\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"560\" y=\"188\">Data\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"560\" y=\"204\">Databricks\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M440 128 C500 128 500 241 548 241\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"548\" y=\"220\" width=\"200\" height=\"42\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"560\" y=\"238\">Communicate\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"560\" y=\"254\">Slack · Teams · Mail\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M350 220 V240\"\u002F>\n  \u003Crect class=\"fig-box fig-box--primary\" x=\"260\" y=\"36\" width=\"180\" height=\"184\" rx=\"14\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"272\" y=\"60\">VORDIX\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"272\" y=\"74\" width=\"156\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"284\" y=\"92\">Organisation\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"284\" y=\"107\">ceiling\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"272\" y=\"122\" width=\"156\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"284\" y=\"140\">Project\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"284\" y=\"155\">selection\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"272\" y=\"170\" width=\"156\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"284\" y=\"188\">Workspace\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"284\" y=\"203\">endpoint\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--primary\" x=\"290\" y=\"240\" width=\"120\" height=\"36\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t fig-c-primary\" x=\"350\" y=\"263\" text-anchor=\"middle\">Audit log\u003C\u002Ftext>\n\u003C\u002Fsvg>\n\u003Cfigcaption>One control point: AI clients connect to the gateway, where organisation, project and workspace rules decide every call to every stage, and each call is written to one audit log.\u003C\u002Ffigcaption>\n\u003C\u002Ffigure>\n\n\u003Cp>An MCP gateway puts one control point between the AI clients and the tools. The agent connects to\nthe gateway instead of holding tokens for each system, and the gateway decides per call. How this\nworks, and when a team actually needs one, is explained in\n\u003Ca href=\"\u002Fblog\u002Fwhat-is-an-mcp-gateway\">what is an MCP gateway\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Trade-offs and limitations\u003C\u002Fh2>\n\u003Cp>A gateway is an additional component, and it has costs. It has to be operated, updated and\nmonitored; in the case of Vordix it runs self hosted on the customer&#39;s infrastructure, which keeps\ndata in house but means the team runs it. Permissions also need an owner: a gateway makes access\nreviewable, but it does not decide what the right access is. Finally, a gateway only covers the\noperations it supports. Coverage differs by tool; the Notion integration, for example, is limited\nto pages in databases today, so teams should check the operations they need against the\ndocumentation before a rollout.\u003C\u002Fp>\n\u003Ch2>Conclusion\u003C\u002Fh2>\n\u003Cp>AI agents are moving from the editor into planning, documentation, review, data and communication.\nThe benefit is real, but so is the combined access. A useful way to adopt agents across the\nlifecycle is to decide per stage which operations are needed, grant only those, and keep one\nrecord of every call. The following articles in this series look at each stage in detail.\u003C\u002Fp>\n\u003Cp>If you want to see how this looks for your own toolchain, you can request a demo or read the\nVordix documentation.\u003C\u002Fp>\n",{"de":20,"en":4},"ki-agenten-softwareentwicklung",1790588073004]