Review Engine

The Review Engine is the automated reviewer — but not of diffs. It sweeps a project's own surfaces (pages, code, config, data, pipelines) and produces findings across quality domains, both on demand and on a schedule. Reviews of coder-produced diffs happen on the Reviews page; that's a separate mechanism.

What it covers

Findings come from domains — each is a tab on the dashboard. The built-in set:

  • Security, Architecture, Code Quality, Functional, Data Integrity
  • Design Coherence, Discovery, Pipeline Health
  • Regulatory Compliance, Third-Party Risk, UI/UX

Each domain produces findings with a severity — Info / Low / Medium / High / Critical — and a one-line summary.

What it reviews

Review sessions run against targets inventoried per project: application pages, code projects, config files, database tables, MCP tools, repositories. Each domain tab has a Target Inventory listing what it knows about. Everything on the page is scoped to the project selected in the top bar.

How it runs

  • Scheduled — a daily pulse (lightweight automated checks) and a weekly deep sweep run per project, so sessions and findings appear without any action from you. The Maintenance Schedule panel on the dashboard shows the last daily pulse, the last weekly deep, the last reviewed commit, and the conversation thresholds: when a sweep produces enough findings at or above the configured severity, the engine opens a conversation about them, and High/Critical findings raise attention requests.
  • Manual — tick the domains you want in the domain-selection panel and click Review Selected Domains (a dialog asks which LLM preset to run with). On a single domain's tab you get Review domain and, for domains that support it, Trigger Maintenance.

The domain checkboxes only scope the run you're starting — there is no per-domain on/off switch on this page, and nothing here blocks merges: the engine has no merge-gating mode at all.

Reading findings

A finding has a domain, severity, status, a category, a title and description, the target it was spotted on, and usually a recommendation. Click a finding to open the detail panel; from there you can add a note and act: Acknowledge, Open Matter, Won't Fix, Resolve.

Finding states:

  • Open — fresh, hasn't been triaged.
  • Investigating — marked as being looked at.
  • Resolved — fixed.
  • Dismissed — you decided it's not a real issue. Stays in history.
  • Deferred — punt to later.

When findings are wrong

The Review Engine uses rules and LLM judgments. It will sometimes flag things that aren't issues. Marking a finding Won't Fix (with a note saying why) is a perfectly good outcome — dismissed and won't-fix findings stay in history and searchable.

What Review Engine isn't

  • It's not a security scanner you'd bet your life on. Don't substitute it for SAST/DAST.
  • It's not a compiler. Some "obvious" errors might slip past if they only fail in a specific build configuration.
  • It's not a substitute for reviewing coder work. Diffs from your missions are reviewed on the Reviews page — the engine's findings live here, on its own dashboard.

When to use the Review Engine page

  • Checking what the scheduled sweeps found — the domain tabs carry open-finding badges, and the dashboard's domain cards show open/critical counts and when each domain last ran.
  • Starting a targeted review after a big change landed in a project.
  • Browsing the target inventory and each domain's rules.
  • Triaging findings — acknowledging, resolving, or opening a matter from the good ones.

The page is on the All features index (the "…" entry at the bottom of the sidebar), under Review Engine.