The coding-agent race looked like an IDE contest. The battlefield has moved.

GitLab's Governed Software Factory is the signal. It connects /goal, Duo Agent Platform, Artifact Central, Dependency Firewall, Secrets Manager, Orbit, and Impact Analytics into one SDLC flow rather than scattered features. The message is one sentence: agents should not stop at generating code but travel through review, security, build, and deployment inside the same identity, policy, and audit chain.

What got tied together

Split by role and the picture simplifies.

Intent          Execution      Context         Control             Measurement
/goal     →  Duo Agent   →    Orbit     →  Policy · Secrets  →  Impact Analytics
             Platform         (context     Artifact Central
                              graph)      Dependency Firewall

One by one:

/goal — state the objective, the flow runs. The /goal command in Duo CLI hands an open-ended objective to a governed agentic flow. Instead of supervising each step, a developer directs the outcome while the flow verifies its own work locally. You can stop a run, revise the goal, and restart. The unit of delegation rises from tasks to outcomes.

Duo Agent Platform — orchestration across the SDLC. Generally available since January 2026, it lets agents split planning, coding, and security analysis. Agentic Chat, Flows, Sessions, Custom Flows, and MCP attach here. The point is not one smarter agent but many agents working under the same rules.

Orbit — the context graph. Code, merge requests, pipelines, deployments, vulnerabilities, and ownership become a live queryable graph that agents and engineers read from the same source. GitLab's internal testing claims up to 11x faster responses, up to 4.5x fewer tokens, and up to 45x fewer hallucinations on the same tasks with the same model. Compare the Market's test across 79 real merge requests found an Orbit-grounded reviewer placing accurate inline comments about 70% of the time versus about 58% for RAG.

Technically it ingests lifecycle data through change-data-capture into ClickHouse, parses 12 languages, and serves the graph over a Cypher-like DSL, MCP, REST, and CLI. At GitLab's own scale it indexes over 40,000 projects, 500 million nodes, and 2 billion edges in under 45 minutes. Authorization mirrors GitLab permissions, so agents see only what their user can see.

Artifact Central and Secrets Manager — controlled assembly and secrets. Artifact Central is a governed home next to source and CI for assembling the right software every time. Secrets Manager brings secrets inside and outside pipelines under one permission model, scoped to environment, branch, and protection status, extending toward Kubernetes, Terraform, and OpenTofu.

Impact Analytics — cost joined to outcomes. Credit consumption by team, task, and model gets connected to real production results. The question shifts from "how often did we use AI" to "what did the usage produce." The measurement story gets its own article at the end of this series.

GitLab's surrounding numbers add context. Orbit is reported in use across thousands of organizations, and agentic development active users grew 200% year over year in the last three months. A Forrester TEI study claims 400% ROI with payback under six months for Duo Agent Platform. Treat vendor numbers as directional, not gospel: adoption and usage volume are rising together.

Why it is no longer an IDE-feature race

The old question was "which agent writes better code." The new one reads like this.

Before: what is the pass@1 score?
After: did it reach production inside the same identity, policy, and audit chain?

Agents usually fail not on code quality but on navigating the system around it. In a large monorepo they crawl files to reconstruct context, burn tokens, follow wrong dependencies, and produce changes teams revert. That is why Orbit leads with "the same work with fewer tokens." Competition has moved toward context engineering plus governance plus observability plus cost control.

Three shifts developers will feel:

Before After
Agents as IDE plugins Agents as members of the SDLC flow
Humans review after the fact Policy enforces before the fact
Cost as a monthly subscription Cost measured in credits, calls, and models

A five-field log: Context / Permission / Evidence / Cost / Outcome

Turn the briefing's action into practice. When you build an agent workflow, log these five fields alongside prompts and code.

[Agent work log]
1. Context: what did it read? (Orbit graph / RAG / file crawl / issue and MR links)
2. Permission: whose identity did what? (mirrored permissions / branch and env scope / approver)
3. Evidence: is there an audit trail? (who, when, what, why / MR, pipeline, deploy links)
4. Cost: what did it spend? (model, tokens, credits, retries, human review time)
5. Outcome: what survived in production? (merged, deployed, reverted, incidents, follow-ups)

A small team can start with one spreadsheet. Run two candidate agents on the same 10 tasks and fill in the five rows. You will see "changes that survived without revert" instead of raw scores. For reading the metrics, see the pass@1, cost, and time post and the cost-per-success post.

Conclusion: teams that govern agents outlast teams that merely run them

The Factory message compresses to this.

As agent autonomy grows, upfront policy enforcement matters more than after-the-fact code review.

Using agents in an IDE is now the starting line. The real gap opens on whether you laid down a context graph, bound permissions and secrets, blocked dependencies at machine speed, and joined cost to outcomes. For enterprise adoption, replace "do we use coding agents" with "what did one agent dollar leave in production." Teams that can answer that go to the next round.

Further reading

References

Go deeper with a course

Running agents fast matters less than keeping them inside a flow with validation and constraints. If you want to connect project rules and verification criteria to the working environment, that practice continues directly from the five-field log above.