Clear the agent PR queue without reading every line.
Write your merge rules in one short YAML file. Verity checks every PR against them and against what the agent actually did, then marks which PRs need a reviewer and why.
@@ OrderDto.cs:12 @@ - public string Status { get; init; } + public OrderStatus Status { get; init; }
longer before a reviewer picks up an AI-assisted pull request than a manual one.
LinearB 2026 benchmarks, 8.1M PRs ↗of agent failures were the agent reporting success on work that had failed.
Characterizing False Success in LLM Agents ↗files: ["src/Api/Mobile/**"] ask: "Does this change alter the API contract: fields, types, status codes or routes?" about: diff expect: no severity: fail
@@ OrderDto.cs:12 @@ - public string Status { get; init; } + public OrderStatus Status { get; init; }
files: ["**/*.cshtml"] ask: "After the last edit, was the page loaded in a browser or by a test?" about: session expect: yes severity: warn
files: ["db/migrations/**"] severity: warn
files: ["src/**/*.cs"] check: tests_passed_after_last_edit expect: yes severity: fail
Show order notes on the order page and in the mobile API. Don't break the mobile contract.
read 42 lines
@@ :12 @@ - public string Status { get; init; } + public OrderStatus Status { get; init; } + public string? Notes { get; init; }
@@ new file @@ +ALTER TABLE orders ADD COLUMN notes text;
$ dotnet test Passed! 212 passed, 0 failed exit 0
@@ :30 @@ +<p class="notes">@Model.Notes</p>
$ dotnet build Build succeeded. · exit 0
"Done. The contract is unchanged: notes is additive." the agent's own words: never evidence
Your code reviewer reads the diff, and often the PR description the agent wrote. Verity checks your team's rules against the diff and the agent's session, and never reads the description. It doesn't judge code quality or correctness, so keep both.
A reviewer who isn't the PR's author adds the label verity-override:<rule>, and the PR shows who did. If a rule fires too often, it's one entry to change in .verity/rules.yml.
Secrets are redacted on the developer's machine, then again on upload. Redacted transcripts are stored encrypted, separately for each org, and deleted after 30 days. Or keep them in your own bucket. A report opens only for people who can read the repository on GitHub.
Only a fail rule that fires, and only if you make the check required. Starter rules are warnings, so nothing blocks until you choose.
Free for design partners while we set pricing with them. It works with Claude Code on private GitHub repos today.
Sign in with GitHub and add Verity to one repo. Starter rules are warnings, so nothing blocks until you choose.