Tools & Technology

AI-Powered Auto-Approval Slashes PR Lead Time by 74% for Ona Platform

Global · · ona.com

Ona Platform significantly reduced its pull request (PR) approval times and overall lead time by implementing an AI agent to automatically approve low-risk code changes. This strategic move, guided by a strict policy and objective criteria, boosted developer productivity and deployment frequency without compromising security or compliance.


The Challenge of Code Review Bottlenecks

The article highlights a common challenge in software development: the code review bottleneck. Despite engineers becoming faster at writing code with the help of AI tools, the necessity for human review often creates significant delays. Ona Platform experienced median PR approval times of nearly three hours, leading to context switching and reduced efficiency. This bottleneck was particularly pronounced for low-risk changes, where human reviewers frequently offered only a perfunctory "LGTM" (Looks Good To Me) approval, indicating that their expertise wasn't fully utilized for these minor updates.

Implementing an AI-Driven Low-Risk Change Policy

To address this, Ona Platform developed and implemented a Low-Risk Change Policy, leveraging an existing AI code review automation. Key to this policy were two principles: objective, automated classification of PRs (engineers could not self-classify changes as low-risk) and the AI agent reviewing every PR, with human intervention only for escalated cases. Six strict criteria defined a low-risk change, including limits on lines of code, and prohibitions on changes to protobufs, database migrations, infrastructure, authentication, or audit logging. If any criterion was not met, the PR was automatically escalated for human review.

Significant Improvements in Efficiency and Governance

The results were dramatic: median time to first approval plummeted from 2 hours 49 minutes to just 3.8 minutes, and overall lead time dropped by 74%. This led to a tripling of deploys per week and a 2.9x increase in individual developer throughput. Crucially, the system maintained strong governance. While the AI approved the review, a human always performed the merge, ensuring traceability for SOC 2 compliance. The engineering platform team owned the classification tooling, and any changes to the AI's logic or criteria required explicit approval from senior leadership, demonstrating a robust control framework for this AI-driven process.

  • Key Takeaway for Auditors: The article emphasizes that the governance model is more critical than the AI model itself. Auditors should focus on the controls around AI-driven processes, such as automated classification, explicit criteria, audit trails, human oversight (e.g., human merge authority), and clear policy ownership.
  • Risk Mitigation: By separating AI approval from human merging, Ona Platform effectively mitigated risks associated with fully automated deployment, ensuring accountability and compliance.
  • Scalability and Efficiency: This case study demonstrates how AI can be strategically deployed to remove bottlenecks in development workflows, leading to significant improvements in efficiency and velocity without compromising quality or control, provided a strong governance framework is in place.

Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →