GitLab Duo Agent Platform
by GitLab Inc.
Agentic AI across the whole GitLab DevSecOps lifecycle: planning, coding, code review, CI/CD and security agents under one governance model
GitLab Duo Agent Platform is GitLab's built-in agentic AI layer that runs planning, coding, code-review, CI/CD and security agents inside the GitLab DevSecOps platform. It is for engineering organisations already on GitLab that want AI agents governed by the same permissions, audit trail and deployment model, including self-managed instances and self-hosted models, instead of bolting on a separate assistant.
GitLab Duo Agent Platform is the agentic AI layer of GitLab's DevSecOps platform, generally available since January 15, 2026. Rather than a standalone coding assistant, it orchestrates AI agents across the software delivery lifecycle (planning, coding, review, CI/CD and security) using the project, pipeline and vulnerability context GitLab already holds. It ships foundational agents (Planner, Security Analyst, Data Analyst and CI Expert), Agentic Chat in the web UI and editor extensions, and foundational flows that automate multi-step work such as turning an issue into a merge request, migrating CI/CD pipelines, fixing failed pipelines and reviewing code. Teams publish custom agents and flows through an AI Catalog, connect external agents such as Anthropic's Claude Code and OpenAI's Codex CLI, and use MCP clients and servers to reach outside tools. Anthropic Claude Sonnet 4 is the documented default model; self-managed customers can instead run self-hosted models behind GitLab's AI Gateway. Usage is metered in GitLab Credits at $1 each, with Premium and Ultimate seats carrying 12 and 24 included credits per user per month under a promotional allowance, and agentic code reviews billed at a flat $0.25 each. GitLab 19.4, released September 17, 2026, added a /goal command in the Duo CLI (public beta), three open-weight models (GLM 5.3, Kimi K3 and MiniMax M3) that GitLab says deliver up to 4x more calls per credit, separate model selection for the Developer Flow, unified allow/ask governance for GitLab MCP server tools, and generally available per-user credit reporting with per-user caps. NatWest is a named customer. For organisations standardised on GitLab it is the most direct alternative to GitHub Copilot's agent features and to third-party coding agents.
VP of Engineering or platform lead at an organisation already on GitLab Premium or Ultimate that wants AI agents inside its existing permissions and audit model rather than another vendor
Agentic automation of code review, pipeline fixes and issue-to-merge-request work, metered in credits and capped per user, on SaaS, Dedicated or self-managed GitLab
At a Glance
- Category
- Developer Tools
- Pricing
- Subscription, Usage-based, Freemium
- Target Market
- CTOs, VPs of Engineering, Platform Engineering Teams, DevSecOps Leaders
- Deployment
- Cloud-first, Self-hosted, Hybrid
- Customers
- GitLab reports 50M+ registered users and about 50% of the Fortune 100 as customers (platform-wide, not Agent Platform specific)
Key Features
- ✓Foundational agents
Pre-built Planner, Security Analyst, Data Analyst and CI Expert agents work on issues, vulnerabilities, data and pipelines using GitLab's own project context.
- ✓Foundational flows
Multi-step automations convert issues into merge requests, migrate CI/CD configuration, fix failed pipelines and review code without hand-offs between tools.
- ✓AI Catalog
A central catalog where teams create, publish and share custom agents and flows, so reusable automation is governed rather than scattered across repos.
- ✓External agents and MCP tool governance
Connects Claude Code and Codex CLI as external agents and exposes GitLab MCP server tools, with per-tool Always Allow or Always Ask modes.
- ✓Model choice including open-weight and self-hosted
Administrators pick models per feature, including GLM 5.3, Kimi K3 and MiniMax M3, or run self-hosted models on self-managed instances via the AI Gateway.
- ✓GitLab Credits spend controls
Usage-based credits with per-user caps, hard monthly subscription limits and per-event usage exports let finance teams forecast and cap agent spend.
- ✓/goal command in Duo CLI
A public-beta command that delegates an open-ended objective to a governed local flow with verification steps, which developers can pause or redirect at any time.
Capabilities
Use Cases
- •Issue-to-merge-request automation
A developer hands a well-scoped issue to the flow, which drafts the code change and opens a merge request for human review and approval.
- •Pipeline failure triage
Platform teams let the CI Expert agent and pipeline-fix flow diagnose failed CI jobs and propose fixes, cutting time spent reading job logs.
- •Vulnerability remediation
Security teams use the Security Analyst agent to review scanner findings, explain severity and suggest remediation inside the existing merge request workflow.
- •CI/CD pipeline migration
Teams modernising their build systems use the migration flow to convert existing pipeline configuration into GitLab CI with far less manual rewriting.
- •Governed agent spend
Engineering leaders set per-user credit caps and export per-event usage data to charge back agent consumption by team, namespace or project.
Ideal For
Best For
- ✓Enterprises already standardised on GitLab Premium or Ultimate
- ✓Regulated teams that need self-managed deployment with self-hosted models
- ✓Flat-rate AI code review on every merge request
- ✓Platform teams fixing failed CI/CD pipelines at scale
- ✓Security teams triaging vulnerabilities inside the merge request workflow
Not Ideal For
- ✗Teams whose code lives on GitHub or Bitbucket: the platform's value depends on GitLab-hosted issues, pipelines and security data
- ✗Organisations that need fully predictable per-seat AI budgets: consumption varies with usage and model choice, and the included credit allowances are described as promotional and subject to change
- ✗Existing Duo Pro or Duo Enterprise contract holders expecting continuity: GitLab's docs say the Agent Platform could not be used with the Duo Enterprise add-on in 18.9 and earlier, and InfoQ reported users told by sales that those seat add-ons are being phased out for credits
Deployment
Market & Ratings
GitLab reports 50M+ registered users and about 50% of the Fortune 100 as customers (platform-wide, not Agent Platform specific)
Market Analysis
Pros
- ✓Agents inherit GitLab's existing permissions, audit and project context instead of needing a separate integration
- ✓Runs on GitLab.com, Self-Managed and Dedicated, with self-hosted model support for data-sensitive environments
- ✓Flat $0.25-per-review agentic code review keeps review cost predictable regardless of merge request size
- ✓Open-weight model options that GitLab says stretch credits up to 4x versus some frontier models
- ✓Backed by GitLab's SOC 2 Type 2, ISO 27001 and ISO 42001 attestations for GitLab.com and Dedicated
Cons
- ✗Credit-based billing adds forecasting complexity, and InfoQ reported Reddit users being told by sales that Duo Pro and Duo Enterprise seats are being phased out, raising contract questions
- ✗Prompt injection is a demonstrated risk: Legit Security showed remote prompt injection in GitLab Duo leading to source-code exfiltration (May 2025, patched), and Hacker News commenters called the fix incomplete
- ✗Earlier Duo releases drew Hacker News criticism for trivial output quality, a price roughly double Copilot's, and self-hosting friction that needed significant admin time with GitLab support (2024 thread)
- ✗Value is largely confined to repositories, issues and pipelines hosted in GitLab
Pricing
Free
$0
- ✓5 users per top-level group
- ✓400 compute minutes per month
- ✓Agent Platform access on GitLab.com by purchasing GitLab Credits
Premium
From $29/mo
- ✓Per user per month, billed annually
- ✓12 included GitLab Credits per user per month (promotional)
- ✓10,000 compute minutes per month
Ultimate
Contact for pricing
- ✓24 included GitLab Credits per user per month (promotional)
- ✓50,000 compute minutes per month
- ✓Unlimited guest users
GitLab Credits
$1 per credit
- ✓Meter all Agent Platform features
- ✓Agentic code review at a flat $0.25 per review
- ✓Shared pool or monthly on-demand purchase
Agent Platform usage is metered in GitLab Credits at $1 each on top of seat subscriptions: Premium lists at $29 per user per month billed annually and includes 12 credits per user per month, while Ultimate is custom-priced with 24 credits per user per month; GitLab describes both allowances as promotional and subject to change. Agentic code review is a flat $0.25 per review regardless of merge request size. Free-tier GitLab.com groups can buy credits in monthly blocks, and admins can set per-user caps and hard monthly limits.
Security & Compliance
Sources
This page was written from 10 sources, 8 on domains other than about.gitlab.com.
- 1.about.gitlab.com — gitlab duo agent platformvendor
- 2.ir.gitlab.com — default
- 3.docs.gitlab.com — gitlab 19 4 released
- 4.docs.gitlab.com — duo agent platform
- 5.about.gitlab.com — pricingvendor
- 6.trust.gitlab.com — trust.gitlab.com
- 7.infoq.com — gitlab flatrate view ai access
- 8.stocktitan.net — git lab 19 4 brings new agentic automation at a lower 2xyng4
- 9.news.ycombinator.com — item
- 10.news.ycombinator.com — item
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
CodeRabbit
AI code review and agentic change management for teams shipping human- and machine-written code
Qodo
Agentic code review and governance layer for teams shipping AI-generated code at scale
Sonar Vortex
Guardrails inside the coding agent's loop, not at the pull request
Slack Code
Agentic coding in shared Slack channels, where the whole team can see the diff