ENGINEERING
Nudge stale GitLab security-review MRs on a schedule
Runs on a schedule to find open merge requests carrying the security-review label that have sat without reviewer activity past your SLA.
How it runs
The automated pipeline, trigger to output.
- TriggerScheduled run (e.g. weekday morning)
- ActionList open MRs with the security-review labelGitLab
- LogicBucket each MR by idle time vs SLA
- ActionDM assigned reviewers about nudge-bucket MRsSlack
- OutputEscalate breached MRs to the security lead channelSlack
What it does
Keeps security reviews from stalling. On a recurring schedule it lists open merge requests with the `security-review` label, checks how long each has gone without reviewer activity, and chases the ones past your SLA. Reviewers get a direct reminder; anything well over the threshold is escalated to the security lead so nothing sensitive lingers unreviewed.
When to use it
Use it when security review is a bottleneck and MRs quietly age out. Good for teams with a thin reviewer pool who need gentle automated follow-up rather than manual triage of the queue every morning.
How it works
- 1A schedule triggers the run (for example every weekday morning).
- 2The flow queries the GitLab API for open MRs carrying the `security-review` label.
- 3A logic step computes idle time per MR and buckets each as on-track, nudge, or breached.
- 4For nudge-bucket MRs it DMs the assigned reviewers in Slack with the link and age.
- 5Breached MRs are posted to the security lead's channel as an escalation summary.
Set it up
What you configure once, before turning it on.
- 1Connect GitLabRepos, MRs, pipelines, registry.
- 2Connect SlackChannels, DMs, threads, mentions.
- 3Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 4Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 5Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Engineering workflows
Gate breaking API PRs behind downstream consumer acknowledgement
When a PR introduces a breaking contract change, comments the impact summary back on the PR, applies a blocking label.
Publish a versioned API changelog to Confluence on each release tag
On a new semver release tag, gathers the contract changes since the last release and writes a clean.
Agent reviews model-license fit and suggests compliant swaps on the PR
When a PR adds a Hugging Face model, an agent reads the model card and license, judges fit against your commercial-use policy.
Upgrade Impact Router to Module Code Owners
Maps a dependency-bump PR's affected modules to their CODEOWNERS, then DMs each owner on Slack with only the changelog slice that touches code they own.
Re-Voice IVR Prompts on Phone-Tree Config Merge
When a phone-tree config change merges in GitHub, regenerates the ElevenLabs audio for any prompt whose script changed in the diff and opens a follow-up PR adding the new audio…
Upstream Release to Notion Upgrade Brief
When a watched package publishes a new release, fetches the release notes, maps them to the internal modules that depend on it.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
