Agent profile · Coding
GitLab Duo Agent Platform
GitLab Duo Agent Platform is classified by AgentenCode as a devsecops agent platform from GitLab. It belongs to the Coding category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.
AgentenTrust 2.0 · EU & governance evidence
Trust, privacy and control evidence for GitLab Duo Agent Platform
Direct answer: AgentenCode currently documents 5 of 36 normalized trust controls for this profile. Missing fields remain Unknown and are never automatically interpreted as “no”.
Important: these numbers show evidence coverage, not a product rating. 0 of 10 means that no field-level public evidence is stored for those ten controls in the current dataset. It does not mean the product lacks those capabilities.
Field-level evidence
Documented controls and values from primary sources.
API · Rest
Duo Agent Platform flows have a documented API surface.
Scope: duo_agent_platform_flows · verified 2026-10-01 · Primary source ↗Governance · Audit logs · API
Duo-related audit events are accessible through GitLab audit-event APIs.
Scope: duo_related_gitlab_audit_events · verified 2026-10-01 · Primary source ↗Governance · Audit logs · Available
Duo Agent Platform sessions generate dedicated AI audit events.
Scope: duo_agent_sessions · verified 2026-10-01 · Primary source ↗Governance · Audit logs · SIEM export
GitLab can stream AI audit events to external destinations suitable for SIEM ingestion.
Scope: gitlab_self_managed_and_dedicated_ai_audit_events · verified 2026-10-01 · Primary source ↗Governance · RBAC
GitLab Duo Agent Platform administration and agent enablement are governed by GitLab roles.
Scope: gitlab_duo_agent_platform_group_and_project_controls · verified 2026-10-01 · Primary source ↗Governance · SCIM
GitLab.com group membership used for Agent Platform access can be provisioned with SCIM.
Scope: gitlab_com_group_identity_governing_agent_platform_access · verified 2026-10-01 · Primary source ↗Hosting · Managed
GitLab.com provides a vendor-managed Duo Agent Platform deployment.
Scope: gitlab_com · verified 2026-10-01 · Primary source ↗Hosting · Self Hosted
Duo Agent Platform is supported on GitLab Self-Managed.
Scope: gitlab_self_managed · verified 2026-10-01 · Primary source ↗Protocols · Mcp · Client
GitLab Duo Agent Platform features can consume external MCP tools as MCP clients.
Scope: gitlab_duo_agent_platform · verified 2026-10-01 · Primary source ↗Protocols · Mcp · Server
GitLab exposes an MCP server with a Duo Agent Platform toolset.
Scope: gitlab_instance_with_duo_agent_platform_toolset · verified 2026-10-01 · Primary source ↗Evidence-backed overview
What is GitLab Duo Agent Platform?
GitLab Duo Agent Platform is classified by AgentenCode as a devsecops agent platform from GitLab. It belongs to the Coding category. This English profile does not maintain a separate factual record: it renders the same underlying evidence, trust and history data as the German profile.
Product-specific evidence for GitLab Duo Agent Platform
This profile links 13 unique primary sources across the product profile, field-level evidence, trust controls and documented relations. The points below describe this product’s stored evidence rather than generic characteristics of Coding.
SIEM Export
Yes · Scope: gitlab_self_managed_and_dedicated_ai_audit_events · verified 2026-10-01.
Primary source ↗RBAC
Yes · Scope: gitlab_duo_agent_platform_group_and_project_controls · verified 2026-10-01.
Primary source ↗SCIM
Yes · Scope: gitlab_com_group_identity_governing_agent_platform_access · verified 2026-10-01.
Primary source ↗protocols · mcp · client
Yes · Scope: gitlab_duo_agent_platform · verified 2026-10-01.
Primary source ↗AgentenCode treats this page as a reference profile rather than a ranking. Product facts are separated from editorial classification, and the profile is tied to a specific verification date. If a capability is not backed by sufficiently precise public evidence, it remains unknown instead of being inferred from marketing language or from similar products.
How to read the evidence
The field-level evidence layer records a value, a scope, a confidence level, a verification date and one or more primary sources. Scope matters: an enterprise-only security feature must not be generalized to every plan or deployment surface. The same rule applies to hosting, privacy, audit and protocol claims.
AgentenCode also keeps Unknown distinct from false. A missing claim means the public dataset does not currently contain sufficiently precise evidence for that field. A negative value is used only when a reliable primary source explicitly documents a restriction or non-availability.
Decision context
Provider and category
GitLab Duo Agent Platform is documented under Coding and is associated with GitLab. Category labels help navigation but do not replace product-specific evidence.
Verification status
The public profile is marked editorially reviewed and was last checked on September 30, 2026.
Trust coverage
5 of 36 normalized trust controls currently have field-level public evidence. The remaining controls are not treated as negative findings.
Source-first use
For procurement, security or legal decisions, use the linked primary sources and verify the plan, region and configuration that apply to your organization.
Capabilities, strengths and deployment checks for GitLab Duo Agent Platform
GitLab Duo Agent Platform is classified as DevSecOps-Agentenplattform from GitLab. The profile’s editorial layer is derived from the stored use cases, strengths and checks below; claims about security, privacy or governance remain separate and require field-level evidence.
Issue- und Codeaufgaben
This use case is part of the stored profile for GitLab Duo Agent Platform. The related strength is “Direkter GitLab-Kontext”. In a production evaluation, the practical boundary to verify is: Repository- und Projektberechtigungen eng vergeben.
DevSecOps-Automation
This use case is part of the stored profile for GitLab Duo Agent Platform. The related strength is “Abdeckung des Software-Lebenszyklus”. In a production evaluation, the practical boundary to verify is: Security- und Compliance-Prüfungen nicht überspringen.
Security-Workflows
This use case is part of the stored profile for GitLab Duo Agent Platform. The related strength is “Enterprise-Governance”. In a production evaluation, the practical boundary to verify is: Agentische Änderungen über Review- und CI-Regeln absichern.
Agentische Softwareprozesse
This use case is part of the stored profile for GitLab Duo Agent Platform. The related strength is “Agenten in bestehenden DevSecOps-Prozessen”. In a production evaluation, the practical boundary to verify is: Repository- und Projektberechtigungen eng vergeben.
What to verify before adoption
- Repository- und Projektberechtigungen eng vergeben. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
- Security- und Compliance-Prüfungen nicht überspringen. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
- Agentische Änderungen über Review- und CI-Regeln absichern. Treat undocumented controls as Unknown and verify the exact plan, region and deployment scope.
Verified history
The public history layer records only confirmed profile changes and verification events. Monitoring signals are not published as product facts until they have been reviewed.
- September 30, 2026 · New profile
Official sources
This profile links 13 unique primary sources across the product profile, field-level evidence, trust layer and documented relations. Provider documentation remains authoritative when the product changes between verification cycles.
- GitLab – Duo Agent Platform
- GitLab Docs – Agent Platform
- GitLab Docs – Flows API
- GitLab Docs – Audit events
- GitLab Docs – Audit event schema and examples
- GitLab Docs – Audit AI events
- GitLab Docs – Audit event streaming for instances
- GitLab Docs – Control GitLab Duo Agent Platform availability
- GitLab Docs – Custom agents
- GitLab Docs – Configure SCIM for GitLab.com groups
- GitLab Docs – Agents
- GitLab Docs – GitLab MCP clients
- GitLab Docs – GitLab MCP server
Frequently asked questions
What is GitLab Duo Agent Platform?
GitLab Duo Agent Platform is listed by AgentenCode as a coding agent or agentic product from GitLab.
How much trust evidence is documented for GitLab Duo Agent Platform?
The current trust layer documents 5 of 36 normalized controls. Missing controls remain unknown rather than being treated as false.
When was this profile last checked?
The current profile verification date is September 30, 2026. The linked primary sources remain authoritative if the product changes between checks.