BACK TO BLOG

AI coding agents, a major outage, and a security patch: what this edition means for you

Technology keeps moving fast, and a lot of it is genuinely exciting. This is where we slow down, pull out what actually matters, and share our own take on what it means for you, and where it's worth a conversation with us if any of it applies to your team.

This edition: AI coding agents showing up inside everyday tools, what happens when a single vendor outage takes several of your tools down at once, and a security flaw that's a reminder to check what your AI assistants are actually connected to.

Salesforce launches Slack Code, bringing AI coding agents into shared channels

Dimly lit office at night with glowing monitors showing abstract chat and code windows, Salesforce and Slack logo overlay in the center.

What happened

Salesforce's new Slack Code creates dedicated channels where coding agents, including Claude, Devin, Copilot, ChatGPT, or Vercel's agents, work on a task while product managers, designers, and reviewers watch progress, add context, and step in in real time. Analysts point to real upsides, fewer handoffs and better cross-functional visibility, alongside real risks: channel sprawl, notification overload, and unclear boundaries between who's in the chat and what that person or agent can actually touch in the codebase.

Our take

Slack is already one of the platforms we help clients manage as part of our SaaS Managed Services work, so we've seen this pattern before it involved AI agents: chat membership and system permissions quietly drift apart. Someone gets added to a channel for visibility, and months later nobody remembers that channel also has write access to something important.

Slack Code raises the stakes on that same drift. Being in a channel where a coding agent is working isn't the same as having reviewed or approved what that agent can do, but it can start to feel that way, since watching an agent work in real time creates a sense of oversight that may not match the actual permission boundaries underneath. Before rolling something like this out, it's worth mapping who's actually in these channels against what access that membership silently grants, rather than assuming visibility and control are the same thing.

The upside is real. Fewer handoffs and more shared context are genuinely useful. It just needs an explicit permissions model underneath it, not an assumed one. Happy to help you think through what that model should look like.

Source: InfoWorld, "Salesforce wants to move AI coding into a shared workspace with Slack Code"

Related: SaaS Managed Services | Agentic AI services

Google brings its Antigravity coding agent under Gemini Enterprise for spend control

erver room at night with a dashboard screen showing abstract usage graphs, Google's logo overlay in the center.

What happened

Google is adding budget caps, pooled quotas, overage controls, and usage metrics to its Antigravity coding agent by folding it into Gemini Enterprise, replacing a more fragmented, project-level cloud billing setup. Analysts note the added governance pays off most for enterprises running autonomous, multi-turn agents, while teams doing lighter, autocomplete-style AI assistance may not see enough savings to justify upgrading.

Our take

We covered this exact pattern in a previous edition, when Stripe was reportedly in talks to buy OpenRouter to help companies manage AI spend across models. Google building spend controls directly into its own agent platform is the same problem showing up a layer higher: even the companies building these tools are concluding that unmanaged AI spend is common enough to build a whole feature around.

A dashboard with budget caps is genuinely useful, but it doesn't replace the decision it's meant to enforce. Caps and quotas only work once you already know which use cases justify an autonomous, multi-turn agent versus a lighter tool, and who has authority to raise a cap when a team hits it. Turning on spend controls without that groundwork just moves the ungoverned decision from "how much did we spend" to "who gets to raise the limit," which is progress, but not the whole fix.

If your team is evaluating Antigravity, Gemini Enterprise, or a similar platform, the native controls are worth using. Just don't mistake having the dashboard for having the policy. Worth a conversation if you're not sure which one you actually have.

Source: InfoWorld, "Google brings Antigravity under Gemini Enterprise to provide granular spend controls"

Related: SaaS Managed Services

GitHub's nearly 8-hour outage took Actions, pull requests, and Copilot down with it

Dark server room with one rack flickering red amid steady blue lights, GitHub logo overlay in the center.

What happened

A GitHub incident starting August 17 pushed error rates as high as 50 percent across core services, including pull requests, Actions, webhooks, and Copilot authentication. Recovery took nearly eight hours and proceeded in fits and starts rather than a clean fix, and GitHub had not published a root-cause analysis as of this writing.

Our take

The detail worth sitting with here isn't the outage itself, outages happen to every vendor eventually, it's how much came down with it at once. Code review, CI/CD, and AI-assisted coding all went dark together, because they're increasingly bundled into the same platform. A few years ago, a GitHub outage meant your team couldn't merge code. Now it can also mean your AI coding assistant stops working mid-task, which is a different, less familiar kind of disruption to plan around.

This is exactly the kind of dependency that a real vendor risk review surfaces and a general sense of "we use a lot of SaaS tools" doesn't. The useful question isn't "what happens if GitHub goes down," it's "what specifically stops for us, for how long, and what's our fallback," mapped out before an incident, not during one. That's core to how we approach SaaS Managed Services with clients: knowing what depends on what, so an outage is an inconvenience rather than a surprise.

Source: InfoWorld, "GitHub restores services after nearly 8-hour outage disrupts Actions, APIs, PRs, and Copilot"

Related: SaaS Managed Services

Microsoft patches a one-click flaw in Copilot Personal that could expose connected app data

Laptop on a dark desk with a single glowing warning icon on screen, Microsoft Copilot logo overlay in the center.

What happened

Varonis Threat Labs disclosed three vulnerabilities in Microsoft Copilot Personal, collectively named CoSnitch, that could let an attacker use a single crafted link to quietly pull data from a victim's connected apps and Copilot session. The flaws relied on an undocumented URL parameter that the assistant itself revealed during testing. Microsoft shipped patches on August 18, roughly eight months after the issue was first reported in December 2025.

Our take

Two things stand out here, and both matter more than the specific bug. First, this happened to Copilot Personal, a mainstream, well-resourced product, not an obscure tool. If a flaw like this can sit undocumented in something this widely used, it's a reasonable bet that less scrutinized AI assistants have similar gaps nobody's found yet. Second, the eight-month gap between report and patch is a reminder that waiting on a vendor's patch cadence isn't a security strategy on its own.

This is the same gap we keep coming back to in these roundups: most organizations don't have a clear, current picture of which AI assistants their employees use, what those assistants are connected to, and what that connection actually allows. That visibility is what our SaaS Security Management work is built to establish, and it matters regardless of how well-resourced the vendor is, since even Microsoft shipped this eight months after the report came in. Happy to help you check where your own blind spots might be.

Source: The Hacker News, "Microsoft Copilot Personal flaws could silently exfiltrate data"

Related: SaaS Security Management

The pattern across all four

Different stories, same underlying shift: AI agents are showing up inside the tools your team already uses, Slack, your coding platform, your personal assistant, faster than the access, cost, and security controls around them are catching up.

If any of these raised a question about where your organization stands, that's worth a conversation.

Let's talk

Share this post:

Book a meeting

Our Fractional CTOs are strategic, innovative team leaders. They’ll apply their technical knowledge and business strategy to help your company succeed.
talk to a cto
A Trusted Partner for all your digital needs

Meet the Band of Coders Community