KAiM AI Code Governance Home · Use cases · AI Code Governance
Status: Live evaluation engine · Demo Data seeded PR · No backend; runs in browser
Flagship use case · 02 of 05 · Engineering · Guided walkthrough

AI code governance under HELM

An AI coding agent (claude-coding-agent) has opened a pull request that introduces a dependency with a known CVE and lacks human attestation. This page is a guided demo: pick a persona, review the PR, submit it to the HELM merge gate, see the deterministic decision, then take the next-step action that belongs to your role.

How this walkthrough works

Four steps. Each persona sees the same PR differently and takes different next-step actions. Try at least two personas to feel the architecture.

1

Pick a persona

Four roles in the same engineering organization. Each has different authority and different responsibilities post-decision.

2

Review the PR

Same PR for everyone — but the framing card shows how your role reads what's happening.

3

Submit to HELM

The deterministic merge gate evaluates 4 checks. The eval is the same regardless of persona — HELM is not opinion-based.

4

Take your action

After the decision, your persona panel on the right shows what you can actually do next. Interactive ones expand inline.

Acting asclick a tile to switch role
1 · Persona 2 · PR 3 · HELM 4 · Action
Pick a persona, then review the PR below.
Step 3. Submit the PR to the HELM merge gate. The eval is identical regardless of which persona you're viewing as — HELM is deterministic.
HELM· Merge Gate Evaluation · 4 checks Evaluating…
What's being evaluated: the AI agent's authority to merge this PR against this codebase, with checks for AI-origin elevated scrutiny, dependency advisory matching, human attestation, and test/eval coverage. Result is the same for every persona — what changes is what each persona can do with the decision.
HELM intervention · System worked as designed

Unsafe merge prevented

3 of 4 gates triggered an intervention. No CVE-bearing dependency reached main. 2 human reviewers assigned with SLAs. 5-step remediation plan generated. Decision signed and chained.

Why this was blocked

The PR introduces a known-CVE dependency under AI authorship with no human attestation and insufficient test coverage. HELM is configured to treat AI-authored PRs as requiring elevated scrutiny when any of the security / attestation / coverage gates fail. All three failed; merge gate intervened. The codebase remains safe.

Required remediation

Required human reviewers

🔒 Audit Evidence Chain Entry Signed · Immutable
Decision logged. · Switch personas above to see the same decision from another role.

This is how HELM fits CI/CD.

The same evaluation pattern lives in every workflow KAiM governs. Bring us your highest-risk code-merge path — production deploys, infrastructure changes, security-sensitive merges. We map it to actor / action / authority / policy / evidence / escalation, then show how HELM gates it.