Install
brew install glabShowcase


Verified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cdevidence →
Continuous integration and delivery — pipelines, runners, caching
Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrationsevidence →
The surrounding ecosystem — integrations, marketplaces, community packages
Governance — stories about governance in this arenaGovernanceevidence →
Stories about governance in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Project planning — stories about project planning in this arenaProject planningevidence →
Stories about project planning in this arena
Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaborationevidence →
Working on repos together — pull requests, reviews, permissions
Security — security posture and hardening storiesSecurityevidence →
Security posture and hardening stories
Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hostingevidence →
Running it yourself — self-hosted servers, open-source clients
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where GitLab stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓9/10
unlocks → Webhooks · API sandbox · Sync repository notifications and activity with chat tools · Connect the platform to external CI/CD tools instead of using its native pipelines · Install third-party security scanning integrations directly from a security tab
Subscribe to events via webhooks
—–
Build against official SDKs
~4/10
Issue scoped/least-privilege API credentials for an agent
~6/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
✓9/10
Rely on versioned APIs with a documented deprecation policy
✓8/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
✓8/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓9/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
✓9/10
unlocks → MCP client
Operate the product with natural-language commands
✓7/10
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
✓8/10
Set up automations that run autonomously in the background
✓8/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd
Continuous integration and delivery — pipelines, runners, caching
Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations
The surrounding ecosystem — integrations, marketplaces, community packages
Sync repository notifications and activity with chat tools
—–
Connect the platform to external CI/CD tools instead of using its native pipelines
—0/10
Extend my stack with third-party apps, actions, and AI models from a marketplace
✓8/10
Install third-party security scanning integrations directly from a security tab
—0/10
Governance — stories about governance in this arenaGovernance
Stories about governance in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Project planning — stories about project planning in this arenaProject planning
Stories about project planning in this arena
External pm sync
Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration
Working on repos together — pull requests, reviews, permissions
Security — security posture and hardening storiesSecurity
Security posture and hardening stories
Access security
Vulnerability scanning
Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting
Running it yourself — self-hosted servers, open-source clients
Deployment options
Sorted by importance (agentic first) (high → low) · 72/72 stories · click a row’s chevron for the rationale and evidence
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Cclaimed | |
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Cclaimed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none± | 0/10 | ||
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Cclaimed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full± | 8/10 | Cclaimed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial± | 4/10 | Cclaimed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none | 0/10 | ||
Consolidate static analysis, dependency, secret, and dynamic security scanning into one platform C Vulnerability scanning | devops-lead | Security — security posture and hardening storiesSecurity | 3 | full | 9/10 | Cclaimed | |
Create and manage Git repositories and browse their commit history C Repo management | developer | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 3 | full | 9/10 | Xcommunity | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | full | 9/10 | Xcommunity | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 7/10 | Cclaimed | |
Install a self-managed instance of the platform without laborious configuration G Deployment options | devops-lead | Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting | 3 | full | 7/10 | Cclaimed | |
Propose, discuss, and merge code changes using a pull or merge request workflow C Repo management | developer | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 3 | full | 7/10 | Xcommunity | |
Automatically receive pull requests that update vulnerable dependencies C Vulnerability scanning | developer | Security — security posture and hardening storiesSecurity | 3 | partial | 5/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 5/10 | Xcommunity | |
Review code changes online and respond to inline review comments C Code review | developer | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 3 | partial | 5/10 | Cclaimed | |
Define CI/CD pipelines as code using a YAML syntax C Pipeline authoring | developer | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 3 | partial | 3/10 | Cclaimed | |
Run CI/CD jobs on runners hosted by the platform without managing infrastructure C Runners | devops-lead | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 3 | partial | 3/10 | Xcommunity | |
Track requirements, features, and bugs using issues with milestones, time tracking, and dependencies C Issue tracking | developer | Project planning — stories about project planning in this arenaProject planning | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Secure my account with two-factor authentication G Access security | developer | Security — security posture and hardening storiesSecurity | 3 | none | untested | none yet | |
Automate application deployments as part of my CI/CD pipeline C Deployment | developer | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 2 | full | 9/10 | Cclaimed | |
Enforce coding standards and CI/CD policies across all teams and repositories C Policy enforcement | devops-lead | Governance — stories about governance in this arenaGovernance | 2 | full | 8/10 | Cclaimed | |
Extend my stack with third-party apps, actions, and AI models from a marketplace C Marketplace extensions | developer | Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations | 2 | full | 8/10 | Cclaimed | |
Generate and manage personal access tokens for authenticating to the platform G Access security | developer | Security — security posture and hardening storiesSecurity | 2 | full | 8/10 | Cclaimed | |
Have an AI reviewer analyze code changes and suggest fixes during review C Code review | ai-native user | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | full | 8/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 7/10 | Tprobed | |
Run my self-hosted instance on my choice of operating system and architecture, including containers G Deployment options | devops-lead | Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting | 2 | partial | 7/10 | Cclaimed | |
Set up SSH keys to authenticate and connect securely to the platform G Access security | developer | Security — security posture and hardening storiesSecurity | 2 | full | 7/10 | Cclaimed | |
Assign the initial code review of a pull request to an AI reviewer for faster turnaround C Code review | ai-native user | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | partial | 6/10 | Cclaimed | |
Have AI automatically generate and apply fixes for detected security vulnerabilities C Vulnerability scanning | ai-native user | Security — security posture and hardening storiesSecurity | 2 | partial | 6/10 | Cclaimed | |
Scale my self-hosted installation using reference architectures supporting tens of thousands of users G Deployment options | devops-lead | Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting | 2 | partial | 6/10 | Xcommunity | |
Detect and remediate leaked secrets across the organization's repositories C Vulnerability scanning | devops-lead | Security — security posture and hardening storiesSecurity | 2 | partial | 5/10 | Cclaimed | |
Enforce standardized, customizable merge checks before code can be merged C Code review | devops-lead | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | partial | 5/10 | Cclaimed | |
Get centralized visibility into CI/CD workflow runs across the organization C Runners | devops-lead | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 2 | partial | 5/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 5/10 | Cclaimed | |
Reuse community-built CI/CD actions or plugins in my pipelines C Pipeline authoring | developer | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 2 | partial | 5/10 | Cclaimed | |
Review large diffs and view third-party code quality reports directly in the review screen C Code review | developer | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | partial | 5/10 | Cclaimed | |
Use migration tooling to move my code and users from another platform or from self-hosted to cloud C Deployment options | devops-lead | Self hosting — running it yourself — self-hosted servers, open-source clientsSelf hosting | 2 | partial | 5/10 | Xcommunity | |
Search across repositories to find code, files, and commits C Repo management | developer | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | partial | 4/10 | Cclaimed | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 3/10 | Cclaimed | |
Control granular access permissions at the workspace, project, repository, and branch level C Repo management | devops-lead | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | partial | 3/10 | Cclaimed | |
Organize work from high-level roadmaps to everyday tasks using project boards C Issue tracking | developer | Project planning — stories about project planning in this arenaProject planning | 2 | none | 0/10 | ||
Run CI/CD jobs on my own self-hosted or private runners C Runners | devops-lead | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 2 | none | 0/10 | ||
Automatically update linked issue tracker statuses by referencing issue keys in my commits C External pm sync | developer | Project planning — stories about project planning in this arenaProject planning | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Launch a ready-to-code cloud-based development environment in seconds C Dev environments | developer | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Publish and consume software packages in multiple package formats from the same platform C Package registry | open-source-maintainer | Repos collaboration — working on repos together — pull requests, reviews, permissionsRepos collaboration | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Restrict repository access to specific IP address ranges C Access security | devops-lead | Security — security posture and hardening storiesSecurity | 2 | none | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
Access built-in resources to learn the Git version control system C Onboarding | developer | Governance — stories about governance in this arenaGovernance | 1 | full | 8/10 | Cclaimed | |
Make a single annual commitment and flexibly allocate spend across seat-based and usage-based licensing G Licensing cost management | devops-lead | Governance — stories about governance in this arenaGovernance | 1 | partial | 6/10 | Cclaimed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | partial | 5/10 | Cclaimed | |
Require automated change approval workflows before code reaches production C Policy enforcement | devops-lead | Governance — stories about governance in this arenaGovernance | 1 | partial | 4/10 | Cclaimed | |
Connect the platform to external CI/CD tools instead of using its native pipelines C External ci cd integration | devops-lead | Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations | 1 | none | 0/10 | ||
Install third-party security scanning integrations directly from a security tab C Security tool integrations | devops-lead | Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations | 1 | none | 0/10 | ||
Manage external issue tracker items directly within the code hosting UI C External pm sync | developer | Project planning — stories about project planning in this arenaProject planning | 1 | none | untested | none yet | |
Manage projects and assign tasks from my mobile device C Issue tracking | developer | Project planning — stories about project planning in this arenaProject planning | 1 | none | untested | none yet | |
Map incidents to deployments and require change approval before releases C Deployment | devops-lead | Ci cd — continuous integration and delivery — pipelines, runners, cachingCi cd | 1 | none | untested | none yet | |
Sync repository notifications and activity with chat tools C Chat notifications | developer | Ecosystem integrations — the surrounding ecosystem — integrations, marketplaces, community packagesEcosystem integrations | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 48 stories with headroom
What would move GitLab’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
Missing: documentation of adding/registering external MCP servers as tool sources for GitLab Duo agents, any UI/config for MCP server URLs within Agent Platform, and independent confirmation that GitLab agents can invoke tools from arbitrary MCP servers.
Project planning — stories about project planning in this arenaTrack requirements, features, and bugs using issues with milestones, time tracking, and dependencies
nonemoves PA Scoreimpact 30
Missing: any docs or community evidence on issue creation, milestone planning, time tracking, or linking blocking/dependent issues.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence pack item addresses opting out of AI model training on user data, data usage policies for Duo/AI features, or any privacy controls specific to training-data exclusion; the AI governance items ([gitlab-docs-44], [gitlab-docs-45]) cover tool permissions and monitoring, not training data usage.
Security — security posture and hardening storiesSecure my account with two-factor authentication
nonemoves PA Scoreimpact 30
Missing: any documentation of 2FA/MFA enrollment, enforcement policies, or authenticator app support.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
The evidence pack covers REST API, personal access tokens, SSH keys, MCP server, and CLI, but contains no mention of webhooks or event subscription mechanisms anywhere.
Ci cd — continuous integration and delivery — pipelines, runners, cachingRun CI/CD jobs on runners hosted by the platform without managing infrastructure
partialq3/10moves PA Scoreimpact 21
Missing: explicit documentation of GitLab.com shared/hosted runners, runner autoscaling, and infra-free operation, plus independent confirmation it works reliably.
Ci cd — continuous integration and delivery — pipelines, runners, cachingDefine CI/CD pipelines as code using a YAML syntax
partialq3/10moves PA Scoreimpact 21
Missing: explicit mention of .gitlab-ci.yml YAML pipeline definition, pipeline syntax examples, and independent corroboration of YAML-as-code CI/CD authoring.
Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows
nonemoves PA Scoreimpact 20
The evidence pack covers CI/CD, agent flows, and API automation broadly, but nothing explicitly documents recurring/scheduled job triggers (e.g., pipeline schedules, cron-based automation, or recurring agent flow runs) for AI-native users.
Showing the top 8 of 48 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map10 surfaces · 50 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
User docs24 stories
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Issue scoped/least-privilege API credentials for an agent
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Version, review, and roll back my automations
- Automate application deployments as part of my CI/CD pipeline
- Reuse community-built CI/CD actions or plugins in my pipelines
- Get centralized visibility into CI/CD workflow runs across the organization
- Extend my stack with third-party apps, actions, and AI models from a marketplace
- Require automated change approval workflows before code reaches production
- Enforce coding standards and CI/CD policies across all teams and repositories
- Do everything through the API that I can do in the UI
- Have an AI reviewer analyze code changes and suggest fixes during review
- Assign the initial code review of a pull request to an AI reviewer for faster turnaround
- Review code changes online and respond to inline review comments
- Search across repositories to find code, files, and commits
- Create and manage Git repositories and browse their commit history
- Propose, discuss, and merge code changes using a pull or merge request workflow
- Have AI automatically generate and apply fixes for detected security vulnerabilities
about.gitlab.com21 stories
- Get AI-generated insights and suggestions from my data inside the product
- Set up automations that run autonomously in the background
- Delegate tasks to a built-in AI assistant inside the product
- Operate the product with natural-language commands
- Automate application deployments as part of my CI/CD pipeline
- Define CI/CD pipelines as code using a YAML syntax
- Get centralized visibility into CI/CD workflow runs across the organization
- Make a single annual commitment and flexibly allocate spend across seat-based and usage-based licensing
- Require automated change approval workflows before code reaches production
- Enforce coding standards and CI/CD policies across all teams and repositories
- Choose where my data is stored (region/residency)
- Have an AI reviewer analyze code changes and suggest fixes during review
- Assign the initial code review of a pull request to an AI reviewer for faster turnaround
- Review code changes online and respond to inline review comments
- Review large diffs and view third-party code quality reports directly in the review screen
- Enforce standardized, customizable merge checks before code can be merged
- Propose, discuss, and merge code changes using a pull or merge request workflow
- Have AI automatically generate and apply fixes for detected security vulnerabilities
- Automatically receive pull requests that update vulnerable dependencies
- Consolidate static analysis, dependency, secret, and dynamic security scanning into one platform
- Detect and remediate leaked secrets across the organization's repositories
docs.gitlab.com21 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Define rules that trigger actions automatically on events
- Automate application deployments as part of my CI/CD pipeline
- Define CI/CD pipelines as code using a YAML syntax
- Run CI/CD jobs on runners hosted by the platform without managing infrastructure
- Access built-in resources to learn the Git version control system
- Export all of my data in open formats and leave
- Self-host the core product
- Choose where my data is stored (region/residency)
- Control granular access permissions at the workspace, project, repository, and branch level
- Create and manage Git repositories and browse their commit history
- Generate and manage personal access tokens for authenticating to the platform
- Set up SSH keys to authenticate and connect securely to the platform
- Run my self-hosted instance on my choice of operating system and architecture, including containers
- Scale my self-hosted installation using reference architectures supporting tens of thousands of users
- Use migration tooling to move my code and users from another platform or from self-hosted to cloud
- Install a self-managed instance of the platform without laborious configuration
API reference16 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Explore an interactive API reference with runnable examples
- Download a machine-readable API spec (OpenAPI or equivalent)
- Rely on versioned APIs with a documented deprecation policy
- Perform bulk operations across many items at once
- Automate application deployments as part of my CI/CD pipeline
- Define CI/CD pipelines as code using a YAML syntax
- Get centralized visibility into CI/CD workflow runs across the organization
- Enforce coding standards and CI/CD policies across all teams and repositories
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Control granular access permissions at the workspace, project, repository, and branch level
- Generate and manage personal access tokens for authenticating to the platform
Partners docs10 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Automate application deployments as part of my CI/CD pipeline
- Reuse community-built CI/CD actions or plugins in my pipelines
- Extend my stack with third-party apps, actions, and AI models from a marketplace
- Have an AI reviewer analyze code changes and suggest fixes during review
- Assign the initial code review of a pull request to an AI reviewer for faster turnaround
- Review code changes online and respond to inline review comments
- Propose, discuss, and merge code changes using a pull or merge request workflow
- Use migration tooling to move my code and users from another platform or from self-hosted to cloud
Hacker News7 stories
- Run CI/CD jobs on runners hosted by the platform without managing infrastructure
- Export all of my data in open formats and leave
- Self-host the core product
- Create and manage Git repositories and browse their commit history
- Propose, discuss, and merge code changes using a pull or merge request workflow
- Scale my self-hosted installation using reference architectures supporting tens of thousands of users
- Use migration tooling to move my code and users from another platform or from self-hosted to cloud
gitlab.com6 stories
- Get centralized visibility into CI/CD workflow runs across the organization
- Require automated change approval workflows before code reaches production
- Enforce coding standards and CI/CD policies across all teams and repositories
- Enforce standardized, customizable merge checks before code can be merged
- Have AI automatically generate and apply fixes for detected security vulnerabilities
- Consolidate static analysis, dependency, secret, and dynamic security scanning into one platform
Editor_extensions docs2 stories
Orbit docs2 stories
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
1 of 11 testable claims verified · 0 contradicted → integrity 9/100
13 distinct capability claims found in GitLab’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
1
Verified
10
Unverified
0
Contradicted
39
Undersold
Verified (1)
“Provides recommended reference configurations to scale self-hosted installations”
Scale my self-hosted installation using reference architectures supporting tens of thousands of userspartialproof ↗
Unverified (10)
“AI agents can convert issues into merge requests automatically”
Set up automations that run autonomously in the backgroundfullproof ↗
“AI agents can automatically remediate detected vulnerabilities”
Have AI automatically generate and apply fixes for detected security vulnerabilitiespartialproof ↗
“AI agents can review code changes while humans stay in control”
Have an AI reviewer analyze code changes and suggest fixes during reviewfullproof ↗
“Combines SAST, SCA, secret detection, and DAST scanners into a single platform”
Consolidate static analysis, dependency, secret, and dynamic security scanning into one platformfullproof ↗
“Customers can make one annual commitment and flexibly allocate spend across seat-based and usage-based licensing without re-procurement”
Make a single annual commitment and flexibly allocate spend across seat-based and usage-based licensingpartialproof ↗
“Supports personal access tokens for authenticating to the platform”
Generate and manage personal access tokens for authenticating to the platformfullproof ↗
“Supports SSH keys for secure authentication”
Set up SSH keys to authenticate and connect securely to the platformfullproof ↗
“Provides built-in resources for learning the Git version control system”
Access built-in resources to learn the Git version control systemfullproof ↗
“Linux package installs GitLab with minimal manual configuration”
Install a self-managed instance of the platform without laborious configurationfullproof ↗
“Can be interacted with programmatically via an API”
Drive the product through a documented public APIfullproof ↗
Undersold (39)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Issue scoped/least-privilege API credentials for an agentpartialproof ↗
Get AI-generated insights and suggestions from my data inside the productfullproof ↗
Delegate tasks to a built-in AI assistant inside the productfullproof ↗
Operate the product with natural-language commandsfullproof ↗
Explore an interactive API reference with runnable examplesfullproof ↗
Download a machine-readable API spec (OpenAPI or equivalent)fullproof ↗
Rely on versioned APIs with a documented deprecation policyfullproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Automate application deployments as part of my CI/CD pipelinefullproof ↗
Reuse community-built CI/CD actions or plugins in my pipelinespartialproof ↗
Define CI/CD pipelines as code using a YAML syntaxpartialproof ↗
Run CI/CD jobs on runners hosted by the platform without managing infrastructurepartialproof ↗
Get centralized visibility into CI/CD workflow runs across the organizationpartialproof ↗
Extend my stack with third-party apps, actions, and AI models from a marketplacefullproof ↗
Require automated change approval workflows before code reaches productionpartialproof ↗
Enforce coding standards and CI/CD policies across all teams and repositoriesfullproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Choose where my data is stored (region/residency)partialproof ↗
Assign the initial code review of a pull request to an AI reviewer for faster turnaroundpartialproof ↗
Review code changes online and respond to inline review commentspartialproof ↗
Review large diffs and view third-party code quality reports directly in the review screenpartialproof ↗
Enforce standardized, customizable merge checks before code can be mergedpartialproof ↗
Control granular access permissions at the workspace, project, repository, and branch levelpartialproof ↗
Search across repositories to find code, files, and commitspartialproof ↗
Create and manage Git repositories and browse their commit historyfullproof ↗
Propose, discuss, and merge code changes using a pull or merge request workflowfullproof ↗
Automatically receive pull requests that update vulnerable dependenciespartialproof ↗
Detect and remediate leaked secrets across the organization's repositoriespartialproof ↗
Run my self-hosted instance on my choice of operating system and architecture, including containerspartialproof ↗
Use migration tooling to move my code and users from another platform or from self-hosted to cloudpartialproof ↗
Claims outside our story set (2)
Real capability claims found in GitLab’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Security findings are surfaced directly inside merge requests and IDEs”
source ↗“Provides tools to build and test applications as part of CI/CD”
source ↗
Business model
Free tier plus per-seat Premium/Ultimate subscriptions (Ultimate now custom-quoted), with usage-based CI/CD compute-minute overage billing.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt 100% (30d, checked every 6h since Sep 8 '26)
