Wain AI/Tech Blog

AI news and trends worldwide, updated nearly every day

Cursor Releases Two Bots for the Work After the PR: Rollouts and Security Review

Cursor Releases Two Bots for the Work After the PR: Rollouts and Security Review

On September 23, 2026, Cursor released Rollouts, which monitors deploys, and Security Review, which reports vulnerabilities on every PR. Both ship on Teams and Enterprise. Cursor says Rollouts is a rebuild of the Change Monitors from Firetiger, which joined the company in August.

Cursor, the AI coding tool, released two bots on September 23, 2026 that take on the stretch of work that begins once a pull request is open. Rollouts keeps an eye on changes after they deploy, and Security Review attaches a vulnerability review to every PR. Both became available the same day on the Teams and Enterprise plans 1. Either one is turned on from the automations tab in the dashboard.

Cursor frames the pair as bots for the last stretch of getting code into production 2. Its blog argues that writing code is no longer where the time goes, and that what has not sped up is the work after the PR is filed: confirming the code is safe, sitting with the deploy, deciding whether a jump in latency means anything, and working out which of several changes took down checkout 1.

Rollouts writes a monitoring plan at PR time, then checks it after the deploy

As soon as a PR is opened, Rollouts goes through the diff, works out which systems it reaches into, and leaves a monitoring plan in the PR thread. The plan sets out the risks it spotted, the effect the change is supposed to produce, the signals it intends to watch, and the places where thin instrumentation would make verification hard. Edit the plan on the PR and Rollouts follows the edited version 2. Only people holding write access to the repository may change it 3.

Once a deploy event arrives, Rollouts runs the plan for that commit against logs, metrics and traces. Because each environment is tracked on its own, a change can come out verified in staging and still be flagged in production. The verdicts are “verified healthy,” “regression detected” and “inconclusive,” and the result is posted back to the PR once one is reached 2. Per the documentation, checks happen right after the deploy and then again at 20 minutes, 1 hour, 1 day and 3 days 3.

When a regression turns up, Rollouts identifies which change it holds responsible and lets the author know. Per the changelog, configuration decides what follows: a revert PR raised for approval, or the finding handed off to a cloud agent for repair. What it does not do today is merge or roll back by itself 2.

For source control it connects to Origin or GitHub, for deploy events to whatever continuous delivery system is in use, and for signals to telemetry providers, Datadog among them. Feature flag integration is described as coming soon. The documentation also lists GitLab.com and Bitbucket Cloud among the repositories it can watch 3.

What decides whether this is usable is less about running Cursor and more about whether deploy events and a monitoring stack can be handed over. The documentation is explicit that without at least one observability tool connected, changes sit in a pending state and Rollouts cannot detect problems. Up to 200 repositories can be watched, and anything that cannot alter what actually runs is skipped by default: docs-only edits, formatting, lint, typo corrections that leave behavior alone, and changes confined to tests 3.

Security Review takes the vulnerabilities, while Bugbot keeps style and quality

Security Review goes through each PR with the rest of the codebase in view and files a single review comment listing exploitable bugs. Style and quality reviews stay where they were, with Bugbot, so the two divide the work. It is enabled per repository, and draft PRs are passed over 2.

Six areas are listed as covered out of the box, among them injection by way of SQL, commands, templates and LDAP; authentication and authorization that is absent or broken on routes that are new or have changed; and unsafe defaults in infrastructure and configuration 1. Cursor’s stated contrast with static analysis is that pattern matching cannot follow where user input enters, where it ends up, and what it passes through along the way.

Every finding arrives with a severity rating, the path an attacker would take, and a suggested fix. Turn one down with a reason attached and it will not come back on that PR. Teams can also add rules specific to their codebase — the client that external calls have to route through, the tables that a request handler must never touch — and have them enforced on every PR.

One wrinkle: the naming is not consistent within Cursor’s own material. The changelog uses “Security Review” in its headings and through most of its text, switching to “Security Reviewer” only in the closing instructions. The blog carries “Security Review” in its article title while the table of contents, the opening summary, the section heading and the closing instructions say “Security Reviewer,” and both forms turn up in its body text.

Firetiger, which joined in August, resurfaces under a new product name

Cursor states plainly that Rollouts is its rebuild of Firetiger’s “Change Monitors,” done with the Bot Development Kit 2. Firetiger built agents that watched software once it reached production and fed what they learned back to coding agents, and its move into Cursor was announced in August. What was known then stopped at the shutdown of Firetiger as a standalone product and the notice to existing customers about data deletion; nothing had been said about what Cursor would ship in its place. That answer now has a name and a described behavior.

The code review side has been building up since the Graphite acquisition in December 2025, and a security-specific bot now joins it. In the sense of running continuously without being asked, both bots point the same direction as the coordinator agent in Projects, which went into beta on September 10.

None of the three documents mentions price or billing units; what they establish is the availability range, Teams and Enterprise. Projects came without pricing details as well. Individual plans are outside the scope as of today. For Rollouts, usage credits for trying it on real changes are included for 10 days after launch, roughly 50 changes’ worth for Teams and 500 for Enterprise 2.

The strengths Cursor names are three: catching a regression that stays inside one endpoint in one region, ahead of any alert firing globally; telling a deliberate effect apart from a regression, so an intended spike wakes nobody; and calling out gaps in instrumentation while the change is still unmerged. All three are the company’s own account 1. Anyone weighing adoption would start by checking whether their telemetry is in a shape that can be handed to Rollouts.

Sources

  1. Bots for the last mile: Rollouts, Security Review - Cursor official blog (September 23, 2026)
  2. Rollouts and Security Review - Cursor official changelog (September 23, 2026)
  3. Rollouts - Cursor official documentation (accessed September 25, 2026)

We publish the latest AI news nearly every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →