TLDR overview
- Sonar builds code quality and security tools because Sonar engineers rely on it every day. Quentin Chevrin, a front-end developer in Sonar's billing squad, barely writes code by hand anymore, and the verification layer is what lets him commit with confidence.
- As generation gets cheaper, the bottleneck moves to review. Quentin's time split shifted from roughly 90%writing and 10%reviewing to closer to 60/40, while his squad doubled from four to eight people.
- Every pull request passes three checks: SonarQube analysis for how the code is written, Gitar for whether the change is correct and fits the product, then a human reviewer. Each layer catches a different failure mode.
- AI still falls short on design review, handing specification work to an agent costs you the mental model you need later, and test files now dominate his pull requests.
Verification is mandatory in the agentic era. Here is what that looks like inside Sonar.
In episode 4 of The Next Commit, Sonar's podcast on how developers actually work with AI, host Tom Howlett sat down with Quentin Chevrin, a front-end developer on the billing squad. Quentin calls himself a late adopter, skeptical of every new framework that arrives. About a year ago he started with GitHub Copilot next-line suggestions in VS Code, mostly to write the unit tests he had always hated writing.
Today, Quentin barely opens his IDE. He runs Claude Code in the terminal with the Sonar CLI, plus MCP servers and plugins for Playwright, Chrome DevTools, and Figma. How he works now says something quite profound about where AI-assisted development is heading.
How has AI shifted the code review bottleneck for dev teams?
Before AI, a simple feature took Quentin three to four days. A larger one could fill a two-week sprint. On the day of the recording, he had opened four pull requests by 5 p.m.
Generation stopped being the hard part. The constraint moved:
- His time split went from about 90% writing and 10% reviewing to closer to 60/40.
- The billing squad grew from four to eight people, and pull request volume climbed with it.
- Paul, a new intern, halved CI build time within two weeks of joining.
When code is cheap to produce, the human reviewer becomes the bottleneck. Quentin's squad hit that wall directly. The answer is not to lower the bar on what gets merged, it’s to make verification automated, multilayered, and fast enough to keep the pipeline moving.
Three layers of AI code review before a human sees the pull request
Quentin's workflow never lets the AI that wrote the code sign off on its own work.
His repository-level CLAUDE.md files spell out the verification steps the agent must complete before a task counts as done: run the tests, run the linter, run a SonarQube analysis. His personal home-directory CLAUDE.md wires the Sonar CLI into every repository he touches, so generated code gets analyzed even in a repo that is not configured for it. And he instructs the agent never to commit. He does that himself, from the command line, so he sees which files changed.
Every pull request then passes three checks:
- SonarQube analysis examines how the code is written: bugs, security vulnerabilities, missed best practices.
- Gitar reviews the change end to end: security, bugs, performance, edge cases, and the logic and intent behind the change, including whether the feature fits the product and what it breaks elsewhere.
- A human reviewer looks last.

Each layer serves a distinct purpose, catching what the others might miss. Quentin illustrates this with a simple example: a specific button element is placed on the Teams plan page, despite every comparable add-on being housed on the Enterprise page. SonarQube analysis sees a valid HTML element with the right accessibility properties. Gitar sees a button in the wrong place.
"It's a kind of different feedback that I get from both tools. And I want to make sure that both feedback tools are happy."
Deterministic analysis and reasoning-based review answer different questions. Neither one catches everything on its own. Together they catch considerably more, and they do it before a developer spends an afternoon fixing issues. That is the Verify stage of Sonar's Agent Centric Development Cycle (AC/DC) framework, applied to our own repositories.
Where AI coding agents still fall short in development workflows
Design review is the clearest gap. Giving an agent enough context to review a Figma design is slow and expensive in tokens, and the work depends on back and forth with the PM, the designer, and the back-end engineers. Quentin is still faster at review than the agent is.
Token cost shapes the setup elsewhere, too. One of his CLAUDE.md instructions forbids reading messages.json in full, because doing so would cost around $20 in tokens. The agent uses grep and sed instead.
Then there is comprehension debt. Quentin writes his own Jira tickets on purpose, even though the agent writes good ones.
"They might even be better than the ones I wrote. But then I'm lost as to what should be done, because I haven't really done that work myself."
Decomposing the work is what builds the mental model he needs to steer the agent later. His back-end colleagues generate their tickets with AI, and sometimes finish a feature with one ticket still sitting in To Do that nobody can account for. Quentin compares it to assembling furniture and finding a few screws left over.
The test files have grown accordingly. His pull requests shifted from roughly 80 percent code and 20 percent tests to 40 percent code and 60 percent tests, and he does not review the test files closely. He is candid that this is a tradeoff he has accepted rather than solved.
How do developers stay in control when using AI coding agents?
Code bloat comes from insufficient constraints, not from AI itself. That principle shapes how Quentin works.
He treats the agent like a junior developer—start precise, widen the scope gradually, find the right level of detail through trial and error. He keeps context small by starting a fresh session for each small commit rather than running one long session. And he calibrates scope by blast radius:
- Tight, one-prompt-per-commit control on the SonarQube Cloud web app, a large codebase shared across teams and used by a lot of people.
- Wider scope on the internal billing back office, which has a few dozen internal users and a direct feedback loop to them.
He steers actively rather than running 10 parallel sessions, watching what the agent does and stopping it when it heads the wrong way. Scoping, steering, and deciding what good looks like stay with the human.
The upside is range. Quentin used to refuse to touch the back end or infrastructure, on principle. Now he makes small API changes, debugs CI failures, and queries CloudWatch logs in AWS. He can read another squad's repository before asking them questions, which makes the conversation shorter. He describes the result as becoming a T-shaped engineer for the first time in his career.
His advice is practical. Ask the agent questions, not just implementation tasks, because it is very good at explaining a codebase. And put a real review process in place, so people can move boldly without putting production at risk.
"It does all the things I hated doing. And I can just design software in my head. I just do what I enjoy and I give what I don't enjoy to AI."
Listen to the episode
Quentin's workflow is one squad's answer: multilayered checks, deterministic analysis first, and an agent that never signs off on its own work. It's also the driving force behind everything we create at Sonar.
Hear the full conversation in episode 4 of The Next Commit, Sonar's podcast on how developers actually work with AI.

