Playbook: developers
Engineering workflows for coding assistants: generate, explain, test, and review—without skipping security or ownership.
What it is
Engineering workflows for coding assistants: generate, explain, test, and review—without skipping security or ownership.
Why it matters
AI-written code can be plausible and wrong. You still own bugs, licenses, and secrets.
How it works (plain)
May draft: boilerplate, tests, refactors, docs, SQL drafts for review. Must human: authz changes, crypto, payments, production data access, dependency trust. Verify: run tests; read diffs; check licenses; never paste secrets.
Everyday example
Assistant drafts a function; you write/adjust tests first or immediately after and watch them fail/pass.
Try it
Enable an assistant on a toy repo. Require tests for every generated function this week.
Myths
- ⚠️ Myth: If it compiles, it’s done.
- ✓ Reality: Correctness, security, and maintainability remain human duties.
Sources
- Course 21 Python labs; Course 19 security; OWASP LLM Top 10
- Provider coding-assistant ToS (cite yours)
