Journal/Engineering

Our review checklist for AI-generated pull requests

Twelve questions every change answers before it’s merged, whoever or whatever wrote it.

AI coding tools changed how fast code gets written. They didn’t change who is responsible for it. At Sampan Labs, a human engineer reviews every pull request, and their name goes on the merge. This is the checklist they use.

Understanding

  1. Can the reviewer explain what this change does, line by line?
  2. Does it follow the patterns already in the codebase, or invent new ones?
  3. Is there anything clever that should be boring?

Correctness

  1. Are there tests, and do they test behaviour rather than implementation?
  2. Have edge cases been considered: empty lists, time zones, currency rounding, duplicate submissions?
  3. Does it handle failure: network errors, timeouts, partial writes?

Security & data

  1. Is all user input validated on the server?
  2. Are permissions checked for every new endpoint?
  3. Is personal data kept out of logs, URLs and error messages?
  4. Are any new dependencies maintained, licensed suitably and actually needed?

Maintainability

  1. Would a new team member understand this in six months?
  2. Is anything here that we would be embarrassed to hand over to a client?
What we noticedAI-generated code tends to be confidently verbose. It adds defensive checks that hide real bugs, and it invents helper functions that already exist elsewhere in the codebase. The second question under Understanding catches more issues than any other.

Is this slower than accepting whatever the tool suggests? A little. It’s much faster than debugging code nobody understands in production.

EngineeringSampan Labs Journal
All articles
Written by Arjun Nair

Co-founder & Engineering Lead. Former platform engineer at a regional logistics company. Owns our engineering standards and the AI review checklist.

Have an idea?
Let's ship it.

Tell us what you're building. A real person replies within one business day, Singapore time.