Vibe coding is over. Now AI keeps an eye on whether it has broken production. This is more than a catchy headline: it’s the reality Cursor is offering with its new Rollouts and Security Review bots. In this article, we’ll look at how these tools change the familiar development cycle, what they do after code is written and deployed, and where the human role remains essential. You’ll learn how Rollouts monitors changes in production and how Security Review identifies vulnerabilities in pull requests—and be able to assess whether this approach is right for your team.
How does Rollouts check a change after deployment?
According to Rollouts and Security Review · Cursor, Cursor introduced two new bots, Rollouts and Security Review, designed to automate the “last mile” of shipping code. Rollouts’ main job is to monitor each change as it’s deployed and report its status in each environment. That means once your code has been sent to production or staging, Rollouts takes on the role of a watchful observer, providing feedback on how “healthy” the change is.
While Rollouts focuses on post-deployment monitoring, Security Review serves a different but equally important purpose. This bot reports exploitable bugs in every pull request. It reads each pull request in the context of the entire codebase, allowing it to understand potential vulnerabilities in depth. Security Review doesn’t just look for syntax errors or style violations—other tools, such as Bugbot, handle those, according to Cursor’s official announcements. Its focus is on real security issues that attackers could exploit.
For developers and technical leads, this represents a significant shift in how quality and security are managed. Instead of manually checking logs and metrics after every deployment, teams can rely on automated Rollouts reports. This frees up time and helps them respond to potential issues faster. Integrated into the pull request review process, Security Review adds another layer of protection by identifying critical vulnerabilities before code is merged into the main branch. It even tracks where user input enters the system and the stages it passes through—an essential capability for detecting injection attacks and other threats.
Consider a typical scenario: you submit a pull request for a new feature. Security Review analyzes it right away, taking the context of the entire project into account, and leaves a comment if it finds a potential vulnerability. After the code is successfully merged and deployed, Rollouts gets to work, closely monitoring how the change behaves in a real environment. If anomalies arise, you receive a status report so you can act quickly. This doesn’t replace human oversight, but it significantly expands what people can monitor.
Use cases
- Automated deployment monitoring: DevOps and SRE teams can use Rollouts to receive automatic reports on the status of new deployments, reducing the burden of manual monitoring and speeding up issue detection.
- Faster CI/CD cycles: Integrating Security Review into the CI/CD pipeline makes it possible to automatically check every pull request for vulnerabilities, speeding up reviews and improving overall code security.
- Preventing critical incidents: By identifying exploitable bugs before code is merged, Security Review helps keep critical vulnerabilities out of production, reducing the risk of serious incidents and financial losses.
- Tracing user input: Developers can use Security Review’s ability to track the path of user input to better understand potential vulnerabilities and strengthen defenses against injection attacks.
- Assessing the impact of changes: Rollouts provides quick feedback on how a new change affects system health across different environments, which is essential for making informed decisions about whether to proceed or roll back.
- Improving code quality: While Bugbot handles style, Security Review focuses on functional security, complementing the broader effort to improve code quality and make it more resilient to attacks.
- Reducing time spent on manual reviews: Automatically checking PRs for security issues cuts down on the time developers spend manually searching for vulnerabilities, allowing them to focus on more complex design and development tasks.
- Centralized security oversight: Working together, the two bots provide a more complete picture of code security and stability at different stages of the development lifecycle, from PR to production.
What happens if a check finds a problem?
If one of Cursor’s bots finds a problem, it’s important to understand the limits of their automation. According to the available confirmed information, Cursor announced the launch of Rollouts and Security Review, as described in Rollouts and Security Review · Cursor. However, the provided sources do not confirm that Rollouts can create a revert PR on its own, hand off a task to a cloud agent for a fix, or roll back production entirely. This is a key distinction between the tools’ current capabilities and potential future scenarios.
For now, Rollouts monitors changes during deployment and reports their status in each environment. Security Review, in turn, reports exploitable bugs in pull requests. These bots are powerful tools for detection and reporting, but they are not fully autonomous agents that can make critical decisions and take actions affecting production systems without human involvement. Any fixes, such as rolling back code or making changes, remain the responsibility of the development or DevOps team.
For teams, this means that despite advanced automation for monitoring and security checks, people remain in control and make the final decisions. Cursor’s tools make it much easier to identify problems, but they don’t eliminate the need for human intervention to assess the situation, confirm the issue, and choose the best way to resolve it. This helps ensure safety and predictability by preventing unwanted or mistaken automated actions in critical systems. In other words, Cursor’s bots augment the team; they don’t replace it.
As for availability, the provided sources don’t establish whether these features are available on the Teams and Enterprise plans, nor do they confirm the terms of any trial credits, such as their amount or expiration date. Any claims about trial access or pricing plans therefore require further confirmation.
Frequently asked questions
What signals does Rollouts analyze after deployment?
Rollouts monitors each change during deployment and reports its status in each environment. However, the provided information doesn’t specify which signals—such as logs, metrics, or traces—it analyzes to determine that status. Its purpose is to provide an overall assessment of deployment health.
What does the inconclusive status mean, and how is it different from regression?
The materials provided don’t specify the exact meanings of the “healthy,” “regression,” or “inconclusive” statuses that Rollouts may report. They also don’t explain the difference between “inconclusive” and “regression.” All that’s known is that Rollouts reports the overall “health” of a change after deployment.
Can Rollouts roll back production on its own?
No. According to the information provided, Rollouts can’t roll back production on its own. The materials don’t confirm that it can create a revert PR or hand off an issue to a cloud agent for a fix. Its role is to monitor changes and report their status.
What vulnerabilities does Security Review look for besides SQL injection?
Security Review looks for a broad range of vulnerabilities. Specifically, it checks for SQL, command, and template injection; authentication and authorization bypasses; and secrets and credentials in source code. It also detects SSRF, unvalidated redirects, insecure deserialization, and vulnerabilities related to dependency changes.
How long do Teams and Enterprise trial credits last, and how many changes do they cover?
The provided sources don’t confirm the terms of trial access, such as how long trial credits last or how many are included with Teams and Enterprise plans. All that’s known is that Cursor launched the Rollouts and Security Review bots.

