Epsilon AI Assistant
Claude inside Azure DevOps. On every pull request it does a deep code review: not just the diff, but the whole
repository, explored with Serena and the C# language server — callers, implementations, DI registrations,
architecture violations — and the findings are posted as comments on the lines of the PR. From a work item it can
also propose an implementation plan and, once a human approves it, implement the task on a feature branch, build it,
run the tests and open a pull request. Everything runs in containers on your own Linux agent, the model never sees an
Azure DevOps token, and nothing is merged without a human.
AI Review (pull requests)
Runs on pull request builds, and on demand from the pull request's ⋯ menu → AI Review. Existing findings are not
posted twice; findings that look fixed are closed.
Setup per team
- Service connection (Project Settings → Service connections → New → Epsilon AI Assistant: Microsoft Foundry):
resource URL
https://<resource>.services.ai.azure.com, model deployment, API key.
For trials you can instead set Model authentication = oauth on the task and put a claude setup-token token in
a secret pipeline variable CLAUDE_CODE_OAUTH_TOKEN (it consumes that person's Claude subscription limits).
- Pipeline (Classic or YAML) for the repository, on a Linux agent with Docker:
- checkout with full history (no shallow fetch), Clean = true,
- add the task Epsilon AI Review and select the connection,
- job timeout at least the review timeout + 45 minutes,
- for the ⋯ menu: name the pipeline
AI Review … and add the queue-time variable AIReview.PullRequestId.
- Build Service permissions: Contribute to pull requests on the repository, Feed Reader on private feeds.
- Branch policy on the target branch: Build Validation → this pipeline, Automatic (or Manual, to review only
when someone asks), Optional.
YAML example:
steps:
- checkout: self
fetchDepth: 0
- task: AIReview@1
inputs:
foundryConnection: my-foundry
AI Implement (work items)
From a work item's ⋯ menu → AI Implement:
- Plan with AI — Claude reads the repository and posts an implementation plan as a work item comment.
- Read the plan; correct it with a comment if needed (comments after the plan override it).
- Approve & Implement — Claude implements the plan, builds and tests it (up to 2 fix attempts), pushes
feature/ai/<id>-<title> and opens a pull request (draft if build/tests fail). Nothing is merged automatically.
Setup per repository: a pipeline named AI Implement … with the task Epsilon AI Implement, the
queue-time variables AIImplement.Mode and AIImplement.WorkItemId, no shallow fetch, Clean = true, and for the
Build Service: Create branch, Contribute, Contribute to pull requests, Edit work items in the area path.
Security
The review (LLM) step runs in its own container without any Azure DevOps token. Only the steps that read the PR,
restore packages and publish comments get the build token, and those steps never run the model.
AI Implement: the steps that run code the AI wrote (implement, verify, guard) get no Azure DevOps token and a
read-only package cache, and shell commands of the agent run without the model credentials. The push step re-checks
the commit in a clean git directory (single commit on the base, no pipeline YAML or other protected paths, no
secrets) before pushing it; changes that make MSBuild run code keep the pull request a draft.