(All Remote)– GitLab Inc., the intelligent orchestration platform for DevSecOps, today released GitLab 19.4. As agentic automation spreads from individual developers to entire engineering teams, what limits its reach is no longer what agents can do but how confidently an organization can extend it. GitLab 19.4 brings agentic automation to every surface developers work in, with new options for cost efficiency and the control platform owners need to scale it.

Developers can now delegate a whole objective from the terminal, run flows the moment a merge request opens, and reach GitLab from any Model Context Protocol (MCP) client through a governed set of tools. Platform owners get the tool-level controls and the per-person attribution to widen access to that automation and account for how it is used.

Both come from the platform already running the work. The same permissions that cover the code govern the agents, and every credit traces to the user account that spent it, so there is no second permission model and no separate audit trail.

The /goal Command Turns an Open-Ended Objective Into Verified Work

AI agents have handled individual tasks well, but developers have still had to break the work into those tasks and check each result. Handing over an objective to agents also meant no independent check on their judgment.

The /goal slash command in GitLab Duo CLI automates a whole objective until it’s done or reports what it could not resolve, with project guardrails and context. The agent implements the work, and a separate model verifies it against the stated goal at each step, deciding whether the goal is met or the iteration limit is hit. The developer can stop the run at any point, then revise the goal and restart, and the flow runs locally under the organization’s existing rules. A developer can hand off a bounded piece of work and come back to a verified result.

New GitLab-Hosted Open Weight Models Add a Cost and Performance Lever to Every Workload

No single model fits every task. GitLab Duo Agent Platform now offers three GitLab-hosted open weight models, Kimi K3, MiniMax M3, and GLM 5.3, alongside the frontier models already available, giving teams more flexibility to choose the model best suited to each agentic automation workload. By selecting models based on task requirements, teams can balance quality, latency, and cost. The new hosted open weight models in GitLab Duo Agent Platform get up to 4x more calls per GitLab Credit than many comparable frontier models, giving teams more model options to match cost to task complexity.

Group owners retain the same governance over model choice as every other GitLab Duo Agent Platform capability. They can set a default model for each feature and curate the models available to teams, with those settings applying across child groups and projects. GitLab evaluates each model against internal performance and quality standards, and vets every hosting vendor through its third-party risk management process, helping teams expand model choice without giving up administrative control.

New MCP Tools Expand the Automation Surface, Governed From Day One

An agent working in a client outside GitLab can now carry a piece of work through GitLab from end to end, without a person moving it between tools. New tools in the GitLab MCP server let it automate work across GitLab, triggering a pipeline and reading the trace of a failed job, running a merge request from opening through review to merge, searching and updating work items, and triaging vulnerabilities.

Administrators govern those tools with the rules they already set for GitLab Duo Agent Platform, configured in the same group and project settings. Read-only tools default to Always Allow, so routine lookups proceed without interrupting the team, and write and delete tools default to Always Ask, giving reviewers a checkpoint before an agent changes anything. Teams can now adopt third-party agents without maintaining a separate set of rules for them.

Usage Visibility Lets Platform Owners Widen Access to Automation

A platform owner can now show each department how it is using the organization’s capacity for agentic automation, without waiting for an invoice. Per-user caps appear on a dedicated settings page, and usage exports go down to the billable event, arriving by email with a secure download link for both GitLab Flex and non-Flex subscriptions. Developers can also see their own consumption for the first time, so a team can manage its own pace.

Additional Capabilities Shipped in GitLab 19.4

GitLab Duo Agent Platform in Slack is now available as an experiment for Premium and Ultimate customers, letting engineering teams mention @GitLab in a thread to search GitLab, open an issue, or get answers about their projects, using the thread and recent channel history as context. This agentic flow runs on a CI/CD runner and posts the result back to the thread, turning a discussion into tracked work without leaving the conversation.

Model selection for the Developer Flow in Duo Agent Platform is now generally available, allowing administrators to choose a model for that flow independently of other GitLab Duo Agent Platform features and match it to the work the flow performs.

A redesigned session details panel is now available in 19.4, surfacing status, timestamps, and the triggering user in an overview bar. The panel also separates what started an agent session from what it produced, so a reviewer can account for an agent’s work without searching for it.

Community contributors through GitLab’s Co-Create program added new MCP server tools that let an agent read a project’s metadata and members, list a repository’s branches, list merge requests across a whole group, and fetch a GitLab Duo session to see what an earlier run did, as well as consolidate semantic search into one tool. Contributors also improved the merge request widget to explain its status in plain language and give a clear reason when a rebase fails, and added a preview that shows how a Markdown or AsciiDoc file will render before it is first committed.

To learn more, please read the what’s new page.

Supporting Quote

“This release takes agentic automation from something individual developers use to something an organization can scale at speed and under the controls already in place,” said Manav Khurana, chief product and marketing officer at GitLab. “The platform running the automation is what governs which tools an agent can touch and attributes what it consumes, so extending it to the next team is a measured decision rather than an open-ended risk.”

About GitLab

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and approximately 50% of the Fortune 100* trust GitLab to ship better, more secure software faster.

*Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab.

Media gallery

About The Author