Dufloth ia.br

EngineerYour development team using AI with a method

Your team can write code. Writing it with AI is a different skill.

For development teams that haven't adopted agents yet, or adopted them without agreeing anything: we build the flow inside your own repository — what the agent needs to know about the codebase, how big a change it may propose, what has to pass a human, and what refuses to merge. Implemented alongside your team, from a diagnosis with a fixed scope and a fixed deadline.

Get in touch 2 to 3 weeks · R$18,000 to R$35,000, fixed · half on signing

Who it's for

Development teams that haven't adopted coding agents yet, or adopted them without agreeing anything — usually a head of engineering or a CTO who can see the whole market using them and wants neither to fall behind nor to put the repository at risk.

The clearest sign you're in the right place: one or two people on the team use AI very well, everyone else is still typing, and nobody has written down what separates the two.

The problem

An agent handed to a team with nothing set up stays a faster autocomplete that nobody fully trusts. It has no idea which patterns this repo settled on, which module is load-bearing, or which of the three ways to do a thing here is the one you kept. So it picks plausibly, a reviewer waves it through because blocking it is unpopular, and the codebase gains a fourth way to do that thing.

The failure is not dramatic and that is the problem. Output goes up, everyone is pleased, and the cost lands one or two quarters later as a codebase nobody has a mental model of — including the model, which only ever sees a slice of it. By then the fast part is over and the expensive part has started.

What we do

We start with the repo and with where the team actually loses time, which is rarely where they think. Reading an unfamiliar module, writing the test nobody wants to write, the migration, the review queue — those are different problems and only some of them are an agent's job. The diagnosis has a fixed scope and a fixed deadline, and it ends in a written answer rather than a workshop.

Then we set the rails, and this is the whole of it: instructions that describe the codebase the agent is actually in, work split into pieces small enough that a human review is a real review rather than a rubber stamp, permissions that stop short of anything irreversible, and gates in the pipeline that refuse what breaks. Speed is allowed to go up. It is not allowed to route around the bar you already had.

Which means some of the work is not about agents at all. If the test suite does not tell you when something old broke, no amount of review will, and the gate has nothing to enforce. So pipelines, tests, observability and the cost of running it are in scope — not as a separate offer, but because they are what makes the generated half safe to ship.

What we hear

  • The team started using coding agents and we haven't agreed what has to be reviewed by a person.

  • Review is the bottleneck now. Everyone generates faster than anyone can read.

  • Generated code gets merged because nobody wants to be the one who blocks it.

  • Two developers use agents well and the rest are still typing.

  • Somebody in the business built a tool on their own with AI and forty people now use it.

Why not just

  • Hand out seats and let people work it out.

    Some of them will work it out, and those two people will be measurably better than everyone else — which is the outcome you are trying to avoid, because it is not a capability, it is two people. The gap between a team where agents pay off and one where they accumulate debt is almost entirely setup: what the agent is told about the repo, how big a change it is allowed to propose, and what refuses to merge.

  • Buy a tool.

    The tools are good and getting better, and you probably already have the right ones. A tool cannot decide what your team is allowed to merge unreviewed, and that is the decision the whole thing turns on. We keep track of which model is currently best at which job because it changes every few months — but the flow it runs inside is what makes the output safe, and that is the part nobody sells you.

Why this isn't our opinion

45% of AI-generated code samples introduce an OWASP Top 10 flaw, and the security pass rate has stalled at 56% even as the models improve on coding benchmarks. Bigger models do not write safer code.

Veracode, GenAI Code Security Report, 2025 and 2026

What the agents are actually costing you

Fixed scope, fixed price, agreed before it starts. We read the repository and watch where the time actually goes, which is rarely where the team thinks it goes.

What you get: where agents are earning their place and where they are quietly adding debt, the patterns in your codebase they keep getting wrong, what your review is failing to catch, the gates that would stop it, and what has to be true of your tests before any gate can be trusted.

It stands on its own. Hand it to your own team and they can act on it without us — that is the point of writing it down rather than running a workshop.

Common questions

  • Which tool should we standardise on?

    Whichever one your team will actually keep using, and the answer changes every few months. We keep track and we will give you a current opinion, but it is the least important decision here — the setup around the tool is what separates a team where agents pay off from one where they add debt.

  • Are you going to tell us to slow down?

    No. Speed is the point and we are not interested in taking it back. What we will do is stop it routing around the bar you already had, which is a different thing: gates that refuse what breaks, pieces small enough that a review is a real review, and permissions that stop short of anything irreversible.

  • Our tests are not good enough for any of this.

    Then that is where the work starts, and it will be in the diagnostic. A gate has nothing to enforce if the suite cannot tell you when something old broke, so tests are in scope — not as a separate project, but because they are what makes the generated half safe to ship.

  • Can you do this without access to our code?

    Not honestly. The whole argument here is that an agent handed a codebase it does not understand picks plausibly, and the same is true of a consultant. If access is the obstacle, say so on the call and we will tell you what is still possible without it.

What we do

  • Adopt

    AI inside the processes you already run

  • Engineer

    Your development team using AI with a method

  • Rescue

    Built fast with AI, and now it has to hold

Tell us what's broken. The answer may be that you don't need us.

The call is free and ends in a yes, a no, or "you can handle this yourselves". The person who answers is the person who would do the work. We work remotely across Brazil, and in person in the north of Rio Grande do Sul — the agroindustry and the cooperatives there are close enough to visit, and a consultancy in São Paulo is not going to.

Get in touch