AI Agents & Tools
A tool-agnostic map of the agentic landscape in 2026 - the coding agents, protocols, and platforms teams actually use - laid across the five phases of AIDLC. No rankings, no affiliates. Pick what fits your team.
Last reviewed: September 2026
Three Modes of AI
Assistant
You prompt, it answers. Chat and inline autocomplete. Great for questions, snippets, and explanations - bounded by a single turn.
Agent
You scope a task, it plans and executes multiple steps - editing files, running commands - then returns a diff for review. This is the 2026 default for real work.
Multi-Agent
Several agents work in parallel under your direction - one builds, one reviews, one tests - coordinated by an orchestrator. Now a shipping feature across the major agents rather than a demo, and still the mode that most demands supervision.
Tools by Phase
Representative options for each AIDLC phase. Tools change fast and overlap heavily - treat this as a starting map, not a shopping list.
| Phase | Representative Tools | What They Do |
|---|---|---|
| Analyze | Claude, ChatGPT, Gemini, Perplexity, Gemini Notebook (formerly NotebookLM) | Research, synthesis, requirements extraction |
| Ideate | Claude, Gemini, Mermaid, Excalidraw | Architecture, diagrams, specs, trade-off analysis |
| Develop | Claude Code, Cursor, GitHub Copilot, Codex, Kiro (replaced Amazon Q Developer) | Agentic coding, generation, review, refactoring |
| Launch | Claude Code, GitHub Actions, Playwright, Codex | Test generation, CI/CD, deployment automation |
| Curate | Claude, Datadog, Sentry, Grafana | Monitoring, triage, debugging, living docs |
The Building Blocks
Coding Agents
CLI and IDE agents that take a scoped task and execute it across your repo - reading, editing, running, and returning a diff. The workhorse of the Develop and Launch phases. The field is broad and growing - Cline, opencode, and others compete on the same shape - which is why AIDLC maps the category, not a winner.
MCP & Connectors
The Model Context Protocol and the servers built on it give agents governed access to your docs, databases, issue trackers, and internal services - the difference between a demo and production use. Agent Plugins, an open standard published at version 1.0.0, now lets skills and MCP server configurations travel between agents as one installable bundle, so the connective tissue you build is no longer tied to one harness.
Orchestration
Frameworks that coordinate multiple agents, manage their context, and gate their actions behind human approval. Where multi-agent workflows are wired together and supervised.
Observability
Monitoring and tracing tools - increasingly with AI triage built in - that watch production and feed real signals back into the Curate phase and the next cycle of analysis.
How to Choose
- Methodology over brand. AIDLC is the constant; tools are interchangeable. Pick for fit, and expect to swap them as the market moves.
- Favor reviewable output. The best agents make their work easy to inspect - clear diffs, explained steps - because you are accountable for what ships.
- Mind your context boundary. Whatever connects an agent to your systems (often MCP) is also a security boundary. Grant the least access that gets the job done.
- Start with one phase. Adopt agents where you feel the most friction, build the review discipline, then expand across the lifecycle.
- Prefer portable configuration. Skills, specs, and MCP configs in open formats can follow you between agents - lock-in is now a choice, not a default.
Working through an actual decision? How to Choose an AI Coding Agent takes these rules further - the eight axes that separate candidates, and how to trial them on real work.
Market landscape, verified September 2026
This category consolidates monthly - verify a vendor's status or pricing before quoting it.
| Phase | Representative tools | Notes |
|---|---|---|
| Planning and design | Linear, Jira with Atlassian Rovo, Notion, Figma | AI drafting and summarization inside the planning tool; ticket-contract generation is usually custom |
| Coding agents (IDE and CLI) | Claude Code, GitHub Copilot, Cursor (a SpaceX subsidiary since 08-2026), Codex CLI and app, Antigravity IDE and CLI (Google moved its consumer and free tiers off Gemini CLI, 06-2026; the open-source Gemini CLI still ships for API-key, Vertex AI and Code Assist users), Devin, Kiro (replaced Amazon Q Developer, whose IDE plugins lose support 04-30-2027), Amp (spun out of Sourcegraph, 12-2025), Augment Code, GitLab Duo Agent Platform | Nearly all read a repo instruction file and support skills and MCP. Per-seat pricing is giving way to usage-based credits across the category |
| Autonomous and cloud agents | GitHub Copilot cloud agent (renamed from coding agent, 04-2026), Codex cloud, Claude Code GitHub Action, Cursor Cloud Agents, Devin, Google Jules, Kiro Crew | Opens pull requests unattended. GitHub's Agents tab has run Claude and Codex inside github.com in public preview since 02-2026 |
| Code review | CodeRabbit (Series C, 08-2026), GitHub Copilot code review (can approve pull requests in preview since 09-2026), Claude Code review tooling, Cursor Bugbot, Graphite Agent (acquired by Cursor, 12-2025), Greptile, Qodo Git, Codacy, GitLab Duo Code Review | The differentiator is whether a tool learns and enforces your rules or only flags generic patterns |
| Testing | Playwright, which now ships an agent-facing CLI and an MCP server alongside the test runner, plus mabl, Testim, Applitools, Qodo, and mutation tools (Stryker, PIT, mutmut, cargo-mutants) | Mutation testing is the gate that matters for generated tests |
| Security | Snyk, Semgrep, SonarQube, Checkmarx, Veracode, GitHub code scanning with Copilot Autofix | SAST catches the classes AI gets wrong most often: cross-site scripting, log injection, error masking |
| DevOps and monitoring | Datadog, New Relic, Dynatrace, PagerDuty, PostHog, Sentry | Incident agents that correlate deploys to errors are now standard across vendors |
| Evals and observability for AI | Promptfoo (OpenAI-owned since 03-2026, still open source), Braintrust, LangSmith, Langfuse, DeepEval, Arize Phoenix | The fixture set is the asset, the tool is interchangeable. OpenAI's hosted Evals API goes read-only 10-31-2026 and shuts down 11-30-2026 |
Vendor identity and governance features
| Vendor | CI identity | Spend controls | Audit and compliance |
|---|---|---|---|
| Anthropic | Workload identity federation for GitHub Actions, AWS, GCP, Azure, Kubernetes, and Okta; service accounts; API keys with an expiry policy | Per-workspace monthly caps and rate limits; usage and cost report APIs; an Enterprise spend limits API | Team includes SSO, a no-training default, and usage analytics. Enterprise adds an audit log, SCIM, a Compliance API, HIPAA readiness with a BAA, CMEK, and an IP allowlist. Claude Code is included in every Team and Enterprise seat |
| GitHub | Copilot's cloud agent runs under a bot identity with signed commits and session-log trailers; GitHub Apps cover third-party agents | AI Credits with per-user budgets on cost centers; Business and Enterprise seats include a credit allowance | Enterprise AI Controls and an agent control plane reached general availability 02-2026, with agent-specific audit events, MCP allowlists, a global model policy, and content exclusion. No BAA |
| OpenAI | API keys; Codex cloud sessions run under the workspace | Project-level budgets on the API platform | ChatGPT Enterprise has audit logs, SCIM, and a BAA; Business does not. Codex local is BAA-eligible, Codex cloud is not |
| GitLab | Service accounts and CI job tokens | GitLab Credits, billed per user per month with on-demand top-ups | Duo Agent Platform reached general availability 01-2026 with audit events in the platform log |
A few conventions cut across every vendor above: AGENTS.md and CLAUDE.md as repo instruction files, Agent Skills as an open standard for portable procedures at agentskills.io, and MCP for tool and data connectors - governed by the Linux Foundation's Agentic AI Foundation since 12-09-2025 alongside AGENTS.md and Block's goose. The OWASP GenAI Security Project maintains the threat taxonomies, and OpenSSF's AI/ML security working group covers model signing and agent guidance.
Every code review vendor makes the same pitch: generation tools raise output volume, so without a strong review layer more code simply means more risk. The argument is correct. It is also the reason to evaluate review tools on your own fixture set rather than their benchmarks, and the reason not to let any of them approve a Tier 3 pull request - see AI Code Review at Scale and Engineering Practices.
Frequently Asked Questions
AIDLC is tool-agnostic, so there is no single right answer. Most teams pair a chat assistant such as Claude, ChatGPT, or Gemini with a coding agent such as Claude Code, Cursor, GitHub Copilot, or Codex, then connect them to their systems through MCP. Choose for fit with your stack and review workflow, and expect the specific tools to change.
An assistant responds to a single prompt - you ask, it answers. An agent takes a goal and executes multiple steps to reach it: planning, editing files, running commands, and checking results before handing back a diff. Agents do more on their own, which is why reviewing their output well is the key skill.
Not strictly - agents work on a local repo without it. But MCP is what lets an agent reach your wider systems (docs, tickets, databases, services) through a standard, governed interface instead of brittle one-off integrations. On real projects it is usually what makes agents genuinely useful, and it doubles as a place to enforce access controls.
Tools Change. The Method Stays.
Learn the framework that outlasts any single tool, and the discipline that makes agents safe to rely on.