Questions

Frequently asked questions

Everything about the Forge agent platform — the SDLC pipeline, governance and security, Shopify intelligence, custom agents, integrations and data handling.

Platform

What is Forge?

Forge is an AI agent platform from Oxytal AI Lab. Its flagship is an AI-run software development lifecycle — eight specialised agents from requirements to monitoring, orchestrated as one pipeline. The same "agents with human approval gates" model then extends to security, estate governance and Shopify commerce intelligence, and you can build your own agents on top. There are 24 specialised agents across the platform in total.

How is Forge different from a single AI coding assistant?

A coding assistant helps one person write code. Forge orchestrates a team of specialised agents across an entire workflow — each with a focused job, structured inputs and outputs, and human approval gates at the decisions that matter. It also reaches beyond code into security scanning, governance posture across your estate, and commerce analytics, all in one observable platform.

Does Forge replace my developers?

No. Forge automates repetitive, high-context work and keeps humans in control through approval gates at design, code review and release. Your team reviews and signs off before anything merges or ships — AI proposes, people decide.

How does the human-in-the-loop model work?

Pipelines pause at configurable gates — typically design, code review and release. Nothing progresses past a gate until an authorised person approves it. Every gate decision (who approved or rejected, when, and why) is recorded in the audit trail.

Agents & suites

What agent families does Forge offer?

Five: (1) the 8-agent SDLC pipeline; (2) Security & Compliance — DevSecOps scanning plus SOC 2 / ISO 27001 / GDPR evidence; (3) Estate Governance — GitHub, Vercel and SharePoint posture; (4) Shopify Intelligence — 8 agents for store analytics; and (5) Custom agents you build yourself.

What does the SDLC pipeline do?

Eight agents cover the lifecycle: Requirements (turns Confluence pages into structured stories), Design (produces an Architecture Decision Record), Development (writes the feature and opens a pull request), Code Review (SAST + quality review with a gate), Build & Deploy (merges and deploys a preview via GitHub + Vercel), Testing (generates and runs tests against the preview), Defect Fix (reads failures and commits the fix) and Monitoring (watches production metrics and flags anomalies).

What do the governance agents do?

Three read-only agents consolidate posture across your estate: GitHub Governance (multiple orgs → repos, 2FA gaps, branch protection, Dependabot/secret/code-scanning alerts, risk score), Vercel Governance (teams → deployment protection, secrets exposure, access hygiene) and SharePoint Governance (sites, owners, storage, document counts and orphaned/stale risk via Microsoft Graph). Each produces a risk score, a ranked list of the riskiest items and an executive summary.

What do the security and compliance agents do?

The Security / AppSec agent is a DevSecOps scanner — dependency CVEs (via OSV.dev), hardcoded secrets, lightweight SAST and supply-chain checks — and can gate the pipeline. The Compliance & Audit agent continuously maps governance and security output plus Forge’s audit trail onto SOC 2, ISO 27001 and GDPR control catalogs, producing an audit-readiness score, a control-by-control register, a gap list and an auditor-facing summary.

What is Shopify Intelligence?

Eight agents that analyse a connected Shopify store via the GraphQL Admin API: Sales Collector (exact revenue/orders/AOV), Conversion Analyst (funnel, cart abandonment, recoverable revenue), Revenue Forecaster (30/60/90-day forecasts with seasonality), Channel Attribution (UTM, ROAS, MER), Customer Segmenter (RFM, LTV cohorts, churn, win-back), Personalisation Engine (product-affinity recommendations, Klaviyo/Shopify Flow plays), Product Analyst (inventory velocity, stockout risk, bundles) and Operations Monitor (OTIF, fulfilment SLA, returns, carrier mix).

Can I build my own agents?

Yes. Create a custom agent in minutes: name it, pick any model, write or auto-infer its system prompt, choose a trigger (manual, auto-continue, scheduled, on-event or conditional), and define schema-driven output. Agents can be scoped to one project or shared org-wide.

How are agent prompts managed?

Every agent’s prompt is fully editable and version-controlled in Prompt Studio — a reusable prompt library with create, edit, duplicate and full version history. Built-in "seed" prompts are read-only but can be duplicated into editable copies, and you can A/B test and score prompts in a live sandbox.

What output formats do agents produce?

Agent output is schema-driven: fields are inferred from the prompt and assigned roles that render as KPI cards, tables, charts or prose. Reports can be delivered as HTML, PDF, CSV, Excel or Markdown, via preview, download, email or Slack.

Integrations & models

What tools does Forge integrate with?

Fourteen native integrations: GitHub (source, PRs) and GitHub Governance; Confluence and Jira (requirements and tracking); Vercel (deploys) and Vercel Governance; Semgrep (SAST); Slack (alerts and digests); Shopify (commerce); Microsoft 365 / SharePoint (documents and governance); AWS SES (email); a database connector (MySQL, PostgreSQL, PlanetScale, Neon, Supabase and more); and three model providers — Anthropic, OpenAI and Google.

Which AI models can I use?

Forge is multi-model. Each agent can run on Anthropic Claude, OpenAI GPT or Google Gemini, selected from a managed model catalog to balance capability and cost. For example, forecasting agents can use a stronger model while routine summaries use a faster one.

Do I need my own API keys?

Yes — Forge runs against your own credentials. You connect your Anthropic/OpenAI/Google keys and your GitHub, Jira, Vercel, Shopify and other accounts, so agents operate in your environment with your permissions. You’re billed by those providers directly for usage.

How are agents triggered?

Agents support five trigger types: manual approval, auto-continue (within a pipeline), scheduled (cron), on-event, and conditional. Governance and Shopify agents are commonly scheduled to produce recurring reports; SDLC agents run inline within a pipeline.

Security, data & control

Is my code and data secure?

Forge runs with your own integration credentials and API keys, over HTTPS/TLS. Approval gates mean no code merges or deploys without explicit human sign-off, and every run, token, cost and gate decision is recorded for full traceability.

Do you train AI models on my data?

No. We don’t use your pipeline content to train models, and API providers process content under their own terms without training on it by default. Forge sends only the content each agent needs — not full database contents, account information or API keys.

How are my credentials stored?

Integration credentials are encrypted at rest with AES-256-GCM, never written to logs, and (for AI provider keys) tied to your individual account rather than shared across a team. You can remove them at any time.

What compliance frameworks does Forge support?

The Compliance & Audit agent maps evidence onto SOC 2, ISO 27001 and GDPR control catalogs and produces an audit-readiness score and gap list. The platform itself is operated in line with UK GDPR and the Data Protection Act 2018 — see the Privacy Policy for details.

Cost & getting started

How does Forge handle cost and ROI?

Every agent run records real token usage and cost. The Forecast dashboard converts delivered work into role-based value and ROI using hourly rates you configure. Because you bring your own model keys, you pay providers directly and see exactly what each run costs.

How do I get started?

Connect the integrations you need with your own credentials, choose or build the agents you want, and run — starting with the SDLC pipeline or any single governance, security or Shopify agent. You can compose the built-in suites or create custom agents at any time.

Still have a question?

We’re happy to help — send us a note and the right person will get back to you.

Contact us →Request access