Cursor’s Rollouts and Security Reviewer target the work that happens after code is written. Rollouts follows a change from pull request through production, while Security Reviewer inspects PRs for security issues in the context of the wider codebase. The goal is to reduce repetitive work around regressions, monitoring gaps, and vulnerability fixes. Cursor says the features are for Teams and Enterprise. Read Cursor’s announcement.

Official image for Cursor 新增部署监控与安全审查机器人,覆盖代码合并之后的工作
Official image from Cursor; click to open the original source.

How Rollouts follows a deployment

After a team connects source control, its deploy system, and telemetry, Rollouts reads the diff before merge and drafts a monitoring plan: the intended effect, services that may be affected, and whether existing instrumentation can show that the change worked. The team can edit this plan before deployment. After release, Rollouts compares the relevant signals with the pre-deploy baseline, tries to distinguish an intended change from a regression, and points to the code change it suspects. Depending on team settings, it can notify the author, pause a progressive rollout, or create a revert PR that waits for approval.

What Security Reviewer examines

Security Reviewer can run on each PR, interpret the change in the context of the repository, and report vulnerabilities, a possible attack path, and a proposed fix. Cursor contrasts this with static rules that match isolated patterns: a risky-looking call may have an authorization check elsewhere, while an innocuous local change may break a security assumption across files. Use the report to decide what to reproduce and fix; it is not a complete penetration test or security certification.

Prepare a controlled pilot

  1. Choose a low-risk service and an observable metric, such as error rate or latency, and establish a pre-release baseline.
  2. Check whether every important business path has adequate telemetry. A bot cannot infer production impact from missing instrumentation.
  3. Start with notifications or approval-required actions. Review false positives and misses before considering automated pauses or rollbacks.
  4. Bring Security Reviewer findings into the existing review process. Have maintainers inspect context, reproduction steps, and possible side effects of a fix.

Scope and limitations

Cursor announced access for Teams and Enterprise. Direct traffic adjustment through feature flags and awareness of release freezes were listed as future work at announcement. Results depend on complete code, deployment, metrics, and tracing data, as well as the team’s authorization for automatic actions. A bot’s “safe” or “regression” label should not bypass existing production review.