Claude Code security review routing: Alberta turns 466M lines into a governed agent lane

Claude Code security review routing moves from demo to government scale as Alberta scans 466M lines, runs 50 agents, and keeps human approval in the loop.

Published via Anthropic

Archive item produced with AI assistance from the cited source and published without individual review. Editor of record: Joe Werner.

Claude Code security review routing shown as parallel code-review agents feeding verified findings into a governed approval lane

Claude Code security review routing is no longer a lab pattern. Anthropic says the Government of Alberta used Claude Code with Opus and Sonnet models to scan 466 million lines of code in about 20 hours, coordinate roughly 50 parallel agents, and remediate security gaps across government systems. The important part for AI engineering teams is not the speed headline. It is the operating model: a rules engine flags candidates, Claude reviews and cites exact files and lines, specialized red-team and blue-team agents run continuous checks, and government engineers keep review and approval authority before patches ship.

What happened in Claude Code security review routing

Anthropic published a July 6 case study describing how Alberta's Ministry of Technology and Innovation has used Claude Code since 2025 to review systems across 27 provincial ministries. The ministry maintains about 1,280 applications and 3,400 repositories, including systems that handle tax records, procurement data, social-services case files, public safety, and wildfire response. Anthropic says most of that estate had not gone through a systematic security review.

The reported first pass scanned 466 million lines in 20 hours. Alberta's team used Claude Code with Claude Opus and Sonnet models, running around 50 agents autonomously and in parallel. The workflow started with a rules engine that flagged known risky patterns, then used Claude to review the flags, cite exact locations, and surface findings that older automated scanners had missed. Anthropic says the team estimated the same review could otherwise have taken about 6.5 years.

The case study also describes remediation, not only detection. Where Claude Code identified a vulnerability, it could often draft a fix, run tests, and build the result. If tests were missing, Claude wrote them first. If a system was too old to patch safely, the team used Claude to rebuild parts of it in a modern language. Separately, Alberta built continuous review agents: a red-team agent probes applications from the outside, a blue-team agent evaluates defenses against roughly 95 controls, and other agents check code quality and public-facing writing.

Why Claude Code security review routing matters for AI engineering teams

Claude Code security review routing changes the question from "can an agent find bugs?" to "which lane is allowed to inspect, patch, test, and escalate security work?" At Alberta scale, agent concurrency becomes an infrastructure concern. Fifty parallel agents scanning thousands of repositories need model-tier policy, repository access boundaries, request attribution, token and wall-clock budgets, evidence formats, and a way to avoid flooding maintainers with duplicate or low-confidence findings.

The case study is also a reminder that vulnerability review is not the same route as ordinary code generation. A coding agent that can trace exploit paths and patch legacy systems is touching highly sensitive data-adjacent infrastructure. It may need read-only access for scanning, write access only on isolated branches for patches, separate handling for proof-of-concept evidence, and a fail-closed policy when the preferred security model or review queue is unavailable.

For enterprise teams, the most transferable pattern is Alberta's two-stage design. Deterministic tooling narrows the search space; model reasoning inspects context and proposes fixes; humans keep approval. That is much healthier than asking a frontier model to roam every repository with broad write credentials. It gives the routing layer clearer inputs: task type, sensitivity, repository class, model tier, allowed tools, reviewer group, and expected artifact.

The router/operator angle for Claude Code security review routing

The router/operator angle for Claude Code security review routing is to treat security review as a dedicated agent lane, not a feature flag on a normal coding assistant. A practical routing matrix has at least four routes:

  1. Inventory and hygiene. Low-risk dependency checks, stale-code discovery, and documentation gaps can use cheaper models, read-only scopes, and batch scheduling.
  2. Evidence review. Vulnerability hypotheses, exploit-path analysis, and exact file-line citations should use stronger models, stricter logging, and structured evidence artifacts.
  3. Patch proposal. Any agent that modifies code should operate on a branch, run tests, attach diffs and build output, and require named human approval before merge.
  4. Continuous red/blue review. Always-on security agents need quota ceilings, repository allowlists, control mappings, and alert deduplication before they enter developer workflows.

That matrix also changes fallback. If the evidence-review route cannot reach its preferred Claude model, the safest fallback may be queueing or read-only analysis rather than silently switching to a cheaper general model. If the patch route cannot run tests, the route should stop at a patch proposal and mark the artifact unverified. If the disclosure route would send information outside the organization, it should require a separate approval trail.

TheRouter users can map those lanes into gateway policy rather than scattering them across scripts. The TheRouter AI routing documentation is the stable place to start for provider routing and request policy. The earlier OpenAI Patch the Planet Codex Security routing analysis is a useful companion because it reaches the same conclusion from a different vendor: security agents need governed remediation routes, not just stronger models.

What TheRouter users should watch or try with Claude Code security review routing

Start by defining a security-review route before giving any coding agent broad repository access. Require each task to declare one mode: advisory scan, evidence review, patch proposal, or external disclosure. Tie each mode to model tier, repository scope, tool permissions, logging, and human reviewer requirements.

Next, measure the queue as seriously as the model. Track confirmed finding rate, duplicate rate, false-positive rate, average review time, patch acceptance, tests created by the agent, and rollbacks. Alberta's case study is impressive because it combines speed with review structure; without those measurements, a large agent fleet can simply turn technical debt into alert debt.

Finally, keep model fallback separate from governance fallback. Claude Code security review routing works only when the route preserves evidence, approval, and isolation. A model swap that keeps the API shape but loses security-review controls is not a safe fallback. Treat security agents as an operational lane with its own budget, audit trail, and stop conditions.

Help & contact