# Review
---
## Review
Before a Task's pull request opens, a reviewer — a second AI agent run — checks the change. Among other things, it looks at security, correctness, and whether the change does what the Task's description asks.
Every Task is reviewed by default. A Task created through the API can ask for its review to be advisory, where findings are only noted on the pull request, or turned off.
### Choosing the reviewer
The reviewer uses the Task's model unless you pick a different one under **Reviewer model** when you create, start or re-run the Task. The default option is "Same as the Task's model".
**Review level** is **Standard** or **Thorough**. Thorough asks the reviewer to reason more: each review round takes longer and uses more of the reviewer's tokens.
### What happens to a finding
Each finding has an area, such as Security or Correctness, and a severity. Your organization's settings decide what happens to it, per area, in **Org Settings → Agents → Review**:
- **Fix automatically at or above** — findings at this severity or higher are sent back to the agent to fix while the review has rounds and time left, with at most two rounds of fixes. Findings below it are only noted on the pull request.
- **Must fix before merge at or above** — if a finding at this severity or higher is still open when the review ends, the pull request opens with "[Needs fixes]" at the start of its title, as a draft where your Git provider supports drafts. The pull request still opens; the work is never thrown away.
Rows marked Platform default follow Deployment.io's defaults, which may change. **Reset to platform defaults** restores them. Changes apply to Task steps scheduled after you save.
### In the pull request
The pull request's description has a review section: what the review found, what was fixed during the review, and what it covered. An area the review didn't check is listed as not checked — never as passed.
The latest review's open findings are also posted as inline comments on the lines they point at, where your Git provider supports it.
## Before deploying
If the change reads configuration — an environment variable — that the review didn't find in the service's environment, the pull request lists it under **Before deploying**.
For a service Deployment.io deploys, each entry has an **Add it** link. It opens that environment's edit page with the variable's name already filled in; you enter the value and save. Nothing is saved for you.
For a service on ECS that Deployment.io doesn't deploy, the entry tells you to set the variable in the service's task definition.
---
Source: https://deployment.io/docs/tasks/review/