How to Build an Azure DevOps AI Bot That Auto-Closes Work Items
What you'll have at the end
- Every open work item in your Azure DevOps project syncs to Agentopias by CynetIQ every 5 minutes.
- AI agents (analyzer → developer → reviewer) generate the patch.
- A pull request is opened on Azure Repos with the AI review attached.
- Work item state transitions automatically: Active → Resolved when the PR opens, Closed when it auto-completes.
- Security-tagged work items route to the OWASP-aware
security_developerreviewer. - Story points are written back to the work item by AI Refinement.
Step 1 — Create the PAT
Go to dev.azure.com/yourorg/_usersSettings/tokens. Create a token with these scopes:
- Code (Read & Write) — required to push branches, open PRs.
- Work Items (Read & Write) — required to import and update.
- Build (Read) — required to read CI status before auto-completing.
- Identity (Read) — required to look up reviewers.
Step 2 — Connect Agentopias by CynetIQ
In Agentopias by CynetIQ → Integrations → Azure DevOps:
- PAT: paste it.
- Org URL:
https://dev.azure.com/yourorg.
Step 3 — Map projects to repos
For each project, Agentopias by CynetIQ shows you its repos. Click Map on each repo you want AI to target. The mapping stores:
- Provider: Azure DevOps
- Owner: project name
- Repo name: repo name
- Base branch: default (
mainormaster) - Playbook: optional repo-specific instructions for the AI
Step 4 — Configure the WIQL filter
The default work item filter:
``
SELECT [System.Id] FROM workitems
WHERE [System.State] <> 'Closed' AND [System.AssignedTo] = @Me
`
Customize per project. Common patterns:
- All open bugs: WorkItemType = 'Bug' AND State <> 'Closed'
- Specific area path: AreaPath UNDER 'Project\\Backend\\API'
- Security backlog: Tags CONTAINS 'security' AND State <> 'Closed'
Step 5 — Set up routing rules
Go to /dashboard/integrations/rules. Add rules per provider:
- Match: Provider = Azure DevOps, Tag contains "security"
- Action: Tag = security_review
, Preferred Agent Role =security_developer, Priority = critical
- Match: Area Path matches Project\\Frontend
- Action: Preferred Agent Role = accessibility_reviewer
Step 6 — Enable auto-import
On any work item, the Agentopias by CynetIQ task page shows a toggle: Auto-import for this query. Turn it on. The worker polls every 5 minutes.
Step 7 — Optional: auto-complete the AI's PRs
In Azure DevOps branch policies for main:
- Require minimum 1 reviewer.
- Require successful CI build.
- Require linked work items.
- Auto-complete AI PRs: ON (recommended).
- Squash on auto-complete: ON.
- Delete branch on auto-complete: ON.
Step 8 — Watch the first run
The first import run will pull every work item that matches your filter. Expect the first batch to be large. Subsequent runs only pick up new or changed work items.
Common gotchas
- Story points field: if your project uses a custom field for story points (not Microsoft.VSTS.Scheduling.StoryPoints
), set the field reference name in Agentopias by CynetIQ → Integrations → Azure DevOps → Field Map. - Work item type names: Agentopias by CynetIQ filters by lowercase types. User Story
works,PBIworks,Bug` works. - Self-hosted Azure DevOps Server: same flow, different base URL. Agentopias by CynetIQ supports both.
Related reading
Agentic AI'ı denemek ister misiniz?
Ücretsiz başlayın ve Agentopias by CynetIQ'nın 3D agentlarının geliştirme iş akışınızı yönetmesine izin verin.
