How to Build an Azure DevOps AI Bot That Auto-Closes Work Items

6 min read
Share:

What you'll have at the end

  • Every open work item in your Azure DevOps project syncs to Agentopias by CynetIQ every 5 minutes.
  • AI agents (analyzer → developer → reviewer) generate the patch.
  • A pull request is opened on Azure Repos with the AI review attached.
  • Work item state transitions automatically: Active → Resolved when the PR opens, Closed when it auto-completes.
  • Security-tagged work items route to the OWASP-aware security_developer reviewer.
  • Story points are written back to the work item by AI Refinement.

Step 1 — Create the PAT

Go to dev.azure.com/yourorg/_usersSettings/tokens. Create a token with these scopes:

  • Code (Read & Write) — required to push branches, open PRs.
  • Work Items (Read & Write) — required to import and update.
  • Build (Read) — required to read CI status before auto-completing.
  • Identity (Read) — required to look up reviewers.
Copy the token. You won't see it again.

Step 2 — Connect Agentopias by CynetIQ

In Agentopias by CynetIQ → Integrations → Azure DevOps:

  • PAT: paste it.
  • Org URL: https://dev.azure.com/yourorg.
Agentopias by CynetIQ validates by listing your projects. If you see project names, you're connected.

Step 3 — Map projects to repos

For each project, Agentopias by CynetIQ shows you its repos. Click Map on each repo you want AI to target. The mapping stores:

  • Provider: Azure DevOps
  • Owner: project name
  • Repo name: repo name
  • Base branch: default (main or master)
  • Playbook: optional repo-specific instructions for the AI

Step 4 — Configure the WIQL filter

The default work item filter:

``

SELECT [System.Id] FROM workitems

WHERE [System.State] <> 'Closed' AND [System.AssignedTo] = @Me

`

Customize per project. Common patterns:

  • All open bugs: WorkItemType = 'Bug' AND State <> 'Closed'
  • Specific area path: AreaPath UNDER 'Project\\Backend\\API'
  • Security backlog: Tags CONTAINS 'security' AND State <> 'Closed'

Step 5 — Set up routing rules

Go to /dashboard/integrations/rules. Add rules per provider:

  • Match: Provider = Azure DevOps, Tag contains "security"
  • Action: Tag = security_review, Preferred Agent Role = security_developer, Priority = critical
Or by area path:

  • Match: Area Path matches Project\\Frontend
  • Action: Preferred Agent Role = accessibility_reviewer

Step 6 — Enable auto-import

On any work item, the Agentopias by CynetIQ task page shows a toggle: Auto-import for this query. Turn it on. The worker polls every 5 minutes.

Step 7 — Optional: auto-complete the AI's PRs

In Azure DevOps branch policies for main:

  • Require minimum 1 reviewer.
  • Require successful CI build.
  • Require linked work items.
In Agentopias by CynetIQ → Integrations → Azure DevOps → Settings:

  • Auto-complete AI PRs: ON (recommended).
  • Squash on auto-complete: ON.
  • Delete branch on auto-complete: ON.
When the AI's PR satisfies the policies, it auto-completes. The work item transitions to Closed via the merge commit message linkage. Agentopias by CynetIQ's webhook also fires to close the Agentopias by CynetIQ task.

Step 8 — Watch the first run

The first import run will pull every work item that matches your filter. Expect the first batch to be large. Subsequent runs only pick up new or changed work items.

Common gotchas

  • Story points field: if your project uses a custom field for story points (not Microsoft.VSTS.Scheduling.StoryPoints), set the field reference name in Agentopias by CynetIQ → Integrations → Azure DevOps → Field Map.
  • Work item type names: Agentopias by CynetIQ filters by lowercase types. User Story works, PBI works, Bug` works.
  • Self-hosted Azure DevOps Server: same flow, different base URL. Agentopias by CynetIQ supports both.

Related reading

Share:

Agentic AI'ı denemek ister misiniz?

Ücretsiz başlayın ve Agentopias by CynetIQ'nın 3D agentlarının geliştirme iş akışınızı yönetmesine izin verin.