What can't a pre-deploy CI gate catch?

A pre-deploy gate only ever judges a diff, so anything that degrades an agent without touching your code walks straight past it. Three real causes do exactly that: a provider swapping the model behind an API you call, an upstream agent or service changing what it returns, and a tool reshaping its own response format.

OpenAI’s April 2025 postmortem on GPT-4o is the clearest public example of a provider-side change like this. An update made the model noticeably more sycophantic, users flagged it within days, and OpenAI rolled it back days later, all inside its own pipeline. The shift landed in ChatGPT with no commit, no version bump, and nothing in any outside team’s repository to review.

A gate built to read diffs structurally can’t see that; it’s a property of what a diff is, not a gap in any one team’s setup. Catching it means watching live traffic for a silent failure instead, since the run itself still looks completely normal.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y