Last week the agent-as-buyer thread graduated from Show HNs to platform roadmaps. This week the story was money — what AI features cost, and what buyers can prove they return. GitHub answered both halves within three days, and the answers belong together.

The seat, the meter, and the shelfware

On July 20, GitHub Code Quality went GA: $10 per active committer per month, plus usage-based billing for the AI parts (AI-assisted detection, Copilot Autofix), plus CodeQL compute on Actions minutes. More than 10,000 enterprises ran it free in preview. That extends the two-part tariff — a seat you can budget, a meter that moves — from code generation (Copilot’s $19/$39 seats with AI credits that drain by usage) to code review. Wednesday’s money piece has the comparables table; the short version is that this is now the default AI price shape in devtools, not an experiment.

Two days later, GitHub shipped the other half: a Copilot impact dashboard that sorts enterprise seats into adoption-phase cohorts — code-first, agent-first, multi-agent — plus a named “Passive (licensed but not engaged)” segment. The seller of the seats built the tool that tells the buyer which ones are shelfware. Thursday’s piece covers the mechanics.

Why would a vendor do that? Because the renewal conversation now demands it. The same week, HCLTech’s 500-enterprise survey with Raconteur (vendor-commissioned — flag it accordingly) put numbers on the gap: 90% of decision-makers say GenAI is transforming workflows; only 18% see significant revenue impact. When five in six buyers can’t show the CFO a revenue line, the vendor that names its own shelfware controls the honest number in the room instead of losing to a hostile one someone else computes. This is verification-first marketing — the same instinct as putting a real price and a cap on the pricing page — arriving at the renewal stage of the funnel.

The play, both directions. Selling an AI feature: price it as seat plus meter and publish both parts and the cap — the positioning section now says this in the evergreen voice — and report adoption in progression cohorts with the passive segment counted, per the measurement section. Buying one: ask for the passive-seat count before you renew, and expect the vendor to have it.

”Agent-safe” hardened into a category

The GoDaddy agent-safe checkout from last week’s issue stopped being a one-off. This week added a credential gateway (OneCLI, a March Rust project re-posted to Show HN on July 23 under the credential-gateway framing, 106 points, 2.9k stars — “agents never see the keys”), Common Room’s headless cr CLI and MCP write layer that gates agent-driven CRM writes behind identity resolution (its Incident.io proof point — duplicate accounts from 3% to 0.3% — is vendor-claimed), and two thin launches a day apart binding agent actions to pre-approved policy (Axtary, ActionRail, three points each, no adoption proof). Sunday’s technology piece makes the full argument: what tipped this from loud to moving isn’t the launch count — none of the OSS entrants has adoption proof yet — but independent corroboration, from The New Stack’s GoDaddy teardown to an arXiv attempt at a pre-action authorization spec.

The one-line version for the reader: if your product lets an agent take a consequential action, build the checkpoint that evaluates the action before it executes — then document the flow. Right now that’s a positioning claim most of your competitors cannot make.

Also this week

  • Reputation buys attention, not the verdict. Jack Dorsey’s Block launched Buzz (July 21), an open-source Slack rival where agents get cryptographic identity — 304 HN points and a skeptical thread (“LLM slop”). The founder-credibility channel filled the room; it didn’t win the argument.
  • HeimWall’s honest benchmark joined the swipe file. The post behind Tuesday’s campaigns piece — 27,075 real prompts scanned, three live-format keys found, and the noise published next to the signal (1.12% alert rate, 48% of alerts from one UUID rule, its own middling F1 of 0.449) — is a copyable template.
  • antirez argues distribution itself changes: repos as templates for AI agents to adapt, not frozen releases for humans to install (July 23). One respected voice, no adoption evidence yet — texture, not a trend.
  • Helical Insight un-gated its paid tier into Community Edition (July 24), keeping support and SLAs as the revenue layer. Near-zero traction on the announcement; a data point for the feature-gating debate, not a trend.
  • DevRelCon NYC wrapped July 23 — and three days later, no recaps. The measurable-ROI hiring-bar claim from last week’s watch remains single-sourced. It carries to W31; if recaps don’t surface by mid-August, it was one person’s job search.

One thing to watch

Whether “passive seat” escapes GitHub’s dashboard. The falsifiable call: by end of Q3 2026, either a second seat-based AI devtool ships phase-cohort reporting with a named unengaged segment, or a public renewal/procurement story cites a passive-seat count as leverage. Either confirms that adoption-phase honesty is becoming the price of selling AI to enterprises. If neither happens, the dashboard was a GitHub one-off — and the 18% revenue-impact number stays a survey stat instead of a negotiating table.