Coinbase cuts 90-case AI support test to 30-45 minutes

Engineers disclosed that Coinbase reduced a roughly 90-case support testing cycle from one-to-two weeks to 30-45 minutes using an Autopilot testing system.

Engineers disclosed on Sept. 21 that Coinbase reduced a roughly 90-case support testing cycle from one-to-two weeks to 30-45 minutes by using an internal system called Autopilot. The company framed the change as a way to speed validation of support procedures while keeping human approval in the release path.

Autopilot automates the creation of isolated test accounts and mock account states, runs simulated support conversations, captures transcripts and tool outputs, and compares results against expected behavior. Coinbase described a workflow in which agents can help generate tests and a repeatable runner executes them. The service is integrated with GitHub Actions release gates and a user interface intended for engineering and non-engineering teams; the company reported those elements together produced the 30-45 minute validation cycle for about 90 cases.

The system uses adversarial conversations designed to probe weak flows. An AI model scores those simulated interactions, and the scores feed into human review and release gates. Engineers said a human must approve procedure changes before they are enabled in production. The company clarified that the approval boundary applies to changes in support procedures, not to a human confirming every action a deployed bot takes on an individual customer account.

Coinbase described a separate platform, Control Center, that enforces authorization, auditing, approvals and rate limits across support, compliance, legal, risk and engineering teams. Permission checks evaluate both the requested action and the specific customer; missing customer context results in a denial. For sensitive operations such as refunds, account-state changes and limit overrides, the platform separates proposing a change from executing it. A proposal enters review, required approvals must arrive, and a separate executor carries out the change. Coinbase has not detailed which Autopilot-driven procedures are subject to Control Center rules.

On security testing, the company reported activity from a Continuous Adversarial Testing platform. As of Sept. 15, Coinbase said it had run more than 150,000 scans of its production estate since mid-2026 and completed over 128,000 pull-request reviews. Engineers reported that more penetration-test findings have been fixed as a result of those scans.

Coinbase noted the reported time figure measures the validation cycle for procedure changes and does not measure effects on live support outcomes. The company uses customer-intent labels, resolution and satisfaction signals to identify frequent weak flows, but the Sept. disclosures did not include quantified before-and-after data for customer resolution quality, escalation rates or unauthorized actions. Engineers also said orchestration from an identified performance gap to a promoted procedure is still being developed and that a common format for conversation summaries is not yet finished.

The company indicated that new client types, including automated agents, must be brought under authorization, audit and rate-limiting rules and that authentication boundaries will need revalidation as callers change. Continued human review and rule maintenance remain part of operating responsibilities as the automation scales.

Articles by this author