The Playbook

The GRC Vibe Coder's Playbook · Lesson 05 of 06

How do I manage costs and know the work is right?

Small tasks and human review beat endless regeneration.

All six lessons · Jump to a lesson
Our running project

Use concise context and smaller models for straightforward edits when practical; reserve more capable reasoning for difficult problems.

Compare actual plan limits and pricing rather than assuming a tool switch saves money.

Inspect tests, diffs, and a preview.

Ask whether the risk score follows the documented rules.

A green check does not mean the product is correct or approved.

Test a vendor with a known high-risk answer, a low-risk answer, and missing information.

Read the output as a human reviewer would.

If the code labels a vendor low risk despite missing evidence, a passing test suite is not enough: the rule or the tests need correction.

Put it into practice

Review one PR against the blueprint. Record a pass, a revision request, or a known limitation with a reason.

Before you move on

Read the AI output critically. Does it match your project goal and the instructions in the prompt? Can you explain the recommendation or change in your own words? If not, ask for clarification or a smaller next step.

Save useful decisions and results in your project notes or GitHub repository. Do not treat a confident answer, generated code, or a passing check as a substitute for your own review.