Using an AI assistant for Azure DevOps deployments
Developers increasingly work alongside an AI assistant such as ChatGPT, Claude, Cursor, or GitHub Copilot. Asking it to "deploy ticket 1482 to UAT" is a natural next step. The Model Context Protocol (MCP) makes that possible: it lets an assistant call tools in other systems, including Azure DevOps.
The hard part is not making the assistant able to deploy. It is making sure it deploys the right thing, only where it is allowed to, and never without a person agreeing. This guide covers the risks, the design choices that address them, and how BranchDeploy's MCP integration works.
What can go wrong when an assistant deploys
- It picks the branch. If the tool accepts a branch name, the assistant will supply one, possibly guessed from a similar ticket, an old conversation, or a typo.
- It picks the pipeline. A generic "run pipeline" tool lets the assistant choose any pipeline it can see, including production.
- It skips your rules. Branch conventions that live in people's heads, or in a different tool, do not apply to the assistant.
- It acts without asking. Some clients run tools automatically. A deploy should never be one of them.
- It follows instructions it should not. Text inside a ticket, PR description, or web page can try to steer the assistant. The less the assistant decides, the less there is to steer.
Design principles for safe AI deployments
- Take the smallest possible input. The assistant provides the work item number and, only if needed, an environment name. Nothing else.
- Resolve everything else on the server. The branch comes from the work item's Development links; the pipeline comes from the environment's saved configuration.
- Enforce the same rules as every other path. Branch allowlists apply whether the deploy starts from a button, a chat, or an assistant.
- Preview, then confirm. Show the resolved ticket, branch, and environment and require an explicit yes before queueing.
- Record it. Every assistant deployment should appear in the same audit trail as human ones.
General-purpose Azure DevOps MCP servers
General-purpose Azure DevOps MCP servers, including Microsoft's own, expose work items, repositories, and pipelines as tools. They are excellent for reading and summarising, and for broad automation. For deployments, though, the assistant usually supplies the pipeline and branch itself, and any branch rules have to be enforced by your pipelines or by the assistant's good behaviour.
If you use one, scope its credentials tightly, keep deployment pipelines behind environment approvals, and configure your client to ask before running pipeline tools.
How BranchDeploy's MCP integration works
BranchDeploy Pro exposes a remote MCP server that follows the principles above. It deploys work items, not branches:
You: Deploy ticket 1482 to UAT
Assistant: Preview for #1482 "Add customer invoice export"
Branch: feature/1482-invoice-export
Environment: UAT
Pipeline: the pipeline configured for UAT
Reply "deploy it" to queue the run.
You: deploy it
Assistant: Queued. Deployment ID and pipeline run link: ... - You give the ticket number. Name an environment only if the branch could go to more than one.
- The
preview_deploytool resolves the work item's linked branch (or linked PR's source branch), the environment, and its configured pipeline, and checks the allowed branch patterns. Nothing is queued. - The assistant shows you the preview and asks for confirmation.
- Only after you confirm does the
deploytool queue the configured Azure Pipeline. - The deployment is recorded in the BranchDeploy audit log with its run status.
The assistant never supplies a branch or pipeline ID, so it cannot deploy an unlinked branch or a pipeline you did not configure. Other tools let it list environments, check deployment status, read recent deployment history, and draft release notes from what was deployed.
Supported AI clients
- ChatGPT: add the BranchDeploy app from the ChatGPT Plugins directory and sign in with your BranchDeploy account. No API key.
- Claude Code, Cursor, GitHub Copilot in VS Code: add the remote server URL with an MCP API key from your account page.
- Claude Desktop: connect through the
mcp-remotebridge. - Any other client that supports remote MCP servers over Streamable HTTP.
What you need
- A BranchDeploy Pro subscription.
- Environments configured in the BranchDeploy extension in Azure DevOps and synced to your account.
- An Azure DevOps PAT with Work Items (Read), Code (Read), and Build (Read & Execute), saved on your account page. Runs queued over MCP use this PAT.
Client-by-client setup is in the MCP documentation.
Frequently asked questions
Can ChatGPT deploy to Azure DevOps?
Yes, through an MCP app or connector. With BranchDeploy, you add the BranchDeploy app in ChatGPT, sign in, and ask it to deploy a ticket. It previews the deployment and waits for your confirmation before queueing the pipeline.
Can the assistant deploy a branch that is not linked to the ticket?
Not through BranchDeploy. The deploy tool takes a work item, not a branch, and resolves the branch from the work item's Development links on the server. Branches that do not match the environment's allowed patterns are rejected.
Does the assistant need my Azure DevOps credentials?
No. The assistant authenticates to BranchDeploy with an API key or, in ChatGPT, OAuth sign-in. BranchDeploy uses the PAT saved on your account page to talk to Azure DevOps, so the PAT is never shared with the assistant.
Are AI deployments audited?
Yes. Deployments made over MCP are recorded automatically in the BranchDeploy Pro audit log, alongside deployments from the work item button. See deployment audit logs for Azure DevOps.