AI Coding the Right Way
Direct coding assistants like a senior engineer: specs, tests first, verified APIs, gated reviews, secure defaults, team rules.
- Level
- Practitioner
- Learning time
- 18 hours
- Price
- $199
- Credential
- Valid 3 years
What changed in this edition.
- The full course is now published: 38 lessons across seven modules, including new material on context engineering, debugging, legacy code, performance, documentation, team instruction files and measuring quality.
- Every code example is real, syntactically valid Go, Python or TypeScript, and the examples were run while the course was prepared.
- Security now covers agent permissions and prompt injection through untrusted content, alongside input validation, injection controls and secrets.
- Eight AI role-play labs (product owner, tech lead, security reviewer, on-call engineer, retiring maintainer, engineering manager) plus a capstone in which you write the spec, the tests and the review notes.
- A new lesson explains what changes when a team adds persistent, governed memory, and points to AI Coding with bRRAIn for the full method.
- Hours now reflect the actual content (18 hours). The exam is assembled per candidate from a larger bank and includes four AI-conducted performance tasks.
What you will be able to do.
- You will be able to turn vague requests into executable specs and thin, verifiable slices, and engineer the context an assistant works from.
- You will be able to drive AI-written changes test-first and evaluate AI-written tests for the anti-patterns that make green meaningless.
- You will be able to detect hallucinated APIs, signatures, behavior and packages, and keep dependencies pinned, vetted and scanned.
- You will be able to gate and review AI diffs, keep changes small and reversible, and refactor without behavior drift.
- You will be able to build security into the pipeline, validate input, prevent injection, protect secrets and run agents with least privilege.
- You will be able to debug, change legacy code, tune performance and document with evidence rather than plausibility.
- You will be able to set team instruction files, review policy and outcome measures for AI-assisted delivery.
Who it's for
- Working software engineers using Claude Code or similar coding agents, chat assistants or editor completion tools
- Tech leads responsible for code quality on teams that ship with AI assistance
- Engineering managers writing their team's AI-coding playbook
- Career-switchers and bootcamp graduates who need production habits from the start
- Founders building products with AI assistance
Not covered here
- Framework-specific tutorials (the practice is language and framework agnostic; examples use Go, Python and TypeScript)
- Training or fine-tuning models
- Prompting for non-coding work
- Working on governed bRRAIn memory in depth (see AI Coding with bRRAIn; the two certifications stack)
7 modules, 62 lessons.
About 18 hours of learning. Open a module to see every lesson.
-
Specification, decomposition and context
Quality is decided before the assistant types: specs instead of prompts, thin verifiable slices, the right first gate, engineered context and requirements elicited from people. Lab 1 interviews a product owner with a vague request.
- Module 1 pretest
- The spec is the work — why prompts succeed or fail before code is typed
- Scope, contract, forbidden moves — writing a spec an assistant can execute
- Decomposition — slices an assistant can finish and you can review
- Contract-first or test-first — choosing which gate to lead with
- Context engineering — deciding what the assistant sees
- Scenario: turning a vague requirement into a spec
- Lab 1: Turn a product owner's vague request into a spec
- Retrieval: 8 questions across Module 1
-
Test-first development with an assistant
Red-green-refactor with clear roles for you and the assistant, the right test level and doubles, assistant-generated edge cases and property tests, and reviewing AI-written tests. Lab 2 drives a business rule test-first.
- Module 2 pretest
- Why test-first is the highest-leverage AI-paired pattern
- Worked example: red-green-refactor with an assistant
- Choosing the test level — unit, integration, end-to-end and test doubles
- Worked example: using the assistant to find test cases you would miss
- Reviewing AI-written tests — the anti-patterns that make green meaningless
- Lab 2: Drive a feature test-first with a simulated assistant
- Retrieval: 8 questions across Module 2
-
Hallucinated APIs and dependency risk
The four hallucination shapes and version mismatches, the package check before any install, signature and behavior verification against the version you run, lockfiles and licenses, and supply-chain controls for assistant-driven work. Lab 3 hunts planted hallucinations in a PR.
- Module 3 pretest
- The code-hallucination taxonomy — API, signature, behavior, package
- Worked example: the package check before any AI-suggested dependency
- Worked example: verifying signatures against the version you run
- Scenario: catching behavior hallucinations that compile and pass
- Pin versions, review lockfiles, audit licenses
- Supply-chain risk in AI-assisted development
- Lab 3: Hunt the hallucinations in an AI-drafted pull request
- Retrieval: 8 questions across Module 3
-
Reviewing AI diffs, refactoring and reversibility
The four-question acceptance gate, the failure modes characteristic of AI diffs, shrinking diffs, behavior-preserving refactors, the assistant as reviewer, drift sweeps and rollback rituals. Lab 4 reviews an oversized AI PR with a tech lead.
- Module 4 pretest
- The acceptance gate — compile, test, spec-match, smallest diff
- Reviewing AI diffs — the failure modes to look for
- Worked example: shrinking an AI diff to the smallest change
- Worked example: refactoring with an assistant without changing behavior
- The assistant as reviewer — useful second reader, never the approver
- The drift sweep — keeping an AI-assisted codebase coherent
- Rollback rituals — making every AI-assisted change easy to undo
- Lab 4: Review an AI-generated pull request with your tech lead
- Retrieval: 9 questions across Module 4
-
Security, secrets and agent permissions
Security as blocking build gates, input validation at the boundary, secrets discipline with assistants, SQL injection, path traversal and SSRF, least privilege and prompt-injection risk for agents, and lightweight threat modeling. Lab 5 faces a security reviewer.
- Module 5 pretest
- Security as a build gate, not a review item
- Worked example: input validation at the boundary
- Secrets discipline with coding assistants
- Worked example: SQL injection, path traversal and SSRF in AI-written Go
- Agent permissions and untrusted content — securing the assistant itself
- Scenario: a lightweight threat model before the assistant writes code
- Lab 5: Security review of an AI-built service
- Retrieval: 9 questions across Module 5
-
Debugging, legacy code, performance and documentation
Evidence over plausibility: the debugging loop with the assistant as hypothesis generator, seams and characterization tests for legacy code, measured performance work and documentation that stays true. Labs 6 and 7 cover an intermittent production bug and a legacy change with a retiring maintainer.
- Module 6 pretest
- Worked example: debugging with an assistant — reproduce, narrow, hypothesize, instrument, verify
- Worked example: changing legacy code you do not understand yet
- Performance work with an assistant — measure, change, measure again
- Documentation with an assistant — fast drafts, verified claims, recorded reasons
- Lab 6: Debug an intermittent data bug without accepting a symptom fix
- Lab 7: Plan a safe change to legacy code with its retiring maintainer
- Retrieval: 8 questions across Module 6
-
Team conventions, measurement, memory and capstone
Instruction files the assistant follows, a one-page review policy, outcome measures for AI-assisted delivery, what persistent governed memory adds, a playbook lab with an engineering manager, and the capstone.
- Module 7 pretest
- Worked example: a team instruction file the assistant actually follows
- Team review policy for AI-assisted changes
- Measuring whether AI-assisted delivery is actually better
- When your team adds persistent memory
- Lab 8: Draft the team's AI-coding playbook with an engineering manager
- The capstone brief — what you do, what you submit, how it is scored
- Retrieval: 8 questions across Module 7
- Capstone: Specify, test and review an AI-built feature end to end
Practice against someone who pushes back.
Labs run in your browser as AI role-plays. An AI plays the person on the other side of the scenario — with their own goals and objections — and your work is scored against the published rubric. There is nothing to install.
-
Lab 1 · Specification, decomposition and context
AI role-play with a credit-union product owner whose request for card alerts hides seven business rules
-
Lab 2 · Test-first development with an assistant
AI role-play with a simulated coding assistant implementing a late-fee rule test-first, with realistic assistant habits to catch
-
Lab 3 · Hallucinated APIs and dependency risk
AI role-play with the author of an AI-drafted payout export containing five planted hallucinations
-
Lab 4 · Reviewing AI diffs, refactoring and reversibility
AI role-play with a tech lead reviewing an oversized AI-generated PR under demo pressure
-
Lab 5 · Security, secrets and agent permissions
AI role-play with an application security engineer reviewing an assistant-built Go service
-
Lab 6 · Debugging, legacy code, performance and documentation
AI role-play with an on-call engineer facing an intermittent export bug and a symptom-hiding assistant fix
-
Lab 7 · Debugging, legacy code, performance and documentation
AI role-play with a retiring maintainer of an untested pricing module and a misleading assistant summary
-
Lab 8 · Team conventions, measurement, memory and capstone
AI role-play with an engineering manager proposing activity metrics and weakened controls
-
Lab 9 · Team conventions, measurement, memory and capstone
AI role-play with a library product owner and a simulated coding assistant; spec, tests, gate report and review notes submitted for AI scoring
Specify, test and review an AI-built feature end to end
Artefact submitted in the capstone lab, AI-scored against the published rubric
Pass mark: 72%
Scored on
- Requirements and spec20%
- Test design20%
- Diff review and gate25%
- Security and dependency handling20%
- Evidence and honesty15%
One exam. A credential anyone can verify.
The exam
- Items per form
- 59
- Time allowed
- 120 min
- Pass mark
- 72%
- Performance tasks
- 4
- Attempts included
- 2
- Wait between attempts
- 7 days
- Online and timed, taken on learn.brrain.io.
- Your form is assembled for you from the course's item bank, so no two candidates sit the same paper.
- Performance tasks are conducted by an AI examiner: you work through a realistic scenario and are scored against a published rubric.
The credential
- A verifiable digital badge in your name.
- A public verification page at learn.brrain.io/verify, so an employer or client can confirm it.
- Valid for 3 years.
- Renewal: At 3 years by passing the then-current exam; quarterly CE modules keep you current in between
Where this course sits.
Prerequisites
- Basic coding literacy: you can read a diff, follow a stack trace and run a unit test in one language
Stacks well with
Frequently asked.
Do I need to install anything for the labs?
No. Labs and the capstone run in your browser on learn.brrain.io as AI role-plays: an AI plays the person on the other side of the scenario, and your work is scored against the rubric published with the course.
How is the exam delivered?
Online and timed: 59 items in 120 minutes, on a form assembled for you from the course's item bank. 4 of the items are performance tasks conducted by an AI examiner: you do the work rather than pick an answer. The pass mark is 72%.
What if I don't pass first time?
You have 2 attempts, with a 7-day wait after an unsuccessful attempt. Further exam attempts can be bought for $199 each.
How long is the credential valid?
3 years. You receive a verifiable digital badge with a public verification page at learn.brrain.io/verify, so anyone can confirm it is genuine.
I hold the v1 credential. Is it still valid?
Yes. Credentials earned on v1 remain valid and verifiable at learn.brrain.io/verify. When you renew, you sit the then-current version of the exam.
Can my company enroll a team?
Yes. Firms can buy a certification bundle for $2,999 per firm per year — see the pricing page — or contact us to arrange enrollment for a larger group.
Related courses.
AI Coding the Right Way
Direct coding assistants like a senior engineer: specs, tests first, verified APIs, gated reviews, secure defaults, team rules.