# The screen got reviewed. The rule did not.

> One agent, one wide diff, one reviewer.

- **Format:** short video, 9 steps, ~51 seconds
- **Topic:** AI build agents for a Flutter and Firebase app — why one coding agent writing the widget, query and security rule produces a diff where only the widget is reviewed, with two real findings: a Firestore rule that lets any rider read any order and a dashboard count that reads the whole order history.
- **Author:** Suthahar Jegatheesan (MSDEVBUILD)
- **Category:** AI · AI
- **Published:** 2026-07-31
- **Tags:** flutter, firebase, firestore, aiagents, security, githubcopilot, aicoding, msdevbuild
- **Canonical URL:** https://blog.msdevbuild.com/shorts/ai-build-agents-four-kinds-of-done/

---
## What you'll learn

- Why a wide diff gets reviewed only where the reviewer looks
- Why a role check in Firestore rules is not ownership
- Why a count over a streamed collection is a bill

## Understand it one step at a time

### 1. One wide diff

A bloc, a screen, a function, a query and a rules edit, in one pull request.

### 2. Only the screen is read

The reviewer knows Flutter. The query and the rule merge on trust.

### 3. The rule: any rider

isRider() lets any signed-in rider read and update any order.

### 4. The count: every order

All orders streamed, today filtered in Dart, then .length.

### 5. Four agents, four dones

Flutter, backend API, database and Firebase, each with its own definition of done.

### 6. Database agent: bound it

placedAt from start of today, on the existing index. Or a daily counter.

### 7. Firebase agent: own it

Assigned rider only, plus unassigned orders waiting for pickup.

### 8. The test that proves it

A second rider reading the first rider’s order is denied.

### 9. Four jobs, four kinds of done

Flutter, backend API, database and Firebase, each reviewed by the right person.

---

## The takeaway

**Four jobs. Four kinds of done.**

A narrow diff gets read. A wide one gets read where the reviewer looks.
