AI coding tools
Cursor Rollouts & Security Review: Worth the Teams Upgrade?
Cursor shipped two new bots on September 23, 2026 — Rollouts, which watches your changes deploy and reports their health per environment, and Security Review, which reports exploitable bugs on every pull request. Both are included on Teams and Enterprise plans only. That immediately raises the question developers are actually searching for: are these bots good enough to justify $40/user/month over the $20 Pro plan, or is this another paywall feature you'll never touch?
Short answer
- The bots cost $0 extra — they're bundled into Teams ($40/user/mo) and Enterprise. The real question is whether they change the Pro ($20/mo) → Teams upgrade math.
- For a 3–10 person team that already ships through PRs with a deploy pipeline, yes, probably: you're paying the difference of $20/seat/mo ($240/seat/year) to automate the "last mile" — deploy watching and security review — that someone on your team currently does manually.
- For a solo developer on Pro: no. You can't enable either bot on Pro, and upgrading to Teams for one person means paying $240/year for team features (central billing, shared context, SSO) you'd mostly not use.
- Cheapest way to decide: don't rush. At launch (Sep 23) Cursor attached usage credits for ~50 changes over 10 days to Teams Rollouts — that window closes around Oct 3, so treat the trial as mostly spent. What remains free: enabling the bot on Teams and reading its monitoring plans on your own PRs.
What Cursor shipped on Sep 23
The official changelog describes two bots "for the last mile of shipping code," available "today on Teams and Enterprise plans." They are separate tools with separate jobs:
| Rollouts | Security Review | |
|---|---|---|
| Job | Watches each change from PR through deploy, reports health per environment | Reads every PR in the context of the whole codebase, reports exploitable bugs |
| Output | A monitoring plan as a PR comment, then verdicts: verified healthy, regression detected, or inconclusive | One review comment per PR with severity, attack path, and proposed fix |
| Skips | — | Draft PRs |
| Plans | Teams, Enterprise | Teams, Enterprise |
One boundary worth stating up front because marketing copy tends to blur it: per the changelog, Rollouts "does not merge or roll back on its own today." It names the suspect change, notifies the author, and — depending on configuration — can open a revert PR for review or hand the finding to a cloud agent. A human still approves the actual revert.
Rollouts: what it actually does between merge and production
When a pull request opens, Rollouts reads the diff and the systems it touches, then posts a monitoring plan as a PR comment: the risks it identified, the effect the change is supposed to have, the signals it will check, and — this is the genuinely useful part — any gaps in instrumentation that would make the change hard to verify. You can edit the plan in the PR and Rollouts uses your version.
On deploy, it runs that plan against your logs, metrics, and traces, tracking each environment separately. The changelog's example is the right one: a change can be verified healthy in staging and still flagged in production. When it detects a regression, it names the change it suspects.
Cursor's launch post (Rustam Lalkaka) lists three things it does well today:
- It catches regressions confined to one endpoint in one region, before a global alert would fire
- It tells intended effects apart from regressions, so a deliberate latency spike doesn't page anyone
- It flags missing instrumentation before merge — per Cursor, the most common reason a bad change goes unnoticed
Setup requires connecting source control, your deploy system, and your telemetry provider. The changelog says Rollouts "connects to Origin or GitHub for source control," your continuous delivery system for deploy events, and Datadog and other telemetry providers for signals — the blog post names Grafana and Honeycomb as well. Feature flag integration is listed as coming soon, which means Rollouts can't yet ramp or unramp traffic directly.
Security Review: what it catches (and what it leaves to Bugbot)
Security Review posts one review comment per PR covering exploitable bugs only — style and quality issues stay with Bugbot. It reads the change in the context of the whole codebase and traces where user input enters and what it passes through. Out of the box, per the changelog and launch post, it looks for:
- Injection across SQL, command, template, and LDAP surfaces
- Missing or broken authentication and authorization — including checks that stopped running after a refactor
- Secrets and credentials committed to source
- SSRF and unvalidated redirects
- Unsafe deserialization
- Dependency changes that pull in known vulnerabilities
- Insecure defaults in infrastructure and config (launch post)
Each finding carries a severity, the attack path, and a proposed fix — the launch post says one-click. Dismiss a finding with a reason and it won't re-raise on that PR. You can also add team rules (e.g. "external calls must go through this client," "these tables are never queried from a request handler") that Security Review enforces on every PR.
Cursor's X account has also stated that Security Reviewer "now finishes 21% faster, in 3.8 minutes on average" alongside the Rollouts launch. We're treating this as the vendor's own figure — no independent benchmark exists yet.
The worth-it math: Teams at $40 vs Pro at $20
Here's the pricing as of October 2, 2026, pulled directly from cursor.com/pricing:
| Plan | Price | Rollouts & Security Review |
|---|---|---|
| Hobby | Free | Not available |
| Individual (Pro) | $20/mo | Not available |
| Teams | $40/user/mo | Included (launch trial: ~50 changes of usage credits over 10 days from Sep 23 — expired) |
| Enterprise | Custom | Included (launch trial: ~500 changes of usage credits over 10 days from Sep 23 — expired) |
The bots don't have their own price tag. So the upgrade question reduces to: is Teams worth +$20/seat/mo for your situation, with these bots as part of the bundle?
Frame it this way. A 3-seat team pays $120/mo on Teams vs $60/mo on three Pro seats — a $720/year gap. If your team currently pays for that last mile in human time — one engineer watching dashboards after each deploy, another skimming PRs for security issues — $720/year is cheap. If instead you already have CI checks, a static analyzer, and Datadog monitors wired to Slack, the marginal value shrinks, and you'd be upgrading mainly for the other Teams features: centralized billing, team-wide privacy mode, shared team context for automations, usage analytics.
For solo developers the math is lopsided in the other direction: $20/mo → $40/mo is a 100% price increase to reach features built around team administration. Pro has no path to either bot. If you want Rollouts as an individual, the honest answer is you can't — and the Enterprise "contact sales" route makes even less sense at that scale.
Rollouts vs. what you already have
If you run Datadog or Grafana, you already have monitors and alerts. Rollouts is not competing with that stack — it sits between your diff and your telemetry. The differentiation, per the changelog, is that it reads the change itself, writes a per-PR monitoring plan (what signals matter for this change), and reports the verdict back on the PR where the author is already working. Traditional alerting knows your baseline; it doesn't know what the change intended to do. That "intended effect vs regression" distinction is the part existing alerting handles badly.
You could approximate this with a homegrown setup — a CI job that annotates PRs with monitoring links, plus disciplined dashboards. Teams that already built that will get less from Rollouts. Teams that always meant to build it and never did are the target customer.
Edges worth knowing before you commit (all from the Sep 23 changelog, checked 2026-10-02): Rollouts does not merge or roll back on its own today — a human approves reverts. Feature flag integration is "coming soon," so no direct traffic ramping yet. Security Review skips draft PRs. Onboarding requires wiring source control, a deploy system, and a telemetry provider — if you don't have all three, the bot has nothing to watch. The changelog lists "Origin or GitHub" for source control; we quote it as written and can't verify Origin's setup details from public pages. Vendor figures (21% faster / 3.8 min average) are unaudited.
Spelling note: Cursor's own changelog uses both "Security Review" and "Security Reviewer" in different sections; this page standardizes on "Security Review" except where quoting.
This page was checked against Cursor's changelog, launch post, and pricing page on October 2, 2026. Plan features and pricing change frequently — verify on cursor.com before making a purchase decision. If Cursor changes bot availability or pricing, the numbers above may be stale.
Sources: Cursor Changelog — Rollouts and Security Review (Sep 23, 2026) · Cursor Blog — Bots for the last mile (Sep 23, 2026) · Cursor Pricing (retrieved Oct 2, 2026)
Related reading: Cursor vs GitHub Copilot 2026: full plan and pricing comparison · Claude Code vs Cursor pricing · What an AI coding assistant actually costs per month