SkillByAIOpen interactive version →

Lesson 21 / 25

Review and Merge Policy

Decide what can ever merge without a human.

Tiers by risk

Define tiers: low-risk changes (formatting, lint auto-fixes, patch-level dependency bumps with passing tests) might merge after CI and a quick human approval or, in mature setups, automatically; medium-risk bug fixes need a code owner's review; high-risk areas (security, payments, data migrations, authentication) are out of scope for autonomous fixing or always need senior review. Reviewers should check the root-cause explanation, not just the green checks.

A risk-tier policy

Adjust to your organisation.

tier     examples                                      merge requirement
low      lint fixes, typo fixes, patch dependency bumps CI green + 1 approval (or auto after trial period)
medium   bug fixes with reproduction tests              CI green + code owner approval
high     auth, payments, crypto, migrations, infra      not eligible for autonomous fixing

Start every tier with human review

Allow any auto-merge only after months of measured, clean history for that tier.

Quick check: Which change is least suitable for autonomous fixing?

  • Fixing a lint warning
  • A change to authentication logic
  • A patch-level dependency bump with passing tests
  • Correcting a typo in a log message
Answer

A change to authentication logic — High-risk areas need human ownership.