# Review and Merge Policy — Safe Autonomous Code Fixing

Source: https://www.skillbyai.com/en/safe-autonomous-code-fixing/m-policy

> Decide what can ever merge without a human.

## Tiers by risk

Define tiers: **low-risk** changes (formatting, lint auto-fixes, patch-level dependency bumps with passing tests) might merge after CI and a quick human approval or, in mature setups, automatically; **medium-risk** bug fixes need a code owner's review; **high-risk** areas (security, payments, data migrations, authentication) are out of scope for autonomous fixing or always need senior review. Reviewers should check the root-cause explanation, not just the green checks.

## A risk-tier policy

Adjust to your organisation.

```text
tier     examples                                      merge requirement
low      lint fixes, typo fixes, patch dependency bumps CI green + 1 approval (or auto after trial period)
medium   bug fixes with reproduction tests              CI green + code owner approval
high     auth, payments, crypto, migrations, infra      not eligible for autonomous fixing
```

## Start every tier with human review

Allow any auto-merge only after months of measured, clean history for that tier.

**Quiz:** Which change is least suitable for autonomous fixing?

- [ ] Fixing a lint warning
- [x] A change to authentication logic
- [ ] A patch-level dependency bump with passing tests
- [ ] Correcting a typo in a log message

*Answer:* A change to authentication logic. High-risk areas need human ownership.
