GitHub
Create one uniquely named branch at an exact existing commit in an explicitly selected pilot repository.
Exact surface
GitHub App installation and exact branch creation
Controlled-operation scope
Create one uniquely named branch at an exact existing commit in an explicitly selected pilot repository.
Enforcement path
Gated evaluates policy, requires human approval when specified, uses temporary server-held GitHub App authority, and records execution and revocation evidence.
Requirements
Pilot access, a selected non-critical repository, a verified installation binding, scoped agent credentials and a human approver with a passkey.
Verification · 8 September 2026
A hosted proof against a separate GitHub account created the exact branch and commit. Independent provider readback matched; replay returned the same execution; the revoked agent was rejected.
Capability status
Branch creation at an exact SHA
Private previewVerified through the server-held GitHub App path with provider readback, replay protection and revocation.
PR merge
PlannedNot implemented.
Force-push governance
PlannedNot implemented.
Bypass and runtime limits
Only actions explicitly routed through a Gated-controlled execution path are governed. Direct provider credentials and tools can bypass Gated. No native or universal runtime interception is implemented.
Current limitations
Private preview covers only the verified staging workflow. PR merge and force-push governance are not implemented. No branch update, deletion or pull-request execution. GitHub Contents-write permission is broader than one branch; the trusted executor enforces the narrower operation.
