Agent-merge audit · SOC 2 CC8.1 · updated

Which merges an AI agent wrote, and whether a person approved them

Auditors test change management (SOC 2 CC8.1) by sampling merged pull requests and checking that someone other than the author approved each one before it merged. When Copilot's coding agent, Claude Code or Cursor wrote the change, and since 1 September 2026 when Copilot's own approval can count toward a branch's required approvals, the branch rule alone no longer shows whether a person reviewed it. These pages show how to list, for a period, which merges an agent wrote and who approved them, from GitHub's own records.

Check it by hand, today

Merged pull requests, who opened, merged and approved each

$ gh pr list --repo OWNER/REPO --state merged --search "merged:2026-07-01..2026-09-30" --limit 1000 --json number,author,mergedBy,reviews --jq '.[] | [.number, .author.login, .mergedBy.login, ([.reviews[] | select(.state == "APPROVED") | .author.login] | unique | join(" "))] | @tsv'

One line a pull request: number, who opened it, who merged it, and who approved it. A line with no approver, or whose only approver opened it, is an exception to explain. It does not tell an approval given before the last commit, or a person from a bot.

Commits an agent co-wrote, by their trailers

$ git log --since=2026-07-01 --until=2026-09-30 -i -E --grep='^co-authored-by: .*(claude|codex|cursor|copilot|amp|aider|gemini|devin|jules|openhands)' --format='%h %an %s'

In a checkout of the default branch. Claude Code, Cursor's agent, Codex, VS Code with Copilot and Amp add a Co-authored-by trailer by default; a trailer can be turned off or removed, so this finds a floor.

The exceptions an auditor asks about

ExceptionThe question to answer
An agent wrote or co-wrote it, and no independent person approved itWho reviewed this agent's change before it merged, and where is that recorded?
Merged with no approvalWhy did it merge without review?
Approved only by its author, a commit author or a co-authorWho other than the people who wrote it reviewed it?
Approved only by a bot or an AI reviewerIs an automated approval part of your documented review control?
Approved before its last commitWho reviewed the commits added after the approval?
Merged by a bot account, with no person queueing itWhich person authorised this merge?
No approval, though the branch rule now requires oneWas the rule added after this merge, or was it bypassed or exempted?
A commit on the branch that no merged pull request accounts forWhy did it reach the branch without a reviewed pull request?

An approval is independent when it comes from a person who is not the pull request's author, a commit author, or a co-author named in a Co-authored-by trailer. Merging the base branch into a pull request does not count as writing it.

How an agent shows up in GitHub's records

What GitHub keeps, and for how long

More

All of it in one run, free

$ npx --allow-git=root github:agentwares/agent-merge-audit OWNER/REPO --period 2026-Q3

Every merged pull request in the period, with whether an agent wrote it, whether a person other than its authors approved it on the final code, who merged it, the rule, and the exceptions, as a dated CSV and markdown pair. Your own GitHub token, or none for a public repo; GETs to GitHub's API only. Also as a GitHub Action, uses: agentwares/agent-merge-audit@main, and a local MCP server: github.com/agentwares/agent-merge-audit.

A continuous, hash-chained record of every agent change, kept across your audit window, is not built

It would record each merge as it happens (who or what wrote it, who approved it, who merged it, under which rule) in okgate's hash-chained log, with a quarterly CC8.1 export and a read-only link for your auditor, so the rule at a merge eleven months ago is on record.

What works today, free: okgate's hook mode holds an agent's git push or merge in Claude Code, Codex and Gemini CLI until a person types the go-ahead, and logs each decision in a hash-chained log on your machine.

$ npx -p @agentwares/agentguard okgate hooks install

What okgate sells today keeps your agents' tool calls through its proxy, not merges: 90 days of hash-chained log on Pro ($99/month), 365 days with a compliance export on Team ($299/month).

I want that record

Sources, each read on 9 October 2026