Agent-merge audit · SOC 2 CC8.1 · updated
Which merges an AI agent wrote, and whether a person approved them
Auditors test change management (SOC 2 CC8.1) by sampling merged pull requests and checking that someone other than the author approved each one before it merged. When Copilot's coding agent, Claude Code or Cursor wrote the change, and since 1 September 2026 when Copilot's own approval can count toward a branch's required approvals, the branch rule alone no longer shows whether a person reviewed it. These pages show how to list, for a period, which merges an agent wrote and who approved them, from GitHub's own records.
Check it by hand, today
Merged pull requests, who opened, merged and approved each
$ gh pr list --repo OWNER/REPO --state merged --search "merged:2026-07-01..2026-09-30" --limit 1000 --json number,author,mergedBy,reviews --jq '.[] | [.number, .author.login, .mergedBy.login, ([.reviews[] | select(.state == "APPROVED") | .author.login] | unique | join(" "))] | @tsv'One line a pull request: number, who opened it, who merged it, and who approved it. A line with no approver, or whose only approver opened it, is an exception to explain. It does not tell an approval given before the last commit, or a person from a bot.
Commits an agent co-wrote, by their trailers
$ git log --since=2026-07-01 --until=2026-09-30 -i -E --grep='^co-authored-by: .*(claude|codex|cursor|copilot|amp|aider|gemini|devin|jules|openhands)' --format='%h %an %s'In a checkout of the default branch. Claude Code, Cursor's agent, Codex, VS Code with Copilot and Amp add a Co-authored-by trailer by default; a trailer can be turned off or removed, so this finds a floor.
The exceptions an auditor asks about
| Exception | The question to answer |
|---|---|
| An agent wrote or co-wrote it, and no independent person approved it | Who reviewed this agent's change before it merged, and where is that recorded? |
| Merged with no approval | Why did it merge without review? |
| Approved only by its author, a commit author or a co-author | Who other than the people who wrote it reviewed it? |
| Approved only by a bot or an AI reviewer | Is an automated approval part of your documented review control? |
| Approved before its last commit | Who reviewed the commits added after the approval? |
| Merged by a bot account, with no person queueing it | Which person authorised this merge? |
| No approval, though the branch rule now requires one | Was the rule added after this merge, or was it bypassed or exempted? |
| A commit on the branch that no merged pull request accounts for | Why did it reach the branch without a reviewed pull request? |
An approval is independent when it comes from a person who is not the pull request's author, a commit author, or a co-author named in a Co-authored-by trailer. Merging the base branch into a pull request does not count as writing it.
How an agent shows up in GitHub's records
- The account that opened the pull request:
Copilot(the app copilot-swe-agent),claude[bot],devin-ai-integration[bot],google-labs-jules[bot],cursor[bot]. On 9 October 2026 GitHub's search counted 1,528,286 merged pull requests opened by Copilot's coding agent. - The commit's author: Copilot's, Cursor's (
cursoragent@cursor.com), Devin's, Jules's and the Claude app's identities. - Co-author trailers:
Co-Authored-By: Claude … <noreply@anthropic.com>(9,684,405 commits),Cursor <cursoragent@cursor.com>(4,530,975),Codex <codex@openai.com>(262,677),Copilot <copilot@github.com>(154,211),Amp <amp@ampcode.com>(107,241). - Agent-only trailers and markers:
Amp-Thread-ID,Entire-Checkpoint, 'Generated with [Claude Code]', a Codex task link. - An agent that leaves none of these, or a trailer someone removed, is not found: any count is a floor.
What GitHub keeps, and for how long
- The branch rule now: readable by anyone for a public repo through the rules API. Classic branch protection needs an admin's token.
- The rule at each merge (pass, bypass, fail): GitHub's rule evaluations look back one month, and a ruleset exemption records no bypass at all.
- The audit log: 180 days, Git events 7 days; streaming it elsewhere is an Enterprise feature.
- A SOC 2 Type II window runs up to twelve months. What the rules were at a merge eleven months ago is a record someone has to have kept as it happened.
More
- SOC 2 CC8.1 evidence from GitHub: what auditors sample, and what GRC tools test
- AI-generated code and SOC 2: what changed in 2026
- Copilot coding agent pull requests: who approved them, and does Copilot's approval count
All of it in one run, free
$ npx --allow-git=root github:agentwares/agent-merge-audit OWNER/REPO --period 2026-Q3Every merged pull request in the period, with whether an agent wrote it, whether a person other than its authors approved it on the final code, who merged it, the rule, and the exceptions, as a dated CSV and markdown pair. Your own GitHub token, or none for a public repo; GETs to GitHub's API only. Also as a GitHub Action, uses: agentwares/agent-merge-audit@main, and a local MCP server: github.com/agentwares/agent-merge-audit.
A continuous, hash-chained record of every agent change, kept across your audit window, is not built
It would record each merge as it happens (who or what wrote it, who approved it, who merged it, under which rule) in okgate's hash-chained log, with a quarterly CC8.1 export and a read-only link for your auditor, so the rule at a merge eleven months ago is on record.
What works today, free: okgate's hook mode holds an agent's git push or merge in Claude Code, Codex and Gemini CLI until a person types the go-ahead, and logs each decision in a hash-chained log on your machine.
$ npx -p @agentwares/agentguard okgate hooks installWhat okgate sells today keeps your agents' tool calls through its proxy, not merges: 90 days of hash-chained log on Pro ($99/month), 365 days with a compliance export on Team ($299/month).
Sources, each read on 9 October 2026
- OneUptime: Can GitHub pull requests prove SOC 2 change management? (4 Aug 2026)
- GitHub changelog: Copilot code review can now approve pull requests (1 Sep 2026)
- GitHub Docs: reviewing a pull request created by Copilot
- GitHub REST API: rule suites
- GitHub changelog: ruleset exemptions (10 Sep 2025)
- GitHub Docs: accessing the audit log (180 days; Git events 7 days)