Agent-merge audit · SOC 2 CC8.1 · updated

AI-generated code and SOC 2

SOC 2 has no separate criterion for code an AI wrote. The same change-management test applies: was the change reviewed and approved by someone other than its author before it shipped? What changed in 2026 is how often the author is an agent, and that the approver can be one too. Auditors have started to ask which changes an agent made and who reviewed them.

What changed in 2026

Show which commits an agent co-wrote

Most coding agents sign their commits. Claude Code adds Co-Authored-By: Claude … <noreply@anthropic.com> by default, and VS Code adds Co-authored-by: Copilot <copilot@github.com> when Copilot helped (the git.addAICoAuthor setting, on by default since May 2026, heise). Cursor, Codex and Amp do the same with their own addresses.

Commits an agent co-wrote, by their trailers

$ git log --since=2026-07-01 --until=2026-09-30 -i -E --grep='^co-authored-by: .*(claude|codex|cursor|copilot|amp|aider|gemini|devin|jules|openhands)' --format='%h %an %s'

In a checkout of the default branch. Claude Code, Cursor's agent, Codex, VS Code with Copilot and Amp add a Co-authored-by trailer by default; a trailer can be turned off or removed, so this finds a floor.

Then show a person approved each one

Merged pull requests, who opened, merged and approved each

$ gh pr list --repo OWNER/REPO --state merged --search "merged:2026-07-01..2026-09-30" --limit 1000 --json number,author,mergedBy,reviews --jq '.[] | [.number, .author.login, .mergedBy.login, ([.reviews[] | select(.state == "APPROVED") | .author.login] | unique | join(" "))] | @tsv'

One line a pull request: number, who opened it, who merged it, and who approved it. A line with no approver, or whose only approver opened it, is an exception to explain. It does not tell an approval given before the last commit, or a person from a bot.

For each agent-written merge, the evidence is an approval from a person who did not write it, given on the code that merged. A pull request approved only by the person who asked the agent for it, or only by an AI reviewer, is the exception an auditor will ask about.

All of it in one run, free

$ npx --allow-git=root github:agentwares/agent-merge-audit OWNER/REPO --period 2026-Q3

Every merged pull request in the period, with whether an agent wrote it, whether a person other than its authors approved it on the final code, who merged it, the rule, and the exceptions, as a dated CSV and markdown pair. Your own GitHub token, or none for a public repo; GETs to GitHub's API only. Also as a GitHub Action, uses: agentwares/agent-merge-audit@main, and a local MCP server: github.com/agentwares/agent-merge-audit.

A continuous, hash-chained record of every agent change, kept across your audit window, is not built

It would record each merge as it happens (who or what wrote it, who approved it, who merged it, under which rule) in okgate's hash-chained log, with a quarterly CC8.1 export and a read-only link for your auditor, so the rule at a merge eleven months ago is on record.

What works today, free: okgate's hook mode holds an agent's git push or merge in Claude Code, Codex and Gemini CLI until a person types the go-ahead, and logs each decision in a hash-chained log on your machine.

$ npx -p @agentwares/agentguard okgate hooks install

What okgate sells today keeps your agents' tool calls through its proxy, not merges: 90 days of hash-chained log on Pro ($99/month), 365 days with a compliance export on Team ($299/month).

I want that record

Sources, each read on 9 October 2026