Agent-merge audit · SOC 2 CC8.1 · updated
Auditing Copilot coding agent pull requests
A pull request from GitHub Copilot's coding agent is opened by the account Copilot, and its commits name the person who asked for the change as co-author. GitHub does not count that person's approval toward a required review: someone else has to approve it. Since 1 September 2026 an admin can also let Copilot code review approve pull requests, and that approval does count toward the branch's required approvals. So for each Copilot pull request, the question is whether a person who did not ask for it approved it.
Two Copilots, one login
- The coding agent opens the pull request and writes its commits. Its account is
Copilot, from the GitHub App copilot-swe-agent. - Copilot code review comments on pull requests and, where an admin allows it, approves them. Its account is also
Copilot, from the GitHub App copilot-pull-request-reviewer. Its approval is a bot's, not a person's. - The person who asked is named as
Co-authored-byon the agent's commits. GitHub's docs: their approval of a Copilot pull request does not count, and another reviewer must approve.
List them by hand
Pull requests Copilot's coding agent opened, and who approved them
$ gh pr list --repo OWNER/REPO --state merged --author app/copilot-swe-agent --limit 200 --json number,mergedBy,reviews --jq '.[] | [.number, .mergedBy.login, ([.reviews[] | select(.state == "APPROVED") | .author.login] | unique | join(" "))] | @tsv'An approver listed as Copilot is Copilot code review, not a person. The person who asked Copilot for the change is named as co-author on its commits, and GitHub does not count their approval.
The branch's review rule, as it is now
$ gh api repos/OWNER/REPO/rules/branches/main --jq '.[] | select(.type == "pull_request" or .type == "copilot_code_review") | {type, parameters}'Rulesets only; classic branch protection needs gh api repos/OWNER/REPO/branches/main/protection with an admin's token. This is the rule today, not at each merge.
A copilot_code_review rule in the output means Copilot reviews pull requests on that branch. Whether its approval counts toward the required approvals is an admin setting; the evidence that a person approved has to come from the approvals themselves.
What to ask of each one
| If the pull request was | The question to answer |
|---|---|
| approved only by the person who asked Copilot for it | Who other than the requester reviewed it? |
| approved only by Copilot code review | Is an AI approval part of your documented control? |
| approved before the agent's last commit | Who reviewed what the agent changed after the approval? |
| merged with no approval | Was the branch rule off, bypassed or exempted? |
All of it in one run, free
$ npx --allow-git=root github:agentwares/agent-merge-audit OWNER/REPO --period 2026-Q3Every merged pull request in the period, with whether an agent wrote it, whether a person other than its authors approved it on the final code, who merged it, the rule, and the exceptions, as a dated CSV and markdown pair. Your own GitHub token, or none for a public repo; GETs to GitHub's API only. Also as a GitHub Action, uses: agentwares/agent-merge-audit@main, and a local MCP server: github.com/agentwares/agent-merge-audit.
A continuous, hash-chained record of every agent change, kept across your audit window, is not built
It would record each merge as it happens (who or what wrote it, who approved it, who merged it, under which rule) in okgate's hash-chained log, with a quarterly CC8.1 export and a read-only link for your auditor, so the rule at a merge eleven months ago is on record.
What works today, free: okgate's hook mode holds an agent's git push or merge in Claude Code, Codex and Gemini CLI until a person types the go-ahead, and logs each decision in a hash-chained log on your machine.
$ npx -p @agentwares/agentguard okgate hooks installWhat okgate sells today keeps your agents' tool calls through its proxy, not merges: 90 days of hash-chained log on Pro ($99/month), 365 days with a compliance export on Team ($299/month).