Change
| Name | change |
| Enabled by default | Yes |
| Steps | 18 |
| Runs at once | up to 3 |
| Catalog | v0.2.0 |
What it does
The steps every Change moves through, from an issue that is ready for an agent to a merge on main. The product-feature-builder opens the pull request, the change-review AgentRoles each fix or judge one concern on the Change branch, the Change is promoted to the rc zone, the e2e-verifier captures the proofs, and a human approves from those proofs before the merge. Work an agent cannot finish is dead-lettered to a human instead of failing silently. Human approval cannot be removed.
When it runs
- On every Change. Runs for every Change opened against a Product repo.
- On the event
issue.ready-for-agent. Runs when an issue moves to Todo (agent) on the board, starting with the builder.
Steps
Rounded steps are human gates, slanted steps are promotions, and double-edged steps run automatically.
| # | Step | Type | Runs | Required | On failure | Attempts |
|---|---|---|---|---|---|---|
| 1 | build | AgentRole | Feature builder | Yes | Dead-letter to a human | 2 |
| 2 | policy-review | AgentRole | Policy reviewer | No | Dead-letter to a human | 1 |
| 3 | lint | AgentRole | Lint fixer | No | Dead-letter to a human | 2 |
| 4 | dependency-currency | AgentRole | Dependency currency | No | Continue | 1 |
| 5 | merge-conflicts | AgentRole | Merge conflict resolver | No | Dead-letter to a human | 3 |
| 6 | ci | AgentRole | CI resolver | No | Dead-letter to a human | 3 |
| 7 | unit-tests | AgentRole | Unit test fixer | No | Dead-letter to a human | 2 |
| 8 | quality-review | AgentRole | Quality reviewer | No | Dead-letter to a human | 1 |
| 9 | security-review | AgentRole | Security reviewer | Yes | Dead-letter to a human | 1 |
| 10 | performance-review | AgentRole | Performance reviewer | No | Dead-letter to a human | 1 |
| 11 | sre-review | AgentRole | SRE reviewer | No | Continue | 1 |
| 12 | versioning | AgentRole | Version manager | No | Dead-letter to a human | 1 |
| 13 | architecture-review | AgentRole | Architecture and doc reviewer | No | Continue | 1 |
| 14 | docs | AgentRole | Docs writer | No | Continue | 1 |
| 15 | promote-rc | Promotion | Promote to zone rc | Yes | Dead-letter to a human | 1 |
| 16 | e2e-verify | AgentRole | End-to-end verifier | Yes | Dead-letter to a human | 2 |
| 17 | human-approval | Human gate | Human gate | Yes | Fail the run | 1 |
| 18 | merge | Automatic | Automatic | Yes | Dead-letter to a human | 1 |
1. build
Implements the issue in small verified increments on its own branch, adds tests, and opens the pull request linked to the issue. Skipped when a human opened the Change.
Runs only when change.author in [agent]. Skipped when its AgentRole is switched off.
2. policy-review
Checks licenses, banned libraries, secrets and forbidden paths against the org's denylists.
Skipped when its AgentRole is switched off.
3. lint
Runs the repo's linters and formatters and commits the fixes.
Skipped when its AgentRole is switched off.
4. dependency-currency
Flags or bumps outdated dependencies the Change touches, following the org's library preferences.
Skipped when its AgentRole is switched off.
5. merge-conflicts
Rebases onto the base branch and resolves conflicts while keeping both sides' intent.
Times out after 30m. Skipped when its AgentRole is switched off.
6. ci
Waits for CI, and diagnoses and fixes any failing check on the Change branch.
Skipped when its AgentRole is switched off.
7. unit-tests
Fixes broken unit tests and adds missing ones for the changed code.
Skipped when its AgentRole is switched off.
8. quality-review
Reviews test quality and code correctness, and adds or fixes tests and code.
Skipped when its AgentRole is switched off.
9. security-review
Scans for malicious edits, secrets and known vulnerabilities. A BLOCK verdict stops the Change.
Skipped when its AgentRole is switched off.
10. performance-review
Benchmarks the changed paths and blocks alarming regressions.
Skipped when its AgentRole is switched off.
11. sre-review
Adds metrics, logs, traces and alerts, and updates internal runbooks.
Skipped when its AgentRole is switched off.
12. versioning
Classifies the Change for semver, and records breaking changes and upgrade notes.
Skipped when its AgentRole is switched off.
13. architecture-review
Reviews the Change against the architecture docs and decision records and updates internal docs.
Skipped when its AgentRole is switched off.
14. docs
Updates internal and external product docs for the Change and runs the humanifier pass.
Skipped when its AgentRole is switched off.
15. promote-rc
Builds the Change and opens a pin PR that promotes its image (tag@sha256) to the rc zone, then waits for Synced and Healthy.
16. e2e-verify
Runs end-to-end tests in the rc zone and captures screenshots, video and a coverage report as the reviewable proofs.
Skipped when its AgentRole is switched off.
17. human-approval
A human reviews the proofs, the verdicts of every step and the diff, then approves or sends the Change back. One approval from @platform/reviewers is needed; after 72 hours without one the step escalates to the dead-letter reviewer. This step cannot be removed.
Needs 1 approval from @platform/reviewers. Times out after 72h and escalates.
18. merge
Merges to main once every required check is green and the approval is recorded.
When it hands off to a human
Human gates: human-approval. Required steps cannot be switched off for a Release.
Work an agent cannot finish is dead-lettered to @platform/reviewers. The AgentWorkflowRun shows the step as DeadLettered until a human picks it up.