AI Code Review

Policy Aware PR Approval Agents

Amartya | CodeAnt AI Code Review Platform
Emroz Ahmed

Product Marketing

The next step towards autonomous SDLC: policy-aware PR approval and verified fixes.

Many of the pull requests waiting on a second approval are low risk: a test change, a copy fix, a dependency bump. Someone still has to open each one, read it and click approve, and until they do, the PR sits. As coding agents open more pull requests every week, that queue only gets longer.

We’re building towards an autonomous software development lifecycle, where review, verification and approval run on their own under rules your team sets, and people spend their time on the decisions that need them. This release takes on one of the last steps that still needed a person on every pull request.

Approval was still manual

CodeAnt AI already reviews every pull request, suggests fixes, and resolves its own comments once they’re addressed. Approval was the step that still needed a person, even when the change was a renamed variable or a new test.

Auto-approval existed, but it followed one rule: approve once CodeAnt AI’s comments are resolved. It couldn’t tell a change to test fixtures from a change to billing logic.

Approval that follows your policy

The policy-aware approval agent adds judgement. It runs after every CodeAnt AI review, whether that review came from a new pull request, a new commit or a PR marked ready, and again whenever a review thread is resolved. It only steps in once every CodeAnt AI thread on the pull request is resolved.

Then it reads the change the way a reviewer would: the title and description, which files changed, how much changed, and the diff itself. It weighs all of that against three things your team controls: the risk you’re willing to accept, criteria you’ve written in plain English, and a policy that lives in the repository next to the code. It comes back with a risk level, a confidence score and any blockers, and it approves only when all of them clear your bar.


Auto Approve PR now offers three modes: Off, Resolved comments, and Policy agent.

Payment logic can always go to a person. Test-only changes can go straight through. You write the decision once, and it applies to every pull request.

{
  "id": "billing-code",
  "description": "Payment logic changes need a human reviewer.",
  "files": ["billing/**", "**/*invoice*"],
  "decision": "human_review"
}
{
  "id": "billing-code",
  "description": "Payment logic changes need a human reviewer.",
  "files": ["billing/**", "**/*invoice*"],
  "decision": "human_review"
}
{
  "id": "billing-code",
  "description": "Payment logic changes need a human reviewer.",
  "files": ["billing/**", "**/*invoice*"],
  "decision": "human_review"
}

A rule in the repository’s approval policy: any change to billing code goes to a person.

Sensitive code stays with people by default

Some changes shouldn’t be approved by software unless you’ve said so. Out of the box, the agent sends these to a person:

  • Authentication and authorization

  • Secrets

  • Payments

  • Database migrations

  • Infrastructure

  • Dependencies

  • CI/CD pipelines

Your policy can open any of them up, but nothing opens up on its own. The defaults lean the same way. The agent ships in shadow mode, with the lowest risk limit. Every step towards more automation is one your team takes on purpose.

Trust it before you turn it on

Nobody should hand approvals to software on day one, which is why shadow mode is the default. In shadow mode, the agent evaluates every pull request and posts what it would have decided and why, without approving anything. Your team sees its calls next to their own and switches to enforcing decisions only once they agree.

Built to say no when it’s unsure

  • It can’t approve a change to its own policy. The rules are read from the branch you merge into, so a pull request can never loosen them for itself.

  • It approves exactly what it checked. Before deciding, it confirms the pull request still points at the commit it reviewed, and the approval is tied to that commit. A new push cancels it, as it would for any reviewer.

  • If it can’t see the whole change, a person decides. An incomplete diff, an invalid policy, or a rule that asks for human review sends the pull request to a person.

  • If something breaks, it waits. When it can’t fetch the pull request or the policy, or the model call fails, it holds the decision rather than guessing.

  • Your branch protection still applies. CodeAnt AI counts as one reviewer, nothing more.

A resolved thread should mean a fixed one

The approval agent starts from resolved review threads, so those threads have to be honest. When a later commit addresses a CodeAnt AI suggestion, CodeAnt AI now confirms it in the thread: which commit fixed it and what changed. If it can’t confirm the fix, it says nothing and the thread stays open. This now runs on Azure DevOps too.

What’s next

Review, verification and approval now run as one loop. It finishes on its own when a change is safe and hands off to a person when it isn’t. That’s the next step towards an autonomous SDLC, and there’s more coming.

Policy-aware approval is available today on GitHub and GitHub Enterprise. Read the docs to set it up: https://docs.codeant.ai/pull_request/features/auto_approve_pr

FAQs

Is it safe to let AI agents approve pull requests?

How does CodeAnt AI decide whether to approve a pull request?

Which code changes should always get a human reviewer?

How can a team test AI pull request approval before turning it on?

Does AI approval replace human reviewers or branch protection?

Start Your 14-Day Free Trial

AI code reviews, security and quality trusted by modern engineering teams.

Table of Content
No headings found on page

Ship clean & secure code faster

Get Pentest Report

NO CC REQUIRED