ForgeLayer

AgentOS provider-aware routing

Deterministic compatibility, separate from control eligibility.

Modeled fit uses server-owned capabilities. It is not provider performance, assignment, approval, verification, dispatch, or execution.
Deterministic recommendationNot assigned

Claude Code

secure payment webhook

Highest modeled fit
95/100
Recommendation state
deterministic recommendation
Recommendation use
available for human review
Routing analysis
routing-analysis-secure-payment-webhook
Task / repository
controlled-task-secure-payment-webhook / repository-connection-preview-secure-payment-webhook
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z

AI PR control layer

MergeGuard

Control AI-generated pull requests before they reach production.

AI-generated pull requests reviewed, controlled, and recorded before merge.

MergeGuard does not replace GitHub or human reviewers. It adds policy, risk, evidence, approval, and audit control around AI-generated software work.

Repository prerequisite

MergeGuard consumes the payment repository preview without claiming GitHub truth.

The repository identity, path scope, policy snapshot, PR number, check preview, and comment preview are deterministic fixtures. GitHub installation and ownership are unverified; metadata, contents, PRs, and checks were not fetched.

GitHub · repository host

acme-payments/payment-webhook-service

Recorded preview

Secure Payment Webhook · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Inactive
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (2)
  • app/api/payments/webhook.ts
  • tests/payment-webhook.test.ts
PR previewdeterministic · not fetched
GitHub postingdisabled
Automatic mergedisabled
Repository verificationnot run
Approvalblocked_platform
Revocation / kill switchnot_revoked / inactive

The problem

AI speed creates a control gap

AI coding tools can produce changes faster than teams can verify policy, evidence, security impact, and ownership. MergeGuard makes those controls visible before production.

Capabilities

One controlled PR decision surface

PR diff inspection

Inspects the submitted pull request diff within configured safety limits.

RepoBrain policy context

Applies repository-owned rules, protected paths, and required review signals.

Risk classification

Classifies software risk and produces a controlled merge recommendation.

Review Run lifecycle

Tracks received, queued, processing, completed, failed, manual-review, and blocked states.

GitHub Check Preview

Models the GitHub-native check status without creating a real Check Run.

PR Comment Preview v2

Creates a safe, copy-ready review comment while posting remains disabled by default.

Evidence and human review

Surfaces missing tests, required evidence, and approval gates before merge.

Merge recommendation

Returns merge, merge-after-changes, or block guidance from review evidence.

Work Record and Ledger connection

Connects the decision to the Agent Work Record and AI Work Ledger foundations.

Workflow

PR opened to recorded decision

Step 01

PR preview recorded

A deterministic repository fixture represents a future pull-request intake.

Outcome: Preview context is available; no GitHub PR was fetched.

Step 02

Intake preview recorded

ForgeLayer models the intended event, action, and repository boundary without receiving a GitHub webhook.

Outcome: A deterministic Review Run preview begins.

Step 03

Policy snapshot bound

RepoBrain applies a deterministic policy snapshot; forgelayer.yml is not fetched from GitHub.

Outcome: Preview policy context is attached.

Step 04

Fixture scope inspected

MergeGuard evaluates bounded deterministic changed-path and review fixtures.

Outcome: Preview work is classified without repository-content access.

Step 05

Risks and evidence evaluated

Tests, approvals, protected paths, and proof gaps are evaluated.

Outcome: Required human checks are explicit.

Step 06

Check and comment previews created

Preview-only GitHub Check and PR comment artifacts are generated.

Outcome: The GitHub-facing decision is inspectable.

Step 07

Human review required

A reviewer confirms evidence and the merge decision.

Outcome: No automatic merge occurs.

Step 08

Result recorded

The Review Run becomes a safe AI Work Ledger foundation record.

Outcome: The decision has an audit trail.

Required checks

Merge recommendations keep independent verification open.

MergeGuard consumes the safe normalized manifest and Policy Engine requirements. It does not claim the proposed diff is verified.

Policy-owned requirements

  • payments-protected-path:verification:payment-webhook-security · unsatisfied
  • payments-protected-path:verification:auth-session-boundary · unsatisfied

Runner state

Repository commands: not run. Verification transport: disabled. Internal metadata controls do not prove code correctness or security.

Open Required Checks

Current evaluator state

Approval is satisfied; platform controls still block progression.

Approval requirement satisfied. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.
Approval requirement satisfied

The exact workspace-owner requirement is satisfied for this scoped payment fixture.

Repository verification required

Repository verification has not run and no result is inferred.

Execution transport disabled

No repository command, provider request, or external action can run.

Platform blocked

Dispatch remains disabled even though the scoped approval requirement is satisfied.

Approval Authority foundation

Approval is bound to one exact work state.

Authority, approval, revocation, kill switches, verification, and execution transport remain separate control dimensions.

secure payment webhook

Approval requirement satisfied. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

blocked platform
Required authority
workspace owner
Principal
Demo workspace owner / demo authority
Exact object
controlled-task-secure-payment-webhook
Repository
repository-identity-secure-payment-webhook
Risk / budget
HIGH / task-budget-secure_payment_webhook-v1
Dispatch authorization
dispatch-authorization-preview-db15b2cd
Verification plan
verification-plan-2458e6d26e940ec0
Evaluated at
2026-08-12T04:28:04.124Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
blocked platform
Approval requirement
Satisfied
Historical grant state
granted
Revocation
not revoked
Kill switch
inactive
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled

Approval requirement satisfied. Repository verification has not run, and execution transport remains disabled.

Immutable bindingsapproval-grant-integrity-a9cdee22ac5c873d5f817dc8policy-snapshot-5cc8bbf1capability-package-secure-payment-webhook-v1verification-plan-2458e6d26e940ec0
Reasoning trail (3)
  • The exact human approval requirement is satisfied.
  • Repository verification is incomplete.
  • Repository runners are not run and execution transport is disabled.
Grant conditions (3)
  • Repository verification remains separate.
  • Execution transport remains disabled.
  • Any immutable binding change requires reevaluation.
Append-only lifecycle (3)
  1. approval authority requested · historical lifecycle event: Exact authority and immutable scope were requested.
  2. approval granted · historical lifecycle event: A deterministic historical approval grant was recorded.
  3. workflow progression blocked · historical lifecycle event: Workflow progression remains blocked; repository execution was not running.

Simulated payment-only Review Run

Secure payment webhook replay handling

acme-payments/payment-webhook-service

Approval requirement satisfied. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

GitHub Check Preview

ForgeLayer preview: merge blocked

Preview-only GitHub check status: completed/failure. Risk: HIGH. Recommendation: needs_human_review. ForgeLayer is not creating GitHub check runs yet.

Preview-only policy artifact; current authority is evaluator-owned.

PR Comment Preview v2

ForgeLayer Review

ForgeLayer reviewed acme-payments/payment-webhook-service#142. Risk is HIGH; merge recommendation is needs human review.

Deterministic preview artifact; it is not the current approval state.

Generic platform guidance

Human authority stays in the loop

  • No automatic merge behavior.
  • GitHub posting is disabled by default.
  • No live agents or autonomous workflows.
  • Generic platform guidance: Human approval is required before merge.
  • GitHub Checks and PR comments remain preview-only in this surface.
  • Safe summaries exclude raw secrets, tokens, diffs, and repository rules.