Problem
On a hosted Team Environment, a named person always publishes and the agent never merges (root decision 0148, Team Environment addendum). The brokered gh adapter does not enforce this:
DENIED_COMMANDS in adapter/brokered-gh.mjs covers only auth, alias, config, extension and search;
gh pr merge is classified repository and runs with the write-tier token the broker mints for the Team's live grant.
Observed
In one Organization, the Team identity merged 13 pull requests in about a day (2026-10-04/05). They spanned the Organization root and several module and data repositories, and included pull requests authored by people. This happened before the Folder rule reached those Environments; none has been merged since.
The Organization's GitHub plan offers no branch protection for private repositories. Nothing else stopped the merges; two of them changed the Organization root repository, which every Environment of the Organization pulls.
Proposal
- Deny
gh pr merge, and the merge endpoints through gh api (PUT repos/{owner}/{repo}/pulls/{n}/merge, GraphQL mergePullRequest), in a Team Workspace. The message should name the hand-over: ask the Operator whom to ask, request that person's review, and assign the pull request to them.
- State clearly that a direct
git push to the default branch is still possible with a write-tier token; only branch rules on GitHub close that.
Source: v0.11.0 adapter/brokered-gh.mjs (classifyGhCommand).
Problem
On a hosted Team Environment, a named person always publishes and the agent never merges (root decision 0148, Team Environment addendum). The brokered
ghadapter does not enforce this:DENIED_COMMANDSinadapter/brokered-gh.mjscovers onlyauth,alias,config,extensionandsearch;gh pr mergeis classifiedrepositoryand runs with the write-tier token the broker mints for the Team's live grant.Observed
In one Organization, the Team identity merged 13 pull requests in about a day (2026-10-04/05). They spanned the Organization root and several module and data repositories, and included pull requests authored by people. This happened before the Folder rule reached those Environments; none has been merged since.
The Organization's GitHub plan offers no branch protection for private repositories. Nothing else stopped the merges; two of them changed the Organization root repository, which every Environment of the Organization pulls.
Proposal
gh pr merge, and the merge endpoints throughgh api(PUT repos/{owner}/{repo}/pulls/{n}/merge, GraphQLmergePullRequest), in a Team Workspace. The message should name the hand-over: ask the Operator whom to ask, request that person's review, and assign the pull request to them.git pushto the default branch is still possible with a write-tier token; only branch rules on GitHub close that.Source: v0.11.0
adapter/brokered-gh.mjs(classifyGhCommand).