Skip to content
Gated

Human review

Prepare a GitHub branch request for human review

Give a reviewer the exact repository, unique branch name, existing commit, and evidence needed to assess one branch request.

Gated · · Private-preview evaluation guide

Turn the task into one concrete operation

A task description explains the desired work. A branch request explains the specific change a person is being asked to authorize. Put the selected repository, proposed new branch name, and full existing commit SHA together. Include a short reason that connects those inputs to the task, without implying permission for later actions.

GitHub represents a branch as a reference to a commit. GitHub’s REST Git references documentation describes that provider concept. Gated’s private preview narrows the operation to creating one uniquely named branch at an exact existing commit in a selected non-critical repository. It does not include branch updates, deletion, merges, force pushes, or deployments.

Review the target and its consequences

Confirm that the repository is the one selected for the pilot and that the commit exists there. A familiar branch label is not a substitute for the full SHA: a label may refer to a different commit when someone reviews it later. Record the exact value the person reviewed.

Check repository automation before a live request. Creating a branch may trigger workflows or other configured activity. A non-critical repository can still have privileged automation. The reviewer should understand these consequences and consult the repository owner when the effect is unclear.

  • Repository: the exact owner and repository selected for the pilot.
  • New branch: a unique name for this request, checked against provider state.
  • Commit: the full existing SHA, with a record of how it was verified.
  • Context: the intended task and relevant repository automation.

Keep each decision visible

Record the policy decision separately from the reviewer’s authorization. When policy requires human approval, the person reviews the specific request and confirms with a passkey. That confirmation does not start execution. Execution must be explicitly requested through the controlled GitHub path.

If the repository, branch, or commit changes, pause the review and treat the changed inputs as a new request. Do not describe an earlier approval as covering a similar operation. Independent provider credentials remain outside this controlled path even when the approved request is precise.

Close the review with provider evidence

After explicit execution, compare the receipt with independent GitHub readback of the branch and commit. Record whether both match the reviewed inputs. A policy result or passkey confirmation alone is not evidence that a branch exists.

If the response is lost or the evidence disagrees, record an uncertain outcome and inspect request status and provider state before another write attempt. The downloadable worksheet gives the reviewer one place to record inputs, decisions, and the final comparison without collecting credentials.

Provider reference: GitHub REST API documentation for Git references. Provider API behavior is separate from Gated’s scoped execution path.

Evaluate one controlled GitHub workflow

Read the verified GitHub scope and pilot entry steps. Join the update list if you want to follow the preview. Signup does not grant immediate access or commit you to a purchase.

Private-preview updates · Joining does not grant immediate access