# Agent authorization pilot scorecard

This manual scorecard evaluates a narrow workflow. It does not establish security effectiveness, production readiness, or control over every agent tool. Keep safe-mode rehearsals separate from live GitHub operations.

**Keep private:** do not include tokens, passkey material, private source code, customer data, or raw sensitive logs. Store evidence in an approved location. Redact repository identifiers, request identifiers, people, and evidence links before external sharing.

## Evaluation agreement

- Pilot owner and reviewer: __________
- Evaluation period and environment: __________
- Selected non-critical repository: __________
- Question the pilot should answer: __________
- Comparable baseline, if available: __________
- Criteria for continuing, fixing, or stopping: __________

## Record each original request once

| Measure | Observation |
| --- | --- |
| Private request reference | ___ |
| Evidence type: live / rehearsal / unknown | ___ |
| Exact repository, unique branch, and existing SHA understood | yes / clarification needed / unresolved |
| Policy result | ___ |
| Human approval status | ___ |
| Explicit execution requested | yes / no |
| Provider comparison | matched / mismatched / absent / unknown |
| Review effort | ___ minutes / unmeasured |
| Reconciliation effort | ___ minutes / unmeasured |
| Alternate credential questions | ___ |
| Denial, abandonment, or uncertainty reason | ___ |

Associate retries with the original request. Count approvals separately from completed writes. A completed live operation requires reconciled execution evidence and independent provider readback of the reviewed branch and SHA. Approval alone is not completion.

## End-of-period decision

- Original live requests: ___; rehearsals: ___; unknown: ___
- Matched live outcomes: ___; mismatches: ___; unresolved: ___
- Clarifications required and why: __________
- Changes to definitions during the period: __________
- Open questions, owners, and next steps: __________
- Decision: continue same scope / fix named issue / stop

Report counts alongside any percentages. Direct credentials can bypass Gated. The supported pilot is exact branch creation; merge, deletion, and deployment governance are outside it.
