Risk-Tiering Repositories for AI Agent Access
Assign every repository or path to one of four risk tiers — Standard, Elevated, Restricted, Prohibited — and map each tier to specific CI/CD enforcement rules. The tiering is the policy; CI is the enforcement.
Why one blanket policy fails
A single rule for all repositories either over-restricts — so engineers route around it — or under-restricts, and you get an incident in your most sensitive code. Risk-tiering resolves the tension: agents move fast where the blast radius is small, and face stricter controls where it is large.
The four tiers
A workable default taxonomy:
- Standard: low-risk code (internal tooling, docs, tests). Agents may open PRs; normal review applies.
- Elevated: application code with customer impact. Agent PRs require code-owner review and full status checks.
- Restricted: security-sensitive paths (auth, payments, infra-as-code). Agent access is read-mostly; changes require senior + security review.
- Prohibited: secrets, key material, compliance-controlled code. No agent access at all.
Make the tier mechanical, not a judgment call
Encode the tier in something enforceable: CODEOWNERS entries, path-based branch-protection rules, and CI jobs that key off the changed paths. The point is that the tier triggers the right controls automatically, rather than relying on a reviewer to remember which rules apply where.
Frequently asked questions
How many tiers should we use?
Four is a good default (Standard, Elevated, Restricted, Prohibited). Fewer collapses meaningful distinctions; more becomes hard to maintain and explain. Start with four and merge or split only if a tier is doing no work.
Where do most teams get the tiering wrong?
By leaving it as a document instead of encoding it. If the tier isn't wired into CODEOWNERS and CI enforcement, it degrades into a reviewer's memory — which fails exactly when it matters.
Related guides
Governed AI engineering, in your inbox
Occasional, practical notes for engineering leaders on putting AI to work without losing control. No spam; unsubscribe anytime.
Subscribe