← All integrations

Scopebond for GitHub · Available now

Every change an AI agent proposes, checked against your rules before it can land

Coding agents deliver their work as pull requests on GitHub. The Scopebond GitHub Action adds a required check that fails when an agent's change steps outside your rules, names which agent wrote it, and keeps a signed record — running in your own Actions runner, with no Scopebond-held credential.

Make the Action a required check so a change that breaks your rules cannot merge.

#4821Refactor billing retriesAI coding agent
Build and testspassed
Scopebond rulesfailed · touches production settings
Merging is blocked until the Scopebond check passes. Rule: no agent changes to production paths. A signed record of this decision has been kept.

Add it in your workflow

Drop this into .github/workflows/scopebond.yml, then make the check required in your branch ruleset. Node ≥ 22.13 in the runner.

name: Scopebond
on: [pull_request]
jobs:
  scopebond:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: avouro-com/scopebond/packages/github-action@v1
        with:
          policy: scopebond.policy.json

A check that actually blocks

An agent change that touches production, exceeds a size you set, or targets a protected area fails the check and cannot be merged.

Know which agent did it

Each change is attributed to the agent that wrote it, and when we're inferring rather than certain, the record says so.

A record for every change

One signed record per pull request, what was decided and why, verifiable outside GitHub. Never your source code.

How it works alongside GitHub

What GitHub already gives you

Who may turn agents on, which repositories they can reach, required checks before merging, code owners.

What Scopebond adds

One set of rules across every coding agent you use; a signed, verifiable record per change; the same rules you run for Claude Code and Cursor on the desktop.

What neither does

Stop an agent from drafting a change in its own workspace, judge code quality, or catch manipulation inside the agent.

Set up in three steps

  1. 1
    Add the workflowcommit scopebond.yml and your scopebond.policy.json.
  2. 2
    Make the check requiredadd it to your branch ruleset; an admin approves it.
  3. 3
    Pick a starter rule"no agent changes to production", or write your own.

What it can't do, and says so

Scopebond can't see inside a cloud agent's private workspace. It stops the change being merged or deployed, and records exactly what was allowed or blocked. A repository that doesn't require the check, or a person allowed to bypass it, isn't covered.
Does it read our code?

It reads the change inside your own GitHub workflow and keeps only fingerprints and file paths, never file contents.

Can it stop an agent from opening a change?

No. It checks the pull request and stops it from merging when you make the Action a required check.