payments-dashboard/AGENTS.md
Adam Moussa 8dfb39914a
Some checks are pending
Deploy / deploy (push) Waiting to run
ci: add org PR policy caller (#87)
Refs: PLAT-62
2026-08-04 11:56:17 -04:00

1.4 KiB

AGENTS.md

Sea Haven Governance

Standards authority: The engineering handbook is the single authority for coding standards, naming conventions, and workflow configuration. Do not justify changes by citing it in PR bodies.

Work authority: Jira is the source of truth for work status. Before creating a ticket, search Jira for duplicates. Route product work to DEV, infrastructure and platform work to PLAT, and security work to SEC.

Branch names: Use feature/, fix/, hotfix/, chore/, docs/, refactor/, or release/ with a kebab-case description. Do not include Jira keys in branch names. Dependabot branches and emergency reverts are exempt from this rule.

PR title format: type(scope): description (DEV-123) — Jira key required on every non-exempt PR. Dependabot and permission-controlled emergency reverts are exempt.

PR body headings (exact, in this order):

  1. Summary
  2. Validation
  3. Tests
  4. Notes

Prohibited: AI-attribution footers in commits, PRs, comments, or generated artifacts.

Security gates:

  • PRs touching payment flows, authentication logic, secret handling, AWS IAM, or untrusted user input require security review.
  • IAM role, policy, or resource-permission changes require cross-family review.

CI workflow refs: All uses: workflow refs must be pinned to a full commit SHA with an inline version comment — owner/repo/.github/workflows/file.yaml@<full-sha> # vX.Y.Z. No floating tags or branch refs.