docs(rfc): record the Lead's merge-rail amendment as settled decision #16 - #193
Conversation
ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe merge policy now permits the Relayflow Lead to merge only when four conditions pass. The RFC, charter, and Rails guidance apply the same exception and retain human approval for all other cases. ChangesMerge policy
Estimated code review effort: 2 (Simple) | ~10 minutes Poem
Note 🎁 Summarized by CodeRabbit FreeYour organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Essentials by visiting https://app.coderabbit.ai/settings/billing. Comment |
RFC-0001 gives the Relayflow Lead two hard rails: it never merges, and it cannot edit the gates that judge its work. **I merged 16 PRs on 2026-09-05 while the first rail said I never merge.** I was acting on an explicit standing instruction -- "MERGE ONLY with a passing independent signoff at the exact head plus green CI" -- so it was authorized rather than freelancing. But document and practice contradicted each other for a full night, and I only noticed because I opened that line to check the OTHER rail. Khaliq's ruling: "yes if fully verified you can merge". The rule is now **settled decision #16**, with four conditions that must ALL hold: an independent signoff at the exact head (and what "independent" means -- not the Lead's own judgement); green CI at that same head, compared by commit sha rather than check name; a target that is not a push-deploying branch, since cloud main deploys to production; and a change that is not about the Lead's own authority or its gates. **Three documents state this rail, and review caught me leaving each of them wrong in turn.** That is worth recording, because the amendment exists precisely because a rail and a practice drifted: * AGENTS.md still said "a human merges" -- and it is the file every agent reads first. Landing the RFC change alone would have reproduced the drift this amendment closes, while complaining about that drift in its own text. * charter/LEAD.md still said "You never merge." Before this diff the charter and the RFC agreed; the diff made them disagree, and the charter is what governs the actor receiving the authority. * Worst of the three: my AGENTS.md summary compressed condition (d) to "not about its own authority", **dropping "or its gates"**. The conditions are all-or-nothing, so that silently widened the Lead's authority in the file agents actually read -- and "never edit a gate" does not cover the Lead MERGING someone else's gate edit, which is exactly what (d) closes. I committed the same failure class this PR exists to fix, inside the PR that fixes it. All three now state the rule identically, verified by grep rather than by reading. The lead-in was also reworded: "Two hard rails carry over" had survived while one of its referents moved to §6. Not self-merging. This changes the constitution about my own merge authority, and #16(d) -- which this commit writes -- excludes exactly that. It waits for Khaliq. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR Session-Id: c228933d-4f94-4d83-9a9a-daf3c83b94f1
ecaa072 to
34b8028
Compare
…s in the anti-drift PR Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR Session-Id: c228933d-4f94-4d83-9a9a-daf3c83b94f1
Not for me to merge. This changes the constitution about my own merge authority, and decision #16(d) — which this PR writes — excludes exactly that. It waits for you.
Why
RFC-0001 gives the Relayflow Lead two hard rails: it never merges, and it cannot edit the gates that judge its work.
I merged 16 PRs on 2026-09-05 while that first rail said I never merge. I was acting on an explicit standing instruction — "MERGE ONLY with a passing independent signoff at the exact head plus green CI" — so it was authorized rather than freelancing. But the document and the practice contradicted each other for a full night, and I only noticed because I opened that line to check the other rail. Asked Khaliq; the ruling was "yes if fully verified you can merge".
This records that where the constitution states the rule, instead of leaving it in a chat log for a future session to reconstruct.
What review changed
The first draft put the amendment in the Lead paragraph as prose. Three fair catches:
AGENTS.mdstill said "a human merges", and that is the file every agent reads first. Landing the RFC change alone would have reproduced the exact drift the amendment exists to close — while complaining about that drift in its own text.What it says now
Settled decision #16, with four conditions that must all hold:
Anything short of all four goes to a human. The Lead paragraph keeps one sentence of provenance and points at the decision.
AGENTS.mdrecords the exception and says plainly that it is the Lead's alone.The second rail is untouched and unconditional — which is why the review-swarm's missing
agent-relayinstall has sat unfixed all night rather than being quietly patched.🤖 Generated with Claude Code
https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR