Found while rewriting the two stale sha-pin passages for #7605 (PR #7616). Filed rather than fixed there: that dispatch scoped the prose to the ruled predicate and its accepted cost, and this is a different sentence.
The gap
scripts/check-governed-queue-guard.mjs states a normative seat rule in its header, and its refusal text prints it too:
⛔ An agent seat never submits an approving review on a governed-surface pull request, under any account. Every seat in this repository writes under a shared GitHub identity, so GOVERNED_APPROVERS is a technical control that is only as good as that normative rule.
AGENTS.md § 受管面 does not carry it. What it carries (the paragraph beginning 「⛔ 绝不 gh pr ready」) is the adjacent set — never ready, never enqueue, never auto-merge, never self-merge, plus 「别去等一个不存在的 approval」. A seat that reads only AGENTS.md learns not to merge and not to wait for an approval; it is never told not to leave one.
Why it got weightier on 2026-09-04
The maintainer's ruling (executed as PR #7606, merged 0d8fd7ce) retired the sha pin, and the guard's header says out loud what that does to this rule:
⚠️ With the pin retired that rule carries MORE weight, not less: one approval now clears every later push on the same pull request.
Before the ruling, a seat-submitted approval decayed on the next push. It no longer does — one such approval clears the queue leg for every commit that follows on that pull request. GOVERNED_APPROVERS restricts which account may approve, and under a shared GitHub identity that is not the same thing as restricting who may approve.
Suggested shape
One sentence in AGENTS.md § 受管面, next to the existing ⛔ list, copied from the guard header rather than paraphrased — the same discipline #7605 applied to the predicate, so the three places cannot drift. AGENTS.md is a governed surface, so this is a draft pull request parked for a human merge; that is the regime, not an obstacle.
Filed by the objectui skills seat working #7605, session session_019RfFHiRCSs3JXLK4cwcfox, under a shared GitHub identity — the branch on that card's pull request is the identifying detail, not the author field. Left unassigned and unlabelled for PM triage.
Generated by Claude Code
Found while rewriting the two stale sha-pin passages for #7605 (PR #7616). Filed rather than fixed there: that dispatch scoped the prose to the ruled predicate and its accepted cost, and this is a different sentence.
The gap
scripts/check-governed-queue-guard.mjsstates a normative seat rule in its header, and its refusal text prints it too:AGENTS.md§ 受管面 does not carry it. What it carries (the paragraph beginning 「⛔ 绝不gh pr ready」) is the adjacent set — never ready, never enqueue, never auto-merge, never self-merge, plus 「别去等一个不存在的 approval」. A seat that reads onlyAGENTS.mdlearns not to merge and not to wait for an approval; it is never told not to leave one.Why it got weightier on 2026-09-04
The maintainer's ruling (executed as PR #7606, merged
0d8fd7ce) retired the sha pin, and the guard's header says out loud what that does to this rule:Before the ruling, a seat-submitted approval decayed on the next push. It no longer does — one such approval clears the queue leg for every commit that follows on that pull request.
GOVERNED_APPROVERSrestricts which account may approve, and under a shared GitHub identity that is not the same thing as restricting who may approve.Suggested shape
One sentence in
AGENTS.md§ 受管面, next to the existing ⛔ list, copied from the guard header rather than paraphrased — the same discipline #7605 applied to the predicate, so the three places cannot drift.AGENTS.mdis a governed surface, so this is a draft pull request parked for a human merge; that is the regime, not an obstacle.Filed by the objectui skills seat working #7605, session
session_019RfFHiRCSs3JXLK4cwcfox, under a shared GitHub identity — the branch on that card's pull request is the identifying detail, not the author field. Left unassigned and unlabelled for PM triage.Generated by Claude Code