📝text•6 months ago
Guardrailed Code Review Pipeline
Run a staged code review workflow with explicit risk assessment, reviewer handoffs, and merge gates.
coding
⭐1
# Guardrailed Code Review Pipeline
Imported from curated first-party documentation sources.
## What this covers
Use this workflow when a change needs structured review evidence, clear approval stages, and a rollback-aware path to merge.
## Use this when
- Multi-step L1 and L2 review signoff
- High-risk changes that need audit trails
- Standardizing reviewer decisions before merge
## Expected outcomes
- Review states and approval checkpoints stay explicit
- Risk assessment and evidence are captured before merge
- The workflow remains small enough to reuse across repositories
## Source synthesis
- AGENT33/docs/functionality-and-workflows.md (https://github.com/mattmre/AGENT33/blob/main/docs/functionality-and-workflows.md)
- AGENT33/docs/walkthroughs.md (https://github.com/mattmre/AGENT33/blob/main/docs/walkthroughs.md)
## Dedupe notes
Combines AGENT33 lifecycle mapping and operator walkthrough material into one review-oriented site entry.
## Source excerpts
### AGENT33/docs/functionality-and-workflows.md
### 4.1 Review Lifecycle
States:
- `draft -> ready -> l1-review -> l1-approved -> (optional l2-review -> l2-approved) -> approved -> merged`
Main APIs:
- `/v1/reviews/{id}/assess`
- `/v1/reviews/{id}/assign-l1`
- `/v1/reviews/{id}/l1`
- `/v1/reviews/{id}/assign-l2`
- `/v1/reviews/{id}/l2`
- `/v1/reviews/{id}/approve`
- `/v1/reviews/{id}/merge`
### AGENT33/docs/walkthroughs.md
## 4. Review Lifecycle (Two-Layer Signoff)
Create review:
```bash
curl -X POST http://localhost:8000/v1/reviews/ \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"task_id":"TASK-101","branch":"feat/docs-refresh","pr_number":12}'
```
Assess risk:
```bash
curl -X POST http://localhost:8000/v1/reviews/<review_id>/assess \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"triggers":["api-public","security"]}'
```
Move to ready and assign L1:
```bash
curl -X POST http://localhost:8000/v1/reviews/<review_id>/ready -H "Authorization: Bearer $TOKEN"
curl -X POST http://localhost:8000/v1/reviews/<review_id>/assign-l1 -H "Authorization: Bearer $TOKEN"
```
Submit L1 decision:
```bash
curl -X POST http://localhost:8000/v1/reviews/<review_id>/l1 \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"decision":"approved","issues":[],"comments":"L1 pass"}'
```
If L2 required, continue:
```bash
curl -X POST http://localhost:8000/v1/reviews/<review_id>/assign-l2 -H "Authorization: Bearer $TOKEN"
curl -X POST http://localhost:8000/v1/reviews/<review_id>/l2 \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"decision":"approved","issues":[],"commen
...
👍0
👁️0
docs