Approval required
An agent proposes a change covered by the policy.
Acceptance target: The protected path waits for the named reviewer.
Illustrative evaluation · not a customer case study
A team already reviews changes before deployment. It wants a portable record of who authorized each selected commit. Here is how a scoped GitHub evaluation could test that requirement.
$10,000 · 2 weeks · fixed fee
These are proposed acceptance tests, not reported results. Enforcement depends on the integration version, configuration, and bypass permissions. Findings may include gaps that need further work.
An agent proposes a change covered by the policy.
Acceptance target: The protected path waits for the named reviewer.
The reviewer denies that request.
Acceptance target: The selected action stays blocked on the configured path.
The reviewer approves a fresh request for the intended commit.
Acceptance target: The gate recognizes that authorization and produces the expected receipt.
The commit changes after approval.
Acceptance target: The earlier approval cannot authorize the new change.
The authorization service is unavailable during a test.
Acceptance target: Observe the actual behavior, compare it with the agreed requirement, and record any gap.
The reviewer inspects the artifact and verifies its signature.
Acceptance target: The record matches the action, approver, policy, and time; verification is reproducible.
The agreed deliverables include the workflow configuration, test results, signed artifacts with verification instructions, and an acceptance readout documenting findings and open gaps. Your reviewer decides whether the evidence meets the requirement.
The two-week clock starts once agreed access is available. A broader rollout or extension requires a separate agreement. This example does not promise certification, auditor acceptance, or coverage of other execution paths.