Code Policy Gate
Turn project rules into focused checks for every agent-generated change before it reaches a branch or deployment.
12 export async function GET() {
+13 writeFileSync('/tmp/export.csv', result)
14 return Response.json(result)
15 }
The gate
One rule, one question
Small questions make a policy file easier to test, explain and update.
Rule verdict
Check every rule with a clear complies, violates or insufficient-evidence result.
Risk signal
Score the impact of the change instead of treating every diff equally.
Reviewer route
Choose the owner, human review or safe stop before merge.
The gate
Number the rules
Give every important instruction a stable ID for results and audit logs.
Pass the diff as data
Keep the changed files, tests and task context together.
Separate unknown
Missing evidence should ask for review, not become a false pass.
Gate in the pipeline
Let deterministic CI and ownership policy apply the final result.
Review a diff
Use AI to inspect policy, not replace it
The model can identify evidence and gaps. Your repository rules and merge permissions remain authoritative.
{
"state": {
"rule": "Payment changes require an owner review and tests.",
"diff": "retry limit changed from 3 to 8; no tests added"
},
"questions": {
"complies": { "type": "noul", "instructions": "Does this diff comply with the rule?" },
"risk": { "type": "score", "instructions": "How risky is this diff?", "criteria": ["low", "review", "high"] },
"gate": { "type": "choice", "instructions": "What should happen next?", "criteria": { "merge": "continue", "review": "ask owner", "block": "stop" } }
}
}Load the rules
Read CLAUDE.md, AGENTS.md or your own policy source.
Check each rule
Ask whether the diff complies, violates or lacks enough evidence.
Apply the gate
Let CI request a reviewer, block the merge or continue safely.
FAQ
Questions about code policy
Does this replace CI rules?+
No. Use Jev to inspect evidence and route review, while deterministic checks and permissions remain authoritative.
What if the diff does not contain enough evidence?+
Return an insufficient-evidence or review result instead of treating missing proof as compliance.
Can I connect this to an agent?+
Yes. The agent can request the check, but the harness should own the merge or deployment permission.
