Skip to content
Critique v4 · AI change control platform for GitHub pull requests

AI change control for GitHub pull requests

Code agents create changes. Critique controls whether those changes can ship. This guide explains what AI change control means in 2026, how Critique’s Control Board and Change Passports work, and why merge-boundary governance is the category after comment-only AI review bots.

What “change control” means at the merge boundary

AI coding tools made creation cheap. The new bottleneck is trustworthy control before production: knowing whether a pull request — human or agent — should merge, with evidence you can audit later.

Comment-only AI review bots answer “what might be wrong in this diff?” Change control answers “is this change allowed to ship?” That requires gating untrusted PRs before review spend, running grounded multi-model review, enforcing merge policy after evidence exists, and recording the full story on one Change Passport.

The Control Board: your PR control plane

Critique v4 merges operator surfaces into /dashboard/control. Tabs cover Gate (Agent Firewall / Checkpoint), unified Policy (gate + review + merge slices), Findings Memory, Delivery health, and Incident learnings — not separate sidebar products.

  • Gate: block or warn before the review swarm spends on slop PRs
  • Policy: one model for installation defaults and per-repo overrides
  • Memory: suppressions and feedback with audit trail — no silent drops
  • Delivery: webhook auth, pipeline readiness, replay failed deliveries
  • Passports: queue and timeline for per-PR merge-boundary records
  • Learnings: promote incidents into policy drafts from the board

Three enforcement phases on every PR

PhaseWhenGitHub checkPurpose
GateBefore review queueCritique / CheckpointFast firewall: trust, shape, paths, deps
ReviewDuring runCritique / ReviewMulti-model evidence generation
MergeAfter evidenceCritique / Merge PolicyEnforceable merge rules with proof

Comment-only review vs change control

DimensionTypical AI review botCritique v4
Product objectReview comment threadChange Passport per PR
Operator UISettings scattered or noneUnified Control Board
Pre-review spendOften noneGate / Agent Firewall first
Blocking claimsUsually advisoryEvidence contract with evidenceId
Fix pathSuggestions or separate toolRemedy with proof bundle
MemoryOften none or silentAuditable suppressions + incident learnings

Six-step rollout playbook

  1. Step 1

    Map your merge boundary

    List every check that runs before merge today: CI, security scanners, CODEOWNERS, and any AI review bot. Note which checks enforce policy vs only comment. Critique v4 targets the gap between “green CI” and “allowed to ship.”

  2. Step 2

    Enable gate in dry-run

    Install Critique and run Checkpoint / Agent Firewall in dry-run on one repo. Observe which PRs would warn or block without stopping contributors. Tune contributor trust, PR shape, and file-risk rules before spending review credits.

  3. Step 3

    Stand up the Control Board

    Configure unified policy (gate + review + merge slices), delivery webhooks, and findings memory from /dashboard/control. Operators should not maintain three separate policy surfaces.

  4. Step 4

    Shadow review on representative PRs

    Run multi-model review on 10–20 recent PRs including agent-authored ones. Score findings against ground truth and verify each blocking claim cites an evidence ID in the passport.

  5. Step 5

    Promote gate to warn, then block

    Move from dry-run to warn on low-trust PR shapes, then block where policy requires. Keep GitHub branch protection on Critique / Checkpoint for stability.

  6. Step 6

    Require merge policy with proof

    After evidence exists, enforce merge rules (owners, risk band, remedy proof) via Critique / Merge Policy. Treat the Change Passport as the audit record, not scattered check-run logs.

Frequently asked questions

What is AI change control?
AI change control is governance at the merge boundary: deciding whether a human- or agent-generated pull request is allowed into the codebase, with auditable evidence. It includes pre-review gates, multi-model review, merge policy enforcement, findings memory, and verified repair — not just posting comments on a diff.
How is AI change control different from AI code review?
AI code review focuses on finding issues in a diff. AI change control owns the full PR lifecycle: gate untrusted changes before review spend, run evidence-backed review, enforce merge rules, store suppressions and incident learnings, and attach remedy proof. Critique v4 is categorized as an AI change control platform; review runs are evidence inside a Change Passport.
What is a Change Passport?
A Change Passport is Critique’s per-PR product object in v4: one auditable record chaining provenance, risk, evidence contracts, policy decisions, remedy proof, and memory. Multiple review runs can attach to one passport; operators read the passport story instead of hunting disconnected check runs.
What is the Critique Control Board?
The Control Board at /dashboard/control is the operator surface for gate (Agent Firewall / Checkpoint), unified policy, findings memory, delivery health, and incident learnings. v4 merges what used to be separate Automation, Checkpoint overview, and Change Gate pages into one engineering control room.
Is Critique just another code review CI bot?
No. Comment-only bots stop at GitHub review threads. Critique adds a three-phase enforcement model: Gate (Critique / Checkpoint) before review queue, Review (Critique / Review) during the run, and Merge (Critique / Merge Policy) after evidence — all visible on the Control Board and recorded on the Change Passport.
How does Critique relate to Cursor, Copilot, and coding agents?
Coding agents optimize for creation speed. Critique governs whether those creations ship: unknown agent sources, forbidden paths, dependency weakening, and override history can block or warn before expensive review. The positioning line is: agents write; Critique governs.
Does AI change control work with private GitHub repos?
Yes. Critique installs as a GitHub App with scoped permissions, does not train on customer code, and supports enterprise tenancy with SSO and audit logs. Gate, review, and merge checks publish as GitHub check runs your branch protection already understands.

Cursor writes. Critique governs.

Install the GitHub App, open the Control Board, and run your next agent-authored PR through gate → review → merge with a Change Passport you can actually audit.

Create account

Search paths

Related guides for buyers comparing AI review and control.

Pair this change-control guide with the AI code review guide, tool comparisons, and pricing research — most teams evaluate both categories in the same buying cycle.

Open source

Hundreds of PRs, no time to review?

PR control for foundations and high-volume OSS — Pro/Team for scale, verified OSS lane, OSS credits on request.

Open

Hub

All Critique guides

PR control, git control, manage pull requests at scale, AI change control, and AI code review — one index for operators.

Open

PR control

PR control for high-volume teams

Gate slop before review spend, Control Board operations, Change Passports, and auditable merge decisions on GitHub.

Open

Git control

Git control at the merge boundary

Govern what merges without replacing Git — Agent Firewall, unified policy, and passports for platform teams.

Open

Operations

Manage pull requests at scale

Triage queues, weekly operating rhythm, and PR management when agent volume explodes.

Open

Launch essay

Critique v4 — full platform breakdown

v3 vs v4, passports, evidence runs, WHO/WHY/WHAT NOT, and why Critique is not just another review bot.

Open

Critique v4

AI change control guide

Merge-boundary governance: Control Board, Change Passports, gate → review → merge phases.

Open

Company

About Critique

Not just a code review CI tool — the real control board for pull requests.

Open

Guide

AI code review guide

What AI PR review does, multi-model review, rollout steps, and limits of comment-only bots.

Open

Comparison

Best AI code review tools

2026 shortlist with pricing, model stacks, and fit by team shape.

Open

Head to head

Critique vs competitors

CodeRabbit, Copilot, Greptile, Qodo, Cursor Bugbot, and more.

Open

Pricing

AI code review pricing

Shared credits, BYOK, student/OSS plans, and PR review cost at scale.

Open

Models

Code review model directory

Lead and specialist models by speed, cost, and reasoning depth.

Open

Essays

Blog and ship log

Product notes, buyer guides, and release updates.

Open