Independent Authorization for Agent Change
TrustRelay observes every agent-authored pull request, assembles verifiable evidence, applies deterministic policy, and issues a signed Agent Change Passport — before anything merges.
The Challenge
Agent-authored code needs independent oversight
AI coding agents are writing more code than ever, but existing review processes weren't designed for autonomous software contribution. TrustRelay fills the gap between agent productivity and safe deployment.
No Attribution
Agent-authored changes lack clear attribution and human sponsorship. Who is responsible when an agent makes a mistake?
Inconsistent Evidence
Without a standardized evidence pipeline, reviewers cannot reliably assess the safety and provenance of agent contributions.
Manual Review Bottleneck
Requiring human review for every agent change negates the productivity gains of AI coding assistants.
The Solution
Independent authorization that earns trust
TrustRelay is a deterministic authorization layer that observes every agent-authored pull request, assembles a verifiable evidence snapshot, and applies your policy before anything merges.
Deterministic Policy
Every authorization decision is reproducible from exact versioned inputs. No AI makes or modifies a decision — only typed assertions with source qualification.
Signed Evidence
Every change produces a KMS-signed Agent Change Passport stored in an immutable S3 ledger. Passports are independently verifiable by any party.
Required Enforcement
TrustRelay publishes a required GitHub check. If the check fails, the PR cannot merge — enforcement is architectural, not advisory.
Customer Control
You define the policy. You control the recovery path. TrustRelay provides the deterministic framework for your authorization rules.
How It Works
From pull request to decision in four steps
TrustRelay integrates at the merge boundary, providing independent authorization without disrupting developer workflows.
Observe
TrustRelay monitors GitHub pull requests where AI coding agents have contributed code changes.
Analyze
Agent attribution and human sponsorship are established. A versioned evidence snapshot is assembled from repository data, CI results, and policy context.
Decide
Deterministic policy evaluates the evidence against your configured rules. The result is APPROVE, BLOCK, or ESCALATE — each with a stable reason code.
Enforce
A signed Agent Change Passport is issued to the immutable ledger. A GitHub required check reports the outcome. Overrides and production outcomes are preserved.
Ready to delegate merge authority safely?
TrustRelay is the independent authorization layer your platform team needs to adopt AI coding agents at scale.