Automatic merge is a policy decision, not a measure of how confident an agent sounds. A useful starting question is: what must be true about this exact commit before it may become part of the protected branch?
Define the gate outside the agent
Required checks, review requirements, and branch rules should remain enforceable even when an agent requests delivery. GitHub protected branches can require status checks and restrict changes to important branches. Repository administrators should review bypass permissions as part of that configuration. See GitHub's protected branch documentation.
The orchestration layer can add delivery-specific conditions, such as acceptance coverage or independent review. Those conditions complement repository controls; they do not justify disabling them. Keep the authority to change policy separate from the authority to propose code.
Tie evidence to the commit
A passing check on an earlier revision does not verify a later revision. Capture the expected head SHA when evaluating delivery and compare it again at the merge boundary. If the branch has moved, stop and re-evaluate. This prevents a valid review decision from silently authorizing different code.
Also distinguish check completion from check success. Cancelled, skipped, missing, or timed-out jobs should not automatically become approval. Your policy must say which outcomes are acceptable for each required gate.
Roll out in stages
Begin with human approval and inspect several complete runs. Identify which changes are predictable, reversible, and covered by meaningful tests. Automatic merge may be reasonable for a narrow class of changes while remaining disabled for schema changes, permissions, infrastructure, or other high-impact work.
Make exceptions visible. If someone overrides a failed gate, record who made the decision and why. If the system cannot establish the expected commit or required evidence, an escalation is more useful than an optimistic merge attempt.
What auto-merge does not promise
Passing tests cannot prove every production property. They establish the behaviors those tests actually exercise. ForgeLoop offers opt-in guarded auto-merge, not a claim that all generated code should merge unattended. Its delivery overview keeps review and delivery distinct so teams can choose the appropriate boundary.