# Protected Paths — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/fs-protected-paths

> Require approval before the agent edits CI, infrastructure, secrets and dependency files.

## Some files matter more

Not every file is equal. A change to `.github/workflows/*`, infrastructure code, deployment config, `.env*`, private keys or dependency lockfiles can affect production or leak access far beyond what a typo fix deserves. List these as **protected paths**: edits are blocked or need explicit approval, and a diff that touches them is flagged in review.

## Matching protected paths, run

I ran this with Python's `fnmatch`. The workflow file and `.env.local` are flagged; ordinary source and docs are not.

```python
import fnmatch
PROTECTED = [".github/workflows/*", "infra/*", "*.pem", ".env*", "package-lock.json"]

def touches_protected(paths):
    return [p for p in paths if any(fnmatch.fnmatch(p, g) for g in PROTECTED)]

print(touches_protected(["src/app.py", ".github/workflows/deploy.yml", ".env.local", "README.md"]))
```

Output:

```
['.github/workflows/deploy.yml', '.env.local']
```

## Back it with CODEOWNERS

On GitHub, a CODEOWNERS file plus branch protection requires a named reviewer for changes to sensitive paths. That enforces the same rule on humans and agents even if the local tool policy is bypassed.

**Quiz:** Which file should usually be a protected path?

- [ ] A unit test for a helper
- [ ] A README paragraph
- [ ] A code comment
- [x] A CI workflow file

*Answer:* A CI workflow file. CI files control what runs with repository secrets, so changes need extra scrutiny.
