Lesson 15 / 25

Branches, Never Main

Make the agent work on a branch and make the main branch impossible to push to directly.

Make it easy to discard

Have the agent work on a throwaway branch (or a separate git worktree) so the whole session can be inspected, merged or deleted. On the server side, turn on branch protection for main: no direct pushes, no force pushes, required status checks and required reviews. Then even a fully compromised agent cannot change what ships without passing the gates.

The repository as the safety net

Git makes every change visible and reversible; CI and required review decide what is allowed to merge.

Four gates: branch, size, tests, review.
Figure 5.1 — Branch, size, tests and review gates.

A branch session

The same commands work for humans. The agent never needs credentials that can write to main.

git switch -c ai/fix-login-typo
# ... agent works, runs tests ...
git diff main --stat
git diff main                       # read every line
git push -u origin ai/fix-login-typo  # then open a pull request

# discard everything:
# git switch main && git branch -D ai/fix-login-typo

Block force pushes server-side

A local rule against git push --force can be bypassed. The server-side protection rule is the one that cannot, so enable it on every important branch.

Quick check: Which control stops even a compromised agent from pushing to main?

  • Server-side branch protection
  • A polite note in the prompt
  • A longer commit message
  • Using dark mode
Answer

Server-side branch protection — Rules enforced by the Git host apply regardless of what the agent tries.