# Branches, Never Main — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/git-branch-workflow

> Make the agent work on a branch and make the main branch impossible to push to directly.

## Make it easy to discard

Have the agent work on a **throwaway branch** (or a separate `git worktree`) so the whole session can be inspected, merged or deleted. On the server side, turn on **branch protection** for `main`: no direct pushes, no force pushes, required status checks and required reviews. Then even a fully compromised agent cannot change what ships without passing the gates.

## The repository as the safety net

Git makes every change visible and reversible; CI and required review decide what is allowed to merge.

![Four gates: branch, size, tests, review.](assets/figures/coding-agent-guardrails/section-5-map.svg) — Figure 5.1 — Branch, size, tests and review gates.

## A branch session

The same commands work for humans. The agent never needs credentials that can write to `main`.

```bash
git switch -c ai/fix-login-typo
# ... agent works, runs tests ...
git diff main --stat
git diff main                       # read every line
git push -u origin ai/fix-login-typo  # then open a pull request

# discard everything:
# git switch main && git branch -D ai/fix-login-typo
```

## Block force pushes server-side

A local rule against `git push --force` can be bypassed. The server-side protection rule is the one that cannot, so enable it on every important branch.

**Quiz:** Which control stops even a compromised agent from pushing to main?

- [x] Server-side branch protection
- [ ] A polite note in the prompt
- [ ] A longer commit message
- [ ] Using dark mode

*Answer:* Server-side branch protection. Rules enforced by the Git host apply regardless of what the agent tries.
