Best practices
Teams without code review
If changes reach main without anyone reading them, because agents commit to main or pull requests merge once CI passes, let HeyDeer be the review. A pull request then merges on its own once HeyDeer approves it.
The risk
CI catches only what your tests cover. Without a review, two problems slip through:
- Model bias. The model that wrote the code tends to accept its own reasoning and miss its own mistakes, even when you ask it to check its work.
- Errors from repeated edits. When an agent revises the same code again and again, each change can quietly break something an earlier one got right.
What HeyDeer adds
- An independent opinion. HeyDeer reviews each pull request separately from the agent that wrote it, and checks every finding against the code before posting it.
- A dedicated review process. Every push gets a review, follow-up reviews recheck earlier concerns, and the HeyDeer Review check records the result on each commit.
Recommended setup
An agent opens a pull request
HeyDeer reviews every push
The check passes and HeyDeer approves
GitHub merges the pull request
If HeyDeer finds issues, the check fails and nothing merges. The agent pushes a fix, and HeyDeer reviews the new commits.
- Open a pull request for every change. Have agents push to a branch and open a pull request instead of committing to main.
- Review every push. In Workspace settings → Review rules, set Review schedule to On every push. See Automatic reviews.
- Make the check fail on issues. Under Publish results, turn on Fail the check when issues are found. See The HeyDeer Review check.
- Turn on automatic approval. Under Publish results, turn on Automatic approval. HeyDeer approves a pull request once a complete review leaves no issues. Major architecture and key behavior changes still wait for a person; to approve those too, set Human approval needed to No additional restriction. See Automatic approval.
- Protect main in GitHub. In the branch rules for main, turn on Require a pull request before merging with 1 required approval, and Dismiss stale pull request approvals when new commits are pushed. Then turn on Require status checks to pass before merging and add HeyDeer Review next to your CI checks.
- Merge automatically. Turn on Allow auto-merge in the repository’s GitHub settings. Then enable auto-merge on each pull request, or have the agent run
gh pr merge --auto --squashafter opening one.
HeyDeer approved these changes
All checks have passed
HeyDeer Review — Review completed — no issues foundRequired
CI / test — SuccessfulRequired
Auto-merge is on: GitHub merges this pull request once every requirement is met.
Write your standards as checks
Agents follow a rule more reliably when the review enforces it. Add a Markdown file to .agents/checks/ for each rule, and HeyDeer applies it to every pull request that changes matching files. See Repository checks.
.agents/checks/tenant-scope.md
---
files:
- "src/db/**/*.ts"
- "!**/*.test.ts"
---
Every query that reads or writes customer data must be
scoped to one tenant, taken from the request context and
never from request parameters.