Build1 distinct publisher3 min readUpdated
The AICPA's change-management criterion asks whether changes are authorized, tested and approved, not whether a second engineer clicked approve. Amp says its auditors agreed.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Amp, the coding-agent company run by co-founder Quinn Slack, says it holds SOC 2 Type II certification while letting engineers push straight to the main branch, with no mandatory pull requests [1][2][5]. What matters here is subtractive: it removes the argument that a second engineer's approving click is a compliance requirement rather than a management choice.
The criteria support that reading. The AICPA's Trust Services Criteria do not mention Git, pull requests or a second human reviewer [6]. CC8.1, the change-management criterion, requires an organization to authorize, document, test, approve and implement changes to its systems, and leaves the organization and its auditor to determine which controls satisfy those objectives [7]. Amp says pull requests have been absent since its first commit and that it took the workflow to its auditors when it began preparing for SOC 2; by Amp's account, the auditors evaluated its change-management process rather than prescribing a Git workflow [3][4].
What replaced the gate is not nothing. Amp describes four controls: access to main limited by business function, GitHub-enforced verified signatures on commits to main, mandatory passage of automated tests plus infrastructure and security checks, and commits linked to the Amp threads that produced them [8][10][11][12]. The first is thinner than it sounds. Every engineer can push, and Amp says most of its staff are engineers [8]; with headcount in the 11-50 range on its LinkedIn profile [9], the group excluded by business function is a minority of a small company, fewer than 25 people at the outer bound [24]. The weight sits on the automated checks and the transcript.
The transcript is the part worth copying. A conventional pull request preserves a diff, comments and approvals; Amp says its thread-linked commits preserve the interaction that generated the change, giving an auditor evidence beyond the final code [13]. That is what allows the approval mechanism to live in access policy and automated enforcement instead of a queue [14]. It also ties the control to the tooling: Amp's agents inspect repositories, edit files, run commands and continue on remote machines after a developer closes a laptop [19], and its orbs give each task a fresh repository copy and toolset that a developer can watch and then synchronize locally [20]. A team whose agent work leaves no durable, commit-linked record of instructions and intermediate steps does not have this control, whatever its branch protection settings say.
Caveats in order of size. This is Amp's account of its own audit: the public note identifies neither the auditor nor the examination period, and Amp directs customers to a trust portal to request reports [15]. Those reports are what carry the scope and tested controls needed to judge how the process operated across the period [16]. The available evidence establishes that Amp holds a Type II certification and says direct push was included; it does not make Amp's control design a universal template [17]. Scale is a factor too. Amp was built inside Sourcegraph and separated into an independent company on December 2, 2025, with Sourcegraph citing different distribution models, and Amp called itself profitable without publishing revenue or customer figures [21][22].
Amp's stated logic is that when writing code becomes fast, slow process becomes the source of delay, so its controls emphasize isolation, automated detection and rapid reversal [18].
Watch whether the trust portal reports name an examination period long enough to cover the direct-push workflow in operation, and whether the tested controls match the four described publicly [15][16]. Watch, too, whether anyone larger than 50 people passes an audit on the same design [9].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Amp says it preserved its direct-to-main workflow while obtaining SOC 2 Type II certification, using signed commits, automated validation and detailed agent transcripts instead of mandatory pull requests.
Amp's current security page says it is SOC 2 Type II certified.
Quinn Slack is CEO and co-founder of the coding-agent company Amp, and backs a rule allowing engineers to push code directly to the main branch.
In Amp's account of its SOC 2 process, pull requests had been absent since its first commit, and Amp took the choice directly to its auditors when it began preparing for SOC 2.
According to Amp's account, the auditors evaluated Amp's change-management process rather than prescribing a Git workflow.
The AICPA's Trust Services Criteria do not specify Git, pull requests or a second human reviewer.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor account plus one standards citation
The only independent, checkable element is the AICPA CC8.1 wording. Everything about the audit itself - that direct pushes were in scope, that auditors accepted the substitute controls, that the four controls operated over the period - rests on Amp's own note and security page in a single publisher's article, with no auditor named, no examination period, and no report excerpt.
One small team, one attestation
Adoption evidence is a single 11-50 person, mostly-engineering company running the workflow in production and holding a Type II attestation. The article presents no second organization, no auditor guidance, and no tooling or industry movement toward the pattern, and Amp itself rejects the model for a 2,000-person organization.
Generalized from one self-reported case
The framing that this 'kills a convenient excuse' extrapolates a portable lesson from one undisclosed-scope audit at a company of at most 50 people, described by the vendor whose product supplies the substitute evidence. The article partially self-corrects with its limits-of-scale section and its statement that the design is not a universal template, which keeps the gap moderate rather than severe.
Vendor-authored narrative that markets its own product
Every audit-related fact originates with Amp, a commercial coding-agent vendor spun out of Sourcegraph on December 2, 2025 and selling to developers and teams. The specific control presented as the auditor-satisfying innovation - commits linked to Amp agent threads - is a feature of Amp's product, and the profitability statement came without figures, so the account simultaneously functions as compliance proof and product positioning.
Facts as attributed are solid; the generalization is not
Confidence is moderate: the standards reading and the existence of a Type II certification claim are clearly reported and internally consistent, and the article discloses its own gaps. But with one publisher, one self-reported audit, no scope disclosure and no second adopter, the load-bearing inference about substituting transcripts and access policy for reviewer approval cannot be independently confirmed from the supplied material.
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
build
Claude Code now outruns Copilot roughly two to one in JetBrains' survey of 15,000 developers1 distinct publisher
build
Yadda 3's real artifact is not the code, it is the rules the agent could not rewrite1 distinct publisher
invest
Cursor ships Origin to paying users as GitHub's outage count reaches 2571 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026