Skip to content

ci: exempt triage+ collaborators from the ai-triage daily budget - #294

Merged
allxsmith merged 1 commit into
mainfrom
ci/ai-triage-collab-bypass
Jul 14, 2026
Merged

allxsmith merged 1 commit into
mainfrom
ci/ai-triage-collab-bypass

Conversation

@allxsmith

@allxsmith allxsmith commented Jul 12, 2026 •

Copy link
Copy Markdown
Owner

Pull Request

Description

Follow-up to #292: issues and PRs opened by collaborators with triage access or higher always get auto-triage — the AI_TRIAGE_DAILY_LIMIT budget now only meters outside authors.

  • bulma-ui (@allxsmith/bestax-bulma)
  • create-bestax (create-bestax)
  • docs (@allxsmith/bestax-docs) — ai-development guide
  • Other: repo tooling (.github/workflows/ai-triage.yml, root CLAUDE.md)

How: in the gate step's opened path, after the existing skips (bot authors, claude/* heads, PRs already carrying Fixes #/Closes # — these still apply to everyone, since triage would be redundant regardless of author), the sender's live role is checked via repos/{repo}/collaborators/{sender}/permission — the exact same check the labeled path already performs. admin|maintain|write|triage ⇒ run triage without touching the budget counter; anyone else charges the daily budget as before.

Security notes:

  • The check is live against the repository, not author_association from the event payload — a revoked collaborator or a gameable "has one merged commit" association can never bypass the cap.
  • For opened events the sender is the author, so this can't be confused with a third party's action.
  • API failure on the permission lookup falls through to none ⇒ the budget path — fail-closed, same idiom as the labeled gate.

Related Issue(s)

Follow-up to #289 / #292.

Type of Change

  • Build tooling
  • Documentation

Checklist

  • My code follows the project style guidelines
  • I have performed a self-review of my code
  • I have added/updated documentation as needed (ai-development guide + root CLAUDE.md)
  • All new and existing tests passed (no package code changed; YAML parsed, gate script bash -n clean, prettier clean)
  • If this PR changes commands, conventions, or package structure, the affected CLAUDE.md files are updated

Additional Context

The budget marker comment's human-readable line now reads "Label-triggered runs and triage+ collaborators' items are exempt." No repo-variable changes needed — this works with the values already set.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up


Generated by Claude Code

Summary by CodeRabbit

  • New Features

    • Triage requests created by collaborators with sufficient permissions are now exempt from the daily auto-triage limit.
    • Label-triggered triage runs remain exempt from the daily cap.
  • Documentation

    • Updated AI triage guidance to clarify daily limits and exemption rules.

Items opened by collaborators with triage access or higher always get
auto-triage — the daily budget only meters outside authors. The bypass
reuses the labeled path's live collaborators/permission check (the opened
event's sender is the author), so stale associations can't skip the cap.
Bot/claude-head/linked-PR skips still apply to everyone.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Pohc8xLkdx4gwXkW3xd7up
@coderabbitai

coderabbitai Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

Walkthrough

The AI triage workflow now exempts items opened by triage-level collaborators from the daily budget after a live permission check. Inline workflow comments, repository guidance, and getting-started documentation describe the updated exemption rules.

Changes

AI triage budget gating

Layer / File(s) Summary
Workflow collaborator bypass
.github/workflows/ai-triage.yml
The opened-event gate checks live collaborator roles, bypasses budget charging for eligible collaborators, and updates related comments and budget markers.
Triage budget policy documentation
CLAUDE.md, docs/docs/guides/getting-started/ai-development.md
Documentation specifies that daily limits apply to outside authors while label-triggered runs and triage-level collaborators are exempt.

Estimated code review effort: 2 (Simple) | ~15 minutes

Sequence Diagram(s)

sequenceDiagram
  participant OpenedEvent
  participant AiTriageGate
  participant CollaboratorAPI
  participant BudgetCounter
  OpenedEvent->>AiTriageGate: process opened item
  AiTriageGate->>CollaboratorAPI: check sender collaborator role
  CollaboratorAPI-->>AiTriageGate: return role
  AiTriageGate->>BudgetCounter: charge outside-author item
Loading

Possibly related issues

  • allxsmith/bestax#289 — Addresses the same AI triage daily-budget gating and collaborator exemption behavior.

Possibly related PRs

  • allxsmith/bestax#229 — Adds related live triage-level collaborator permission checks in an automated GitHub Actions workflow.
  • allxsmith/bestax#277 — Modifies the same AI triage workflow and its associated permission-gating documentation.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main change: triage+ collaborators are exempted from the ai-triage daily budget.
Description check ✅ Passed The description mostly matches the template and includes summary, affected packages, related issues, type, checklist, and context.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/ai-triage-collab-bypass

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://3458c2da.bestax.pages.dev

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ai-triage.yml:
- Around line 18-21: Update the BUDGET explanatory comments and generated marker
text so the collaborator exemption is conditional: only successfully verified
triage+ collaborators bypass the cap, while permission lookup failures continue
through the budget path. Apply this wording consistently at the referenced
workflow sections.

In `@CLAUDE.md`:
- Around line 100-102: Update the AI_TRIAGE_MODE documentation to state that
items are uncapped only after a successful live triage+ collaborator role match;
permission-lookup failures must continue through the normal
AI_TRIAGE_DAILY_LIMIT budget path.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 30984e0d-9ade-473b-987a-194550a34276

📥 Commits

Reviewing files that changed from the base of the PR and between 90dd451 and 9b1bad1.

📒 Files selected for processing (3)
  • .github/workflows/ai-triage.yml
  • CLAUDE.md
  • docs/docs/guides/getting-started/ai-development.md

Comment on lines +18 to +21
# BUDGET (auto runs by outside authors only; label runs are exempt — already
# human-metered by the click — and so are items opened by collaborators with
# triage+ access, verified live: trusted authors always get triage, the cap
# only meters strangers): a repo-wide daily counter kept as ONE marker comment on

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Make the collaborator exemption wording conditional.

Permission lookup failures intentionally fall through to the budget path, so these comments and the generated marker should say that successfully verified triage+ collaborators bypass the cap; they do not always bypass it.

Proposed wording
-# triage+ access, verified live: trusted authors always get triage, the cap
-# only meters strangers):
+# triage+ access when verified live; lookup failures use the budget path,
+# so the cap otherwise meters strangers):

-#      always get triage — the budget only meters outside authors.
+#      bypass the budget when the live role check succeeds; lookup failures
+#      continue through the budget path.

-          **AI triage budget**: ... Label-triggered runs and triage+ collaborators' items are exempt.
+          **AI triage budget**: ... Label-triggered runs and successfully verified triage+ collaborators' items are exempt; lookup failures use this budget path.

Also applies to: 180-193, 231-231

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/ai-triage.yml around lines 18 - 21, Update the BUDGET
explanatory comments and generated marker text so the collaborator exemption is
conditional: only successfully verified triage+ collaborators bypass the cap,
while permission lookup failures continue through the budget path. Apply this
wording consistently at the referenced workflow sections.

Comment thread CLAUDE.md
Comment on lines +100 to +102
issues/duplicates: automatic on new issues/PRs when `AI_TRIAGE_MODE=auto` (outside authors
capped at `AI_TRIAGE_DAILY_LIMIT`/day via a counter comment on issue #290; items opened by
triage+ collaborators are uncapped), or on demand via the label

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Document the permission-lookup fallback.

The workflow only bypasses the budget after a successful live role match; lookup failures follow the normal budget path. This text currently says all triage+ collaborator items are uncapped.

Proposed wording
- outside authors capped at `AI_TRIAGE_DAILY_LIMIT`/day via a counter comment on issue `#290`; items opened by
- triage+ collaborators are uncapped), or on demand via the label
+ outside authors capped at `AI_TRIAGE_DAILY_LIMIT`/day via a counter comment on issue `#290`;
+ successfully verified triage+ collaborators bypass the cap, while permission-lookup
+ failures use the budget path), or on demand via the label
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
issues/duplicates: automatic on new issues/PRs when `AI_TRIAGE_MODE=auto` (outside authors
capped at `AI_TRIAGE_DAILY_LIMIT`/day via a counter comment on issue #290; items opened by
triage+ collaborators are uncapped), or on demand via the label
issues/duplicates: automatic on new issues/PRs when `AI_TRIAGE_MODE=auto` (outside authors
capped at `AI_TRIAGE_DAILY_LIMIT`/day via a counter comment on issue `#290`;
successfully verified triage+ collaborators bypass the cap, while permission-lookup
failures use the budget path), or on demand via the label
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@CLAUDE.md` around lines 100 - 102, Update the AI_TRIAGE_MODE documentation to
state that items are uncapped only after a successful live triage+ collaborator
role match; permission-lookup failures must continue through the normal
AI_TRIAGE_DAILY_LIMIT budget path.

@allxsmith
allxsmith merged commit b0355ea into main Jul 14, 2026
23 checks passed
@allxsmith
allxsmith deleted the ci/ai-triage-collab-bypass branch July 14, 2026 01:48
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 5.4.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.3.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@github-actions

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants