Claim◆Article · 16:40 — 21:02
Auto-approved PRs can still be SOC 2 compliant as long as the process is auditable, queryable, and explicitly part of your documented risk policy.
Claire addresses the compliance question directly: automating approvals is compatible with SOC 2 provided the automated process is auditable, queryable, and written into the organization's risk policy. ✦ AI generated
Claire Vo · Lenny's Newsletter · 2026-08-05 · original ↗
Why auto-approved PRs can be SOC 2 compliant as long as the process is auditable, queryable, and in your risk policy.
Read full article ↗excerpt · fair-use quotation
- ·Auto-approval compatible with SOC 2
- ·Requires auditable, queryable process
- ·Must be written into risk policy
Around this claim
Context · 2
AI writing most of my code created a PR queue I couldn't keep up with, so the answer isn't reviewing every AI-generated PR but routing them through an agent that scores risk, auto-approves the low-risk ones, and escalates the rest.Claire Vo · Lenny's Newsletter · conf 60%You don't have to review every AI-generated PR because most are low-risk reversible changes that can be safely auto-approved.Claire Vo · Lenny's Newsletter · conf 60%
This moment responds to
supports → Legacy rules-based systems and human-in-the-loop approval cannot keep pace with how fast agents operate, so oversight itself must shift to AI-in-the-loop systems.Dev Rishi · The TWIML AI Podcastrebuts → A computer can never be held accountable, and therefore a computer must never make a management decision, as stated in IBM's 1979 training materials.IBM (1979 training slide, cited by Simon Willison) · Simon Willison's Weblog