Synced from Hive. This page is pulled from hivecommons/hive@v5 during the docs build. Edit the canonical source in the Hive repository.

Hive Labels and Control Signals

This is the operator view of Hive labels: if you add or remove a label, this is what the v5 code does. It also calls out non-label controls that look like labels from the dashboard.

How labels reach agents

Most hard gates run before an agent sees work. GitHub issue enumeration reads labels in this order: standing meta issues are excluded first, then hold labels move the item to the Hold list, then exempt labels and the issue-level hard-suppress labels (needs-human, needs-direction, needs-decision, needs-spec; hardSuppressIssueLabels in src/pkg/github/labels.go) filter it out, so no agent kick names, and no kick claims, a parked issue, then project.issue_filter.require_labels admits or rejects the issue, and then is it actionable (src/pkg/github/client.go:955-1045). Pull requests use the same hold-first enumeration for the PR Hold list (src/pkg/github/client.go:1110-1165). That means kick prompts, dashboard actionable counts, planning-from-label, and contributor offers normally inherit the same gate.

Some sweeps bypass that enumeration and list items themselves, but every of them gates on the same hold predicate as enumeration (Client.IsHeldLabels / Client.isHeld, src/pkg/github/client.go:1964-1972, src/pkg/github/client.go:2674-2676), so the generic hold substrings and the exact dashboard hive-pause/<hive-id> label hold everywhere:

  • Auto-merge sweeps reach it through the Transport.IsHeldLabels seam; both the queued (lgtm) and the self-authored sweep skip a held PR before fetching it (src/pkg/github/automerge/automerge_sweep.go:23-38, src/pkg/github/automerge/automerge_sweep.go:959-964, src/pkg/github/automerge/automerge_sweep.go:966-1004, src/pkg/github/automerge/automerge_sweep.go:1029-1046).
  • The task-list sweep skips a held issue before its exempt / issue needs-human gate, so a held issue is never commented on, relabelled, or closed by it (src/pkg/github/task_list_sweep.go:797-815).
  • The SHA-hold sweep lists primary-repo kind/bug issues itself, adds literal hold plus a marker notice when no SHA is present, and removes hold when the current hold is its own: the newest hold label event is a labeled by the App bot and an App-authored SHA-hold notice was posted at or after it (src/pkg/github/client.go:2467-2532, src/pkg/github/client.go:2582-2604).
  • PR-request watching applies server-side PR holds after a PR is opened; the agent’s --label hold flag is deliberately discarded by the wrapper (src/pkg/github/pr_request_watcher.go:452-524, bin/hive-open-pr.sh:142-150).

The “respect hold labels” text in policy templates names the enforced set (hold, on-hold, hold/review, hive-pause/<hive-id>, any label containing hold, plus do-not-merge as exempt) but is a prompt-level backstop. The hard gate is the enumerator or sweep named in the table.

Categories

  • Informational / display-only changes how Hive explains an item, not whether agents can act.
  • Workflow / status marks a process state such as reviewer outcome or rebase need.
  • Gate / permit admits, blocks, or releases a specific workflow.
  • Hold / suppress removes work from agent/contributor/merge lanes until cleared.
  • Contributor eligibility / routing affects /contribute offers or agent lane choice.
  • Human approval / acknowledgement records that a human accepted a direction or design.

Reference table

Label or signalApplies toConsumerEffectGate or signalWho appliesWhen checkedCleared / overriddenConfig knobs
hold, on-hold, hold/reviewIssues, PRsGitHub enumeration, auto-merge sweeps, task-list sweepAny label containing a configured hold substring is held; held issues/PRs leave agent kicks, PR merge lanes, and the task-list sweep. Held red PRs still route back to their owning agent for CI repair, with instructions not to remove the hold.Hard holdHuman, Hive level gate, #5117 gate, holdguard, SHA-holdEnumeration and sweepsRemove the matching label; Hive releases literal hold it applied itself (level gate, #5117, SHA-hold)Built-in HoldLabels; dashboard exact hold via Client.SetHoldLabels (src/pkg/github/client.go:750-755, src/pkg/github/client.go:1894-1972, src/pkg/scheduler/policy_overlays.go:210-220)
hive-pause/<hive-id>Issues, PRsGitHub enumeration, dashboard hold toggle, auto-merge sweeps, task-list sweepExact, hive-scoped dashboard hold. It is not provenance and intentionally avoids the substring hold.Hard holdDashboard operatorEnumeration and sweepsDashboard Release removes labels causing the hold, including thisCanonicalized from hive id (src/pkg/github/client.go:1898-1932, src/pkg/github/client.go:1936-1945, src/docs/dashboard.md:80-96)
GitHub “blocked by” dependencyIssuesGitHub enumeration, kick-list assemblyAn open issue whose GitHub dependency list names an open blocker is enumerated with DependsOn edges and kept out of the ACTIONABLE ISSUES an agent picks from; the kick names it in a Blocked by open dependencies footer with its blockers. A blocker that is closed resolves the edge; a mutual pair (A↔B) is dropped with a warning so neither hides the other. The blocker list failing to load fails open (issue offered).Soft holdHuman (GitHub UI) or agent via hive-open-issue --blocked-by when splitting ordered childrenEnumerationClose the blocker, or remove the dependency on GitHubNone (src/pkg/github/issue_dependencies.go, src/pkg/scheduler/kickmessage.go partitionBlockedIssues/formatBlockedIssuesNote)
hive/<hive-id>IssuesProvenance/migration fallbackMarks hive provenance. It is no longer a hold label except a temporary failed-migration fallback during upgrade.InformationalHiveDisplay/migrationRemove if unwanted; do not use as a holdHive id (src/pkg/github/client.go:1947-1953)
hold from ACMM level gatePRsPR-request watcher, self-authored auto-merge releaseNon-outreach agent PRs at L3-L5 get literal hold; outreach PRs are held at every level. The watcher, not the policy prompt, applies it.Hard merge gateHive AppPR creation, later self-authored auto-merge releaseAuto-release when current policy no longer requires the level hold, latest hold event was by the App, and the release path runs; otherwise a human removes itHive-wide ACMM and agent (src/pkg/github/pr_request_watcher.go:452-524, src/pkg/github/pr_level_hold.go:16-124)
hold from #5117 self-authorizationPRsPR-request watcher and self-authorization releaseA PR whose rationale is unacknowledged hive-filed issues gets literal hold. Acknowledging the issue later does not remove an existing PR hold by itself. At ACMM L6 Fully Autonomous, the unset default is off; lower levels default on.Hard merge gateHive AppPR creation; evaluated when no level hold appliesAcknowledge the issue and remove the PR hold; disabled policy release can remove Hive’s own hold. At L6, that release path also clears existing Hive-applied #5117 holds when no explicit config keeps the policy on.github.self_authorization_hold, per-repo project.repo_policies[].self_authorization_hold, HIVE_SELF_AUTHORIZATION_HOLD (src/pkg/github/pr_self_authorization.go:14-226, src/pkg/github/pr_request_watcher.go:452-524)
triage/accepted (or project.issue_filter.reporter_trust.untrusted_require_labels); needs-triage while waitingHuman-filed issues from untrusted reportersGitHub enumerationWith reporter_trust.enabled: true, an issue whose reporter’s GitHub author_association is outside the trusted set (default OWNER, MEMBER, COLLABORATOR) and whose login is not in trusted_logins is not actionable until it carries of these labels. On the first excluded scan, core github.Client.fetchIssues posts marked explanation comment and applies needs-triage (or awaiting_label); later scans do not repeat the comment. This is a poller-side write, not an agent prompt, and is capped at 10 new notices per poll. When the triage label appears, the same poll loop removes needs-triage if the marker records that Hive added it, then the issue enters the backlog. Trusted reporters’ issues pass untouched. Runs after holds/exempts and before require_labels, so the ordinary allow-list still applies afterwards. Hive- and bot-filed issues are not judged here (#5117 owns them). Counted as “needs triage” on the repo card, not as a generic filter refusal.Hard admission gate (off by default)Human; Hive App for the visibility comment/labelEnumerationAdd the label, trust the login or association under Settings → Labels → Reporter trust, or disable the gateproject.issue_filter.reporter_trust.{enabled,trusted_associations,trusted_logins,untrusted_require_labels,awaiting_label,comment} (src/pkg/config/reporter_trust.go, src/pkg/github/client.go fetchIssues)
hold from #9665 reporter trustPRsPR-request watcher, level-hold releaseA PR whose rationale (closing or referencing links, or the request’s declared issues) traces to an issue filed by an untrusted reporter gets literal hold at every ACMM level, including L6, plus needs-human (so it surfaces as waiting on a person, #10773) and a marked notice naming the untrusted reporter and stating the PR itself was authored by the hive. Any untrusted citation holds. Evaluated even at hold-gated levels, because the notice is what stops promotion to L6 from releasing the label.Hard merge gateHive AppPR creation; re-checked by the level-hold release pathA human removes hold. Hive never auto-releases it: the release sweep sees the notice (or re-evaluates and re-posts it) and leaves the label. Holdguard re-holds on a new head SHA.github.reporter_trust_hold (nil follows reporter_trust.enabled), per-repo project.repo_policies[].reporter_trust_hold, HIVE_REPORTER_TRUST_HOLD (src/pkg/github/pr_reporter_trust.go, src/pkg/github/pr_level_hold.go)
project.repo_policies[].auto_merge: falsePRshive-merge relay, App self-authored auto-merge sweep, proxyBelow L6 this resolves off for every repo; at L6, PRs can still be opened, reviewed and held when the per-repo switch is off, but Hive refuses every merge path for that repo. Existing hold / hive-pause/<hive-id> labels stay put because the disabled repo is skipped before hold release or merge.Hard merge gateOperator/dashboardMerge relay request, self-merge sweep tick, proxy direct merge attemptDashboard repo-card switch or config edit sets auto_merge: true/removes the override at L6; enabling is rejected below L6project.repo_policies[].auto_merge (src/pkg/config/repo_policy.go, src/pkg/agent/manager_modes.go, src/pkg/github/automerge/automerge_sweep.go, src/pkg/proxy/rules.go)
hold from holdguardPRsHoldguard ledgerIf the head SHA changes while held, lifting the hold causes Hive to comment and re-apply literal hold; the next human removal is the fresh approval.Hard merge gateHiveGovernor holdguard passHuman removes the re-applied holdBuilt-in holdguard.ReHoldLabel (src/pkg/holdguard/holdguard.go:1-43)
hold from SHA-holdIssuesSHA-hold sweepHuman-filed primary-repo kind/bug without a 7-40 hex SHA gets hold and a notice carrying “; a SHA appears in body/comments, Hive removes hold if the current hold is its own (newest hold event labeled by the App bot, paired with an App-authored notice at or after it). A human’s hold, a re-hold, or another subsystem’s hold stays.Hard issue holdHiveEval tick SHA sweepAdd SHA evidence; sweep removes its own hold, a human removes any otherPrimary repo and SHA-hold config (src/pkg/github/client.go:2467-2532, src/pkg/github/client.go:2582-2604)
do-not-merge and do-not-merge*Issues, PRsExempt filter, merge sweeps, task-list sweepPermanently exempt; exact match is case-insensitive but prefix matching follows Go strings.HasPrefix on the original label.Hard suppressHumanEnumeration/sweepsHuman removesBuilt-in PermanentExemptLabels (src/pkg/github/client.go:750-755, src/pkg/github/client.go:2030-2048)
governor.labels.exempt entriesIssues, PRsExempt filterSame exempt behavior as do-not-merge; wins over required-label admission. Defaults include nightly-tests, LFX, meta-tracker, auto-qa-tuning-report, adopters, changes-requested, waiting-on-author.Hard suppressOperator/dashboardEnumeration/sweepsRemove label or config entrygovernor.labels.exempt (src/pkg/config/config.go:3388-3396, src/pkg/config/config.go:5800-5808)
needs-humanIssuesEnumeration, task-list sweep, claim escalation gate and un-park sweepIssue is filtered, not held: no agent kick or contributor offer; task-list sweep can add it when a merged PR leaves human remainder work (never on a held issue), and the claim escalation gate adds it instead of a third no-progress claim by the same agent (governor.claims.escalate_after_claims, #10527). The un-park sweep keeps a “What to reply” comment on every parked issue listing the commands. See Maintainer commands.Hard suppressHive or humanEnumeration/task-list sweep/kick buildingHuman removes, or a maintainer with write/maintain/admin access replies /hive approve or /hive decision <text> on the issue, which also adds approved-direction and never touches hold (src/pkg/github/issue_unpark_command.go)Fixed label (src/pkg/github/client.go:1008-1024, src/pkg/github/task_list_sweep.go:611-641, src/pkg/github/task_list_sweep.go:797-815, src/cmd/hive/claimescalation.go)
needs-humanPRsEscalation ledger and reviewer laneApplied when red-CI fix budget is exhausted; stops automated fix dispatch and sends the PR to the human/reviewer lane. It is not a PR enumeration filter.Hard fix-dispatch gateHiveEscalation pass/kick buildingHuman removes after root cause or reviewer un-escalates; budget resets after graceFixed label (src/pkg/escalation/escalation.go:400-470, src/pkg/escalation/escalation.go:1185-1205)
hive/advisoryIssuesStanding meta classifierHive advisory report is never actionable and never appears on the Hold list.Hard exclusionHiveBefore holds/exemptsRemove label, but exact advisory title still excludesFixed label/name (src/pkg/github/standing_issues.go:1-57, src/pkg/github/client.go:983-1001)
approved-directionAgent-filed issues#5117 gate, ranking, kick tagA PR opened after the label is present avoids #5117 hold; the issue ranks ahead of unacknowledged hive-filed backlog.Gate input + soft rankingHumanPR creation and issue rankingRemove label; human assignee/comment can still acknowledge for #5117Fixed HumanAckLabel (src/pkg/github/pr_self_authorization.go:14-226, src/pkg/github/client.go:2740-2832)
Human assigneeIssues#5117 gate and rankingHuman assignee acknowledges hive-filed direction and moves issue into rank tier 2.Non-label approvalHumanPR creation/rankingUnassignN/A (src/pkg/github/pr_self_authorization.go:180-226, src/pkg/github/client.go:2784-2832)
Relay-linked parentHive-filed issues the relay split out of a parent#5117 gate, ranking, kick tagA child the issue-request relay itself linked as a GitHub sub-issue inherits acknowledgement from an open, unheld parent that is human-filed or carries approved-direction/a human assignee; level, and for links the relay made (recorded in /data/split-parents.json), never for sub-issue links added later in the UI. The kick line shows [hive-filed+parent-ack #N].Non-label approvalHive (from the parent’s human signal)Enumeration and PR creationhold the child, or close/hold the parentFixed ledger (src/pkg/github/split_parents.go)
Human commentIssues#5117 gateAny human comment in the first 100 issue comments acknowledges for #5117, but does not change ranking tier by itself.Non-label approvalHumanPR creationN/AselfAuthCommentPageSize (src/pkg/github/pr_self_authorization.go:14-18, src/pkg/github/pr_self_authorization.go:180-226)
needs-reporter-confirmationIssuesIssue-close gate, post-merge refs sweep, dashboardMarks an issue whose fix appears to have landed but still needs the reporter or a maintainer to reply /fixed. The CloseIssue reporter-confirmation gate and the hive-post-merge-refs-sweep prompt apply it; if the reporter has write/maintain/admin access Hive also adds needs-human so the dashboard’s human queue catches it.Hard suppress / human signalHive AppEnumeration/dashboard/fixed, deliberate close, or /reopen removes this label. Hive does not remove needs-human here because it may have been set by another workflow.Fixed label (src/pkg/github/issue_close.go, src/scripts/comment-merged-refs.sh, src/scripts/issue-confirm-fixed.sh)
hive: reporter-confirmed label/body textIssuesIssue-close gateAllows the reporter-confirmation close gate to close a human-filed bug after the fix is verified. PR bodies keep Closes/Fixes; the close path decides whether to leave the issue open pending confirmation.PermitHuman/reporterCloseIssueRemove label/textFixed phrase (src/pkg/github/pr_request_claims.go:266-410, src/pkg/github/issue_close.go:26-28)
hive: close-on-merge label/body textIssuesIssue-close gateFiling-time opt-in for a human-filed bug whose merged fix is the verification (code-sweep findings, timing/failure-path/fleet-only bugs the reporter cannot reproduce): the close path accepts the merge immediately. Without it (or hive: reporter-confirmed) a human-filed bug can still carry Closes #N/Fixes #N, but Hive leaves it open pending reporter confirmation. hive-open-issue --close-on-merge adds it to the body.PermitHuman/filerCloseIssueRemove label/textFixed phrase (src/pkg/github/pr_request_claims.go:268-410, src/pkg/github/issue_close.go:26-28)
design-approvedIssuesPlanning design gateApproves a requested architect design; counts after a design exists.Planning gateHumanPlanning label sweepRemove/re-apply design labels as neededplanning.design_approved_label (src/pkg/planning/design.go:68-125, src/pkg/planning/design.go:320-345)
Lane-name label or agent/<role> segmentIssuesClassifier/schedulerRoutes issue to a lane after title prefix and before keyword routing. Scanner sees every issue; other agents see their lane.Soft routingHive/humanClassification before kicksChange/remove labelagents.*.lane_keywords (src/pkg/classify/classifier.go:249-276, src/pkg/scheduler/templates.go:298-303)
agent/<role>Issues, PRsProvenance, ownership, dashboard bandsMarks the filing/owning agent. The wrapper always derives the suffix from the lane name (HIVE_AGENT), never the display name, so PR ownership and label routing see the same token the scheduler compares against.Informational + routingHiveIssue/PR creation and displayRemove if wrongAgent identity settings (bin/gh-wrapper.sh:1068-1113, src/pkg/scheduler/pr_annotations.go:146-158)
Priority labels (triage/accepted, ai-fix-requested, approved-direction, kind/bug, bug, priority/critical-urgent, priority/important-soon, help wanted, good first issue)Human-filed issuesRankingHuman-filed issues with these labels go to tier 0 in kick lists.Soft orderingHuman/HiveRankingRemove labelHIVE_ACTIONABLE_PRIORITY_LABELS (src/pkg/github/client.go:2740-2832)
auto-qa, auto-qa-finding, kind/security, kind/regressionIssuesClassifierauto-qa/auto-qa-finding make Simple; kind/security/kind/regression make Complex.Soft classificationHive/humanClassificationRemove labelClassifier tables (src/pkg/classify/classifier.go:279-303)
run/spec, run/fixIssuesRuns triageForces spec or direct-fix triage when runs triage is enabled.Gate when enabledHuman/HiveTriageRemove labelruns.triage.enabled (src/pkg/classify/triage.go:1-55)
runs.triage.spec_labels / fix_labels (v6/edge Spek)IssuesSpek/runs triageConfigured exact labels route to spec or fix; mark this v6/edge when documenting Spek behavior.Gate when enabledOperator/humanTriageRemove label/configruns.triage.spec_labels, runs.triage.fix_labels (src/pkg/classify/triage.go:35-55)
tracker, meta-tracker, tracking, epic (last segment)IssuesTracker detector, PR claim rewrite, contributor queueMarks coordination-only/tracker issues; agents see tracker tags, contributors do not get them.Soft for agents; hard for contributorsHuman/HiveEnumeration/contributor admissionRemove label or close trackerTracker detector (src/pkg/github/client.go:2090-2156)
hive-plan, hive-designIssuesPlanning label sweephive-plan mints/decomposes an epic; hive-design asks architect for design first. works when planning-from-label is enabled and ACMM >= 5.Gate when enabledHumanPlanning sweepRemove label or process plan/designplanning.plan_from_label, planning.plan_labels, planning.design_labels (src/pkg/config/config.go:400-460, src/pkg/planning/issue.go:483-510)
lgtmPRsQueued auto-merge sweepQueue label for human/owner merge action; the sweep also requires its normal authorization and skips held/exempt PRs. Adding by hand is not enough if the App approval/authorization is absent.PermitDashboard/mergerAuto-merge sweepRemove label; head changes can de-queuegovernor.labels.automerge, default lgtm (src/pkg/config/config.go:3388-3396, src/pkg/config/config.go:4952-4957, src/pkg/github/automerge/automerge_sweep.go:966-1036)
reviewer-passedPRsReviewer lane/escalation reconciliationMarks reviewer pass/de-escalation; with no needs-human, un-escalates.WorkflowReviewer lane/HiveReviewer/escalation passRemove if intentionally re-reviewingFixed label (src/pkg/escalation/escalation.go:1185-1205)
reviewer-recommend-closePRsReviewer laneReviewer recommends closing rather than continuing automated repair.WorkflowReviewer laneReviewer passHuman decides/clearsFixed label (src/pkg/scheduler/reviewer_lane.go:296-305)
review.human_decision_labelPRsHuman-decision mirrorMirrors review requires_human verdict to an existing repo label. It gates nothing and Hive does not create/remove it.InformationalHive if label existsReview verdictHuman removesreview.human_decision_label (src/pkg/github/human_decision_label.go:1-36, src/pkg/config/config.go:7186-7203)
needs-rebasePRsScanner/kick annotationFills mergeability annotation in kick data.InformationalScanner/HivePR status processingRemove after rebaseFixed label (src/pkg/scheduler/pr_annotations.go:117-144)
hive/covered-by-prIssuesPR-claim label sync and dashboardOpen PR is verified as related; issue remains actionable. Labels are synced for actionable issues, so stale labels can remain on held/exempt/filtered issues.Display-onlyHiveClaim sync after enumerationHive removes when actionable issue no longer has open PR evidenceFixed label (src/pkg/github/prclaims.go:1380-1435)
hive/likely-doneIssuesPR-claim label sync and dashboardMerged PR is verified as related while issue remains open; issue remains actionable until GitHub/operator closes or confirms.Display-onlyHiveClaim sync after enumerationHive removes when actionable evidence no longer says likely doneFixed label (src/pkg/github/prclaims.go:1380-1435)
hive/already-doneIssuesContributor queue, already-done verdict close path, and dashboardContributor already-done verdict/confirmation; default contributor skip label and done band. When the verdict cites a PR that the API verifies as merged on the default branch, Hive labels the issue and runs the normal completed close path; human-filed bugs still wait for reporter confirmation unless they opted into close-on-merge.Contributor hard skip; dashboard display; conditional closeHive/contributor flowContributor admission, verified verdict settlement, issue close gateHuman removes/reopens or confirms reporter-gated bugshub.contribute_already_done_label, fixed label (src/pkg/config/config.go:4701-4924, src/pkg/dashboard/contribute_verdict_settle.go, src/pkg/github/issue_close.go)
blockedIssuesContributor queue and dashboard issue bandsAlways included in contributor skip patterns and default waiting band. Does not by itself stop spoke-agent enumeration unless also exempt/held/filtered.Contributor hard skip; displayHumanContributor admission/dashboard renderRemove labelhub.contribute_skip_labels, dashboard bands (src/pkg/config/config.go:4585-4685, src/docs/dashboard.md:105-140)
needs-directionIssuesEnumeration, escalation labels, dashboard issue bands and un-park sweepADR-0019 escalation marker for work that needs a maintainer direction decision before continuing. Filtered from enumeration like needs-human: no agent kick, kick claim or contributor offer. The un-park sweep keeps the same “What to reply” notice as needs-human/needs-decision and accepts the same /hive approve or /hive decision <text> commands. See Maintainer commands.Hard suppress until directedHive/humanDashboard render and un-park sweepHuman removes, or a maintainer replies /hive approve / /hive decision <text>, which also adds approved-direction and never touches hold (src/pkg/github/issue_unpark_command.go)Fixed escalation label (src/pkg/github/labels.go, src/docs/adr/0019-escalation-over-stalling.md)
needs-decisionIssuesEnumeration, contributor relay, dashboard issue bands and un-park sweepRelay can apply it when a maintainer decision is needed; filtered from enumeration like needs-human, so no agent kick, kick claim or contributor offer. The un-park sweep keeps the “What to reply” notice and command handling documented in Maintainer commands.Contributor hard skip; displayRelay/Hive/humanContributor admission/dashboard renderHuman removes, or a maintainer replies /hive approve / /hive decision <text>, which also adds approved-direction and never touches hold (src/pkg/github/issue_unpark_command.go); empty config disables relay applicationhub.contribute_needs_decision_label (src/pkg/config/config.go:4397-4408, src/pkg/config/config.go:4645-4685)
needs-triage, discussion, question, tracking, epicIssuesContributor queueDefault contributor skip labels/patterns.Contributor hard skipHuman/HiveContributor admissionRemove label or confighub.contribute_skip_labels, HIVE_CONTRIBUTE_SKIP_LABELS (src/pkg/config/config.go:4585-4685)
Contributor allow/deny label filtersIssuesContributor queueHive-wide label filters can run in deny mode (skip if any label matches) or allow mode (offer if at least label matches); per-repo filters layer on top and can narrow offers. Patterns use Hive wildcard/substring matching, not GitHub hold matching.Contributor hard gateOperatorContributor admissionEdit filter mode/list or per-repo filterhub.contribute_labels_mode, contribute_deny_labels, contribute_allow_labels, contribute_repo_filters (src/pkg/config/config.go:4388-4420, src/pkg/config/config.go:6940-6994, src/pkg/config/config.go:7008-7055)
1-triage, 2-discussing, stage labelsIssuesDashboard repo-card bands/legendStage vocabulary is display-only unless another consumer names the same label. 2-discussing ships in the default waiting band; 1-triage is just a visible repo taxonomy label unless configured elsewhere.Display-onlyHuman/repo automationDashboard renderRemove label or change band configdashboard.issue_bands (src/docs/dashboard.md:105-140)
claimed, preempted:<login>, hive/claimed-by-<agent>IssuesClaims/dashboardA claim is a comment; the claimed label is a mirror Hive keeps in sync. Go claim gates use comments/assignees/ledger, not these labels.Display-onlyHive/claim flowsDashboard renderCleared by claim flow or humangovernor.claims.* (src/docs/dashboard.md:105-140)
from-reviewIssuesReview backlog filingMarks issues filed from review findings. No code path uses it as a gate.InformationalHiveIssue creation/displayRemove labelFixed label (src/pkg/github/review_backlog.go:1-40)
hive: churn-triagedIssuesContributor churn guardMarks churn triage acknowledgement for contributor flow.Workflow signalHuman/HiveContributor/churn checksRemove label to re-triageFixed phrase in contributor flow docs/config (src/pkg/dashboard/contribute_admission.go:302-338)
good first issue, help wanted, bug, enhancementIssuesContributor opportunistic orderingSmall ordering boost/visibility in contributor panels; good first issue, help wanted, and bug also appear in default actionable priority labels for human-filed issues.Soft orderingHuman/HiveContributor queue/rankingRemove labelContributor/ranking config (src/pkg/github/client.go:2740-2832)

Matching rules

  • GitHub generic holds are case-insensitive substring matches against hold, on-hold, hold/review, plus configured non-hive-pause/ extra holds. A label such as threshold contains hold and therefore holds (src/pkg/github/client.go:1894-1932).
  • hive-pause/<hive-id> is case-insensitive exact match, not substring, so it does not collide with hive/<hive-id> provenance (src/pkg/github/client.go:1898-1932).
  • Exempt labels use case-insensitive equality or prefix for permanent/configured labels, but the prefix check uses the original label string (src/pkg/github/client.go:2030-2048).
  • Contributor skip labels are lowercased and matched with path.Match glob syntax; invalid globs fall back to exact case-insensitive matching (src/pkg/config/config.go:4658-4708).
  • Lane routing lowercases labels and matches lane/routing tokens by segment, so agent/scanner can route to scanner; PR agent/ ownership paths are stricter and should be treated as case-sensitive operationally. The wrapper writes agent/<lane> from HIVE_AGENT, so the label always carries a routable token (src/pkg/classify/classifier.go:249-276, bin/gh-wrapper.sh:1068-1113).
  • Planning and triage labels are exact label names after normalization; defaults are prefixed (hive-plan, hive-design) so ordinary plan or capitalized Epic taxonomy does not trigger planning (src/pkg/config/config.go:400-460, src/pkg/classify/triage.go:66-84).
  • Linear holds use GitHub-like case-insensitive substring matching with defaults plus work_source.linear.hold_labels (src/pkg/worksource/linear.go:344-355).
  • Jira holds use exact, case-sensitive equality against configured work_source.jira.hold_labels; there is no built-in Jira default (src/pkg/worksource/jira.go:50-68, src/pkg/worksource/jira.go:302-330).
  • GitHub Projects work source carries labels through but does not implement a hold-label gate (src/pkg/worksource/github_projects.go:250-285).

Config that changes label behavior

  • github.self_authorization_hold, project.repo_policies[].self_authorization_hold, and HIVE_SELF_AUTHORIZATION_HOLD change #5117 holds. When all are unset, the default follows the live ACMM level: on through L5, off at L6 Fully Autonomous.
  • Hive-wide ACMM level controls level holds; per-repo ACMM overrides do not make PRs skip the level hold.
  • governor.labels.exempt, governor.labels.automerge, and project.issue_filter.require_labels decide exempt/admit/queue behavior.
  • project.issue_filter.reporter_trust.* (admission by reporter), github.reporter_trust_hold, project.repo_policies[].reporter_trust_hold, and HIVE_REPORTER_TRUST_HOLD (the matching merge hold) are the #9665 reporter-trust gate. Off unless reporter_trust.enabled: true; the hold follows that switch unless set on its own. Both are edited under Settings → Labels (who is trusted, which triage label) and Settings → Repos (the hold).
  • planning.plan_from_label, planning.plan_labels, planning.design_labels, and planning.design_approved_label control planning labels, with the L5+ planning floor.
  • runs.triage.enabled, runs.triage.spec_labels, and runs.triage.fix_labels control run triage labels.
  • governor.question_autoclose.* (HIVE_QUESTION_AUTOCLOSE, HIVE_QUESTION_AUTOCLOSE_HOURS) closes answered question issues; see Question auto-close.
  • governor.claims.*, review.human_decision_label, hub.contribute_*, dashboard.issue_bands.*, and HIVE_ACTIONABLE_PRIORITY_LABELS control the display/contributor/ranking labels above, including contributor label allow/deny filters and per-repo narrowing.
  • work_source.linear.hold_labels and work_source.jira.hold_labels are non-GitHub label-equivalent gates with the different matching rules described above.
  • Not labels: project.paused_repos pauses an entire repo; contributor queue holds can park owner/repo#N without changing GitHub labels.

Question auto-close

Off by default (#9584). When on, a question issue the hive has answered is closed after a short window unless the person who asked objects, so answered questions stop inflating the open-issue count and being rescanned every sweep.

governor:
  question_autoclose:
    enabled: true          # or HIVE_QUESTION_AUTOCLOSE=true
    hours: 4               # or HIVE_QUESTION_AUTOCLOSE_HOURS; default 4
    labels: [question, kind/question]   # default; what marks a question
    human_label: needs-human            # default; added when the author objects

How it works:

  1. The scanner kick gains a short answer contract: an issue that asks a question gets the question label and answer comment, which ends with a hidden “ marker and the line “If this doesn’t answer your question, react 👎 to this comment and the issue will stay open.” The footer text is built by Hive and passed through the mention sanitizer.
  2. Hive watches question-labelled issues from the normal issue pass. When the last comment on is a marked answer posted by the hive’s own identity (the GitHub App bot login <app-slug>[bot] or project.ai_author), it schedules a close at answer time + hours. The schedule lives in /data/question-autoclose.json, so a restart keeps the original deadline. The marker is plain text, so a marked comment from any other account (a person or another bot pasting it) is ignored and never starts the clock; with no hive identity known, nothing is auto-closed.
  3. At the deadline Hive re-reads the issue. A 👎 from the issue author on the answer keeps it open and adds human_label. Otherwise the issue is closed with state_reason: completed and no extra comment, so the answer stays the last thing Hive said.

A schedule is cancelled (never acted on) when anyone comments after the answer, the issue is closed by someone else, the question label is removed, or a bug, enhancement, hold or human_label label appears. Bugs (bug, kind/bug, human-filed bug reports), enhancements/features and held issues are never auto-closed. A cancelled or finished answer is remembered for 30 days so the same answer is never scheduled twice; a new answer after a follow-up starts a new window.

Dashboard

The Governor dialog’s Features tab has a “Question Auto-Close” section: a switch for enabled and a field for hours (GET/PUT /api/config/governor/question-autoclose, owner-only, same pointer/only-what-you-send contract as the other governor-config sections). Turning it on there shows a read-only live-schedule table underneath — row per answered issue currently waiting out its objection window (repo/issue, answered-at, closes-at), backed by GET /api/config/governor/question-autoclose/schedule. The table is read-only: labels/human_label still need hive.yaml.

Lifecycle examples

Strategist-filed direction to a PR

  1. Strategist files an issue with [strategist]/agent/strategist. It is actionable but lower-ranked as hive-filed.
  2. A maintainer adds approved-direction, assigns a human, or comments. Label or assignee also improves ranking; a comment satisfies #5117.
  3. An agent opens a PR citing the issue. If the acknowledgement existed before PR creation, no #5117 hold is applied. At L3-L5, the separate level hold can still apply.
  4. If acknowledgement is added after a PR already has hold, remove the PR hold too.

Holding an issue

  1. Add hold/on-hold/hold/review, or use dashboard ⏸ Hold to add hive-pause/<hive-id>.
  2. Enumeration moves it to the Hold list. It leaves agent kicks and the contributor queue.
  3. Caveat: the task-list and SHA sweeps do their own listing but honour the same hold predicate; SHA-hold lifts the literal hold it applied itself.
  4. Remove the hold label or click ▶ Release; it is reconsidered on the next enumeration.

Holding a PR

  1. The PR receives hold from a human, the level gate, #5117, holdguard, or SHA-related policy.
  2. It is not merge-eligible or auto-merged. If CI is red and it is not outreach/escalated, its owning agent may still be asked to fix CI without removing the hold.
  3. If the branch moves while held and then the hold is lifted, holdguard re-adds hold; removing it again is the fresh approval.

Escalation

  1. Red CI across the distinct-SHA budget applies PR needs-human; automated fix dispatch stops.
  2. Reviewer lane may add reviewer-passed and remove/un-escalate needs-human, or add reviewer-recommend-close.
  3. A human can remove needs-human after addressing the root cause; the ledger resets after the grace period.

Non-label equivalents

  • Human comments and assignees can acknowledge hive-filed directions for #5117; assignees also affect ranking.
  • Hidden comment markers carry state that no label does. records an issue claim, dedupes a published finding, marks an overlap notice, starts the question auto-close clock, and “ is stamped on the single comment a fix lane leaves on a PR it defers to shared incident #<n> (DEFER_TO_INCIDENT from bin/hive-baseline-check.sh), so “every PR incident #<n> broke” stays greppable after the fix lands (#10441). marker per PR per incident; it is never edited or removed while the incident is open. While incident #<n> is open, the governor records it as deferred_incident on the PR’s ci-failing.json row and the kick builders keep that PR out of every CI-FAILING / FIX-BEFORE-NEW repair list, naming it as deferred; the incident closes the PR is listed for repair again (#10528).
  • Paused repos (project.paused_repos) stop whole-repo write/merge/enumeration paths without labels.
  • Contributor queue holds such as active leases, cooldowns, dependencies, and quota guard holds suppress contributor offers without touching GitHub labels.
  • Jira/Linear labels map where the work-source adapter supports them: Linear skips held work using substring hold labels; Jira skips exact configured hold labels; GitHub Projects currently imports labels but does not use a hold gate.

Repo-card legend vocabulary

The repository-card legend is a UI vocabulary, not a second scheduler. Unclaimed, claimed, needs-triage, needs-human, and confirm-and-close issue bands are computed client-side from labels/assignees, the snapshot’s human_acknowledged flag (the cheap half of the #5117 acknowledgment: approved-direction or a human assignee, no comment scan), and dashboard.issue_bands; PR bands are computed client-side from held/needs-human labels, merge verdicts, CI, review links, draft state, and the same waiting/stale display config. Non-winning states stay as badges. State glyphs such as ⛔, ❓, 👤, ✓, role badges, stale 🕒, PR ✓/◐/⚠, held ⏸, failing CI ✗ CI, conflicts ⑂, reviewed 💬, auto-merge 🔀, and review-class badges explain the same data the table above names. Changing a band label changes the repo card description; it does not make an item held, exempt, mergeable, or actionable.

Documented inconsistencies and follow-ups

Issue #8924 recorded the sharp edges of this page’s first version; #8927 aligned the code: auto-merge sweeps, the task-list sweep, and the SHA-hold sweep now gate on the enumeration hold predicate (so hive-pause/<hive-id> holds everywhere), SHA-hold lifts its own hold, policy templates name the enforced hold set, and agent/<role> is always the lane name. Two behaviours remain deliberate rather than fixed:

  • Level-hold and #5117 disabled-policy auto-release are different. The self-authored auto-merge sweep may still release its own #5117 self-authorization holds, but ACMM level-applied holds are never auto-released by a sweep or level change. They are released by a human removing hold, or by a deliberate-off PUT /api/packs/level with release_level_holds: true, which touches Hive App level-hold notices whose latest hold event was by the App.
  • hive-open-pr discards every --label value, including hold, because the PR-request watcher applies holds server-side (bin/hive-open-pr.sh:142-150, src/docs/hive-open-pr.md).