Synced from Hive. This page is pulled from hivecommons/hive@v5 during the docs build. Edit the canonical source in the Hive repository.
Running a hive at ACMM Level 6
For people who operate a hive, Level 6 means unattended merging, not just faster agents. Protect every destination branch with real required tests and coverage checks; aim for 90% or better coverage before enabling automatic merging. Stage repositories individually, keep work creation below CI/merge capacity, and prove your emergency stops work before you need them. Human-authored PRs can merge too. A reviewer comment, a spending limit, and paused agents are not substitutes for a merge stop.
This guide walks through preparation, a weekly routine, and recovery. Start with the merge-path table, configure the five areas below, then use the single pre-switch checklist. After a bad merge, stop further harm first, revert and verify, then demonstrate that a strengthened required check rejects the original change.
Last checked: 2026-10-04 against branch v5, commit 18e4a36e6d81c9e9fcefc6a3dcab8f93b25355e9. Source links name files and symbols rather than fragile line numbers. DOCUMENTED NOT EXECUTED: this is a code-checked guide, not a live deployment trial. JUDGMENT CALL consistently marks operating choices that the product does not establish. Hive does not enforce those choices unless the practice explicitly names an enforcement mechanism.
How directions are given. Every step says where to do it in the dashboard first and gives the config-file setting second. Nothing in this guide needs an API call. Where the dashboard has no control for something, the step says so.
Read this before enabling unattended merges
ACMM is Hive’s AI-native Capability Maturity Model: levels determine permitted automation. Level 6 (L6) is Fully Autonomous, not a release-branch name. An agent is a configured AI worker; a pack supplies a level’s roster, modes and defaults. The governor schedules workers according to workload modes; a cadence is an agent’s wake interval in mode. These definitions and the shipped roster are grounded in the Level 6 pack. scanner has ISSUES_PRS_MERGE; other delivery agents create PRs but the App can merge them independently.
Auto-merge here means Hive initiating a merge without a person doing it, not GitHub’s similarly named feature. A hold is a label-based exclusion from work/merging, including literal hold and the dashboard’s hive-pause/<hive-id> item hold. See labels and control signals; the enforcing predicates are HasHoldLabel, IsHeldLabels and HasExemptLabel in GitHub client.
Which PRs merge without a person?
All answers assume the repository participates in automatic merging, the PR is ready, unheld and non-exempt, GitHub allows the merge, and the path’s checks pass. The common per-repository gate is RepoAutoMergeEnabled in repo policy; below L6 it returns false.
| Author | Direct answer and deciding path |
|---|---|
| Hive’s agents | Yes. The App self-authored sweep needs no human queue approval. It checks author, labels, GitHub mergeability, CI, intent policy and the head again before merging. See trySweepSelfAuthoredPR in sweep. Outreach is an exception below. |
| Dependency bot | Yes, for exact logins in auto_merge.trusted_bot_authors (unset means dependabot[bot]). This is the same sweep with the same gates. Others can enter the scanner/queued paths; removing a bot from this list is not a universal author denylist. See TrustedBotAuthorSet in config and sweepLaneForAuthor in sweep. |
| Contributor relay | Yes. ClankeR is the external contributor relay, not a separate merge exception. Its PRs can enter the scanner’s current merge-eligible list, without a human lgtm. The human queue is another route, not a requirement at L6. See classifyMergeEligibility, bindMergeAuthz in eligibility. |
| Person by hand, including an unknown person | Yes. The scanner eligibility classifier is not filtered by author. An unknown PR author is not itself a merge hold. Reporter trust concerns the issues motivating work, not a blanket PR-author restriction. See eligibility and reporter-trust hold. |
The third route is the human-approved queue (normally lgtm): an authorized merger/owner queues someone else’s PR; the sweep rechecks that authorization. See handleQueuePRAutoMerge in dashboard API and trySweepQueuedPR in sweep. A bare lgtm from an arbitrary account is not authorized queueing.
What waits, and what releases it?
| Item | Why it waits; release |
|---|---|
| Held PR or issue | Label-based hold. A human removes the hold after reviewing the actual current head/request, or resumes the dashboard item hold. Promotion does not release holds automatically, and the dashboard’s level change has no option to release them. See level hold. |
| Outreach PR | shouldHoldAgentPR always holds outreach, even at L6. Human review and removal of hold release it; no level switch removes this exception. See eligibility. |
| PR motivated by an untrusted reporter’s issue | When reporter-trust holding is enabled, an untrusted cited issue causes literal hold; a maintainer reviews and removes it. Triaging the issue alone does not release the PR. See reporter-trust hold. |
| Draft | Excluded; author marks ready for review when finished. See eligibility and sweep. |
| GitHub-blocked PR | Missing required checks/reviews, signatures, conflicts or branch rules still bind the merge. Satisfy the actual rule, not just the Hive pill. See merge block reasons and sweep. |
| PR escalated after failed fixes | The fix ledger parks exhausted repair work; needs-human is a triage signal, not by itself a universal merge hold. The scanner separates escalated rows; the App sweep does not consult that ledger. A green App PR may still merge. Add hold if the decision must prevent merging; repair/review, clear the escalation, then release the hold. See escalation, writeMergeEligible in eligibility, and sweep. |
| Behind/conflicting fork PR | A GitHub behind state triggers an update attempt in the sweep, not a guaranteed repair. The hive cannot assume write access to a contributor’s fork. Author rebases/updates the fork, resolves conflicts and reruns CI; a fork merely older than base is not blocked unless GitHub requires freshness or reports a conflict. See sweep and UpdateBranch in pull requests. |
| Issue parked for a maintainer decision | A human with repository write/maintain/admin permission comments /hive approve or /hive decision <direction>; the un-park sweep removes decision labels, never hold. Plain “approved” is insufficient. See maintainer commands and un-park implementation. |
Does the Hive reviewer stop a merge?
Default: no automatic guarantee. The reviewer is advisory. Its requires_human text is not read by the App sweep. With review.require_approval: true, the scanner eligibility path requires aggregate approval at the same head SHA; absent artifacts or a non-approved verdict stop that path. It does not add a review gate to the App sweep or replace GitHub branch rules. Dispatch fan-out also has its own enabling conditions. See classifyMergeEligibility in eligibility, PlanDispatch in review dispatch, and sweep.
The policy matrix describes the same distinction: reviewer verdicts alone are not universal merge stops, and promotion does not automatically release level holds. Use GitHub rules or an actual hold for a safety guarantee.
Label discipline
Before L6, map your repository’s labels to Hive’s gates. In the dashboard, start with Settings → Labels, Settings → Repos, Governor Config → Hub, and the repository-card legend. Compare them with the repo’s GitHub labels and lifecycle/Prow rules. Where a setting has no dashboard control, use the config file with the deployment operator. Hive ships defaults, not a universal workflow: map your existing labels or opt out of conflicting behavior before enabling unattended work. #10537 illustrates the collision between a repo’s triage/accepted/needs-human workflow and Hive’s /hive approve transition to approved-direction.
Config keys to cross-check: project.issue_filter.require_labels, project.issue_filter.reporter_trust.untrusted_require_labels, governor.labels.exempt, governor.labels.automerge, github.self_authorization_hold, github.reporter_trust_hold, per-repo project.repo_policies[].{auto_merge,self_authorization_hold,reporter_trust_hold}, hub.contribute_*labels, governor.claims.*, review.human_decision_label, dashboard.issue_bands.*, and work_source.{linear,jira}.hold_labels (under governor in runtime YAML).
| Label / signal | Who sets it | What Hive does | Human action |
|---|---|---|---|
hold, on-hold, hold/review, hive-pause/<hive-id> | Human, dashboard, Hive hold paths | Hard work/merge hold; held red PRs can still get CI repair without release. | Use when an item must not proceed; remove after reviewing the current head/request. |
do-not-merge*; governor.labels.exempt defaults (nightly-tests, LFX, meta-tracker, auto-qa-tuning-report, adopters, changes-requested, waiting-on-author) | Human, repo automation, operator | Suppresses enumeration and merge sweeps. | Remove the label/config exclusion when Hive should act again. |
Issue needs-human, needs-decision, needs-direction, needs-spec | Hive, relay, human | Suppresses issue kicks/offers. Un-park commands handle the first three, not needs-spec. | Use /hive approve or /hive decision <text> for a repo using Hive’s command flow; otherwise use its mapped label workflow. Commands never clear hold. |
PR needs-human | Hive escalation/reviewer | Stops automated fix dispatch, not every merge path. | Add hold if merging must stop; clear escalation after repair/decision. |
approved-direction | Maintainer command/label workflow | Acknowledges Hive-filed direction for the self-authorization gate and ranking. | Map it to your acceptance workflow; do not assume it releases existing PR holds. |
triage/accepted; configured untrusted-reporter ready labels | Human/operator | Admits untrusted reporter work when reporter trust is enabled, subject to other filters. | Match the actual reviewed-ready label; test accepted and unreviewed issues. |
blocked | Human/repo bot | Contributor exclusion and waiting display, not a spoke-agent hold alone. | Add hold or an enforced filter if agents must not act. |
help wanted, good first issue, bug, kind/bug, priority/* | Human/repo bot/Hive | Ranking/visibility; some kind labels classify work. | Treat as prioritization, not approval. |
kind/security, kind/regression, auto-qa, auto-qa-finding, lane labels, agent/<role> | Human/Hive | Classification, routing, provenance. | Verify lane keywords and ownership; these are not holds. |
area/* | Human/repo bot | Helper validation; generic scheduling gates if configured. | Maintain ownership taxonomy, not an assumed safety gate. |
lgtm; governor.labels.automerge | Dashboard/authorized merger | Queues authorized human-approved merging; rechecks holds, CI and mergeability. | Do not substitute hand-labeling for authorization. |
review.human_decision_label | Hive, if configured label exists | Mirrors a verdict; text alone does not gate the App sweep. | Choose an actual hold label/GitHub rule when review must stop merging. |
hive/advisory | Hive | Standing advisory, never actionable. | Leave alone unless deliberately moving the digest. |
hive/covered-by-pr, hive/likely-done, hive/verified-open | Hive/agent outcomes | Progress display; verified-open suppresses stale likely-done state. | Confirm/close/remove based on real outcomes, not as a merge stop. |
hive/already-done | Contributor flow | Contributor skip/done display; not a universal agent gate. | Verify the outcome before clearing/closing. |
claimed, preempted:<login>, hive/claimed-by-<agent>, “ | Claim flows | Ownership/display; the ledger/comments carry claim state. | Use governor.claims.comment: false for noisy comments; claim labels do not replace holds. |
release-blocker | Human/release workflow | Stable promotion script gate on open issues. | Clear after release blocker resolution, not to unblock ordinary L6 work. |
ci-flake | CI/Hive scripts | Flake tracking, not an L6 hold itself. | Fix/quarantine the flake while keeping required checks meaningful. |
user-feedback | Dashboard/hub | Feedback provenance. | Triage reporter input; apply trust/hold policy as needed. |
dco-signoff: yes / dco-signoff: no | DCO/Prow | Merge-eligibility display; branch rules enforce the gate. | Fix commit sign-offs rather than hand-editing labels. |
conflicts-with-open-pr | PR-overlap workflow | Overlap signal. | Resolve or close conflicting work before merging; same-file overlap alone may be harmless. |
no-changelog | Dependabot/maintainer | Repo changelog exception, not a Hive safety gate. | Apply under repo policy. |
human-only remainder text (not a default label) | Agent/reviewer | Task-list sweep can park remaining issue work as needs-human. | Treat as a handoff; add PR hold if merging must stop. |
Verify the mapping with canaries: a held item stays held, an accepted issue enters the intended queue, an unreviewed issue stays out, and repo bots do not undo each other’s decision labels. Generic GitHub holds use substring matching (threshold also holds); Linear holds use substring matching, Jira holds use exact configured labels, and GitHub Projects carries labels without an adapter hold gate. Do not assume identical enforcement across sources. Sources: label reference, maintainer commands, GitHub predicates, issue labels, un-park, claim config, progress labels, remainder sweep.
Getting ready to switch
GitHub settings
For hosted and self-hosted hives alike, GitHub repository/organization administrators configure these on GitHub, not the Hive dashboard. In these rows, GitHub enforces its rules; Hive does not enforce the recommended policy choice. The source describing Hive’s interaction is given per row.
| Practice: what and where | L6 failure avoided; how to verify |
|---|---|
G1. Restrict App installation scope. GitHub organization/repository Settings → GitHub Apps → installed Hive App → Configure: select intended repositories; match Hive’s project.repos in runtime config. | Broad installation gives credentials reach beyond intended work. Verify the installation’s repository list against the dashboard repo cards. See App setup and Repositories in client. |
| G2. Grant the documented App permissions, not an assumed owner identity. App administrators use App Settings → Permissions; installation administrators accept permission updates. Include the documented contents/PR/issues/checks/actions access and Workflows write if workflow edits are in scope. | Missing permission causes forbidden API calls or rejected workflow pushes, not useful automation. Verify a harmless PR and permitted workflow edit on a test repository; inspect App errors. See App setup and PR request watcher. |
| G3. Protect every destination branch. Settings → Rules → Rulesets (or Branches → protection): require build, tests, coverage and security contexts, including release branches, with no App bypass for these checks. | Unprotected bases can merge; Hive no longer refuses solely for lack of protection. Verify an intentionally red and a missing-context test PR are blocked for the App identity. See CI gate. |
| G4. Decide whether humans approve. In the same ruleset, require approving/code-owner reviews for branches where unattended merging is unacceptable; make that rule apply to the App. JUDGMENT CALL: retain it for high-impact branches. Maintain CODEOWNERS so those paths have real owners: required code-owner review protects matched paths. Verify with an owned-path canary and an unowned-path canary. | A review rule without App bypass stops unattended merges; a bypass removes this protection. Verify GitHub reports awaiting review before any App merge. Hive’s reviewer approval is not a GitHub approving review. See block reasons. |
| G5. Require an up-to-date base. Enable strict required checks/“Require branches to be up to date before merging” on each protected branch. | Green on an older base does not establish green after integration. Verify a PR becomes blocked after a base push until updated/retested. The sweep attempts updates for behind; see sweep. |
| G6. Allow the merge methods actually used. Settings → General → Pull Requests: allow squash; also allow merge commits if managing release-line forward merges. | The ordinary method is squash; recognized forward merges use merge commits to preserve ancestry. Disallowed methods cause merge refusals. Verify landing method in a test PR and ancestry for a sync PR. See mergeMethodFor in sweep and pull requests. |
| G7. Keep fork-run approval deliberate. Settings → Actions → General → Approval for running fork pull request workflows: choose the trust policy your maintainers can service. JUDGMENT CALL: require approval for untrusted fork authors rather than relaxing it to drain a queue. | Unapproved runs are action_required, not successful CI. Have a maintainer inspect the workflow/diff then approve runs; verify check evidence appears at the PR head. See forkRunApprovalReason in CI gate. |
G8. Test signed-commit requirements end to end. If your ruleset requires signatures, enable github.app_signed_commits in Hive runtime YAML (not a dashboard switch) and test follow-up commits too. | An unsigned follow-up can strand an otherwise green PR. Hive reconciles its own commits, not people’s work. Verify GitHub’s Verified badge at the latest head and branch-rule acceptance. See signed reconciliation. |
Test coverage of 90% or better
T1. Make the 90% target a real CI gate. In each repository’s CI workflow, measure coverage using its native test tooling, save the report as an artifact, and fail below 90%; make that exact job a required GitHub context and declare it in Hive’s required-check set below. Without both, a flattering badge or an optional red coverage job does not protect L6. Verify by opening a PR whose measured coverage falls below the floor and checking that the App cannot merge it. The project’s 90% target is only reported by the advisor, not enforced by Hive as a coverage percentage; CI enforces your configured floor. Sources: advisor code, commit CI, eligibility.
T2. Keep an 82%-covered repository out of auto-merge while improving it. Turn its repo-card auto-merge switch off; use quality work to add behavior/regression tests for uncovered risk, human-review those changes, then measure again in CI. Enable after the 90% target and branch gates are demonstrated. This staging choice is JUDGMENT CALL, not a Hive enforced readiness rule. Verify increasing report coverage and a regression test that fails on the old broken behavior. The quality lane is available in the pack; the switch is enforced by repo policy.
T3. Cross-check the reporting input. The coverage number to trust is the repository’s CI report with its denominator/exclusions, not an agent’s prose. HIVE_COVERAGE_BADGE_URL supplies the dashboard measurement: self-hosters set it in their deployment environment (not dashboard); hosted operators ask the hub operator to set it. Verify the badge agrees with the report. It is a reporting input, not a merge floor. See coverage collector and advisor inputs.
Direct answers about checks:
- Failed test: does Hive still merge? No if it is a required gating check; yes, possibly if it is optional and GitHub allows merging.
- Failed coverage job: does Hive still merge? No if required; yes, possibly if optional. The scanner explicitly permits optional-only red when an operator-declared required set exists and GitHub reports mergeable (
onlyOptionalRed). A report uploaded successfully without a failing floor does not block a merge. - No check results: does Hive merge? The App sweep can say yes after its age/expected-check and GitHub mergeability gates; GitHub protection is essential for missing required contexts. The merge-request path says no to zero statuses/checks/workflow runs unless the repo is explicitly in
auto_merge.no_ci_ok. Aneutralorskippedobserved check is also accepted by the shared evaluator, so keep required gate workflows executing meaningful tests. Missing required contexts block on the merge-request path; on the App sweep, the evaluator recordsMissingRequiredbut its green result does not itself reject that list. GitHub’s required-check rules must supply the missing-context block there. Do not rely on the Hive declaration alone. Unapproved or failed workflows that produced no jobs are also checked on the merge-request path.
These are path-specific, not an “all CI green” promise: see commit CI, sweep, CI gate, and eligibility.
Knowledge accumulation
A bead is an agent’s persistent work-ledger entry. The default hourly bead synthesizer classifies closed beads into wiki facts. It is not merged-PR fact extraction; that old pipeline was never wired. Collection can run while priming is off. The primer selects knowledge for an agent’s next kick (work prompt). See knowledge boot, synthesizer, and knowledge curator reference.
| Practice: what and where | L6 failure avoided; verification and enforcement |
|---|---|
K1. Enable and inspect priming. Dashboard → Knowledge: turn knowledge on (knowledge.enabled in the config file). The panel’s badge must not read not primed or restart required; if it does, the panel’s banner says what still needs a restart. | Stored facts alone do not reach workers. Open an agent’s card → Prior Prompts and check that a recent kick contains relevant facts, not just that the wiki count is growing. The toggle enforces priming enablement, not knowledge quality. See live primer wiring. |
| K2. Add project-specific constraints by hand. JUDGMENT CALL: record release branches, test commands, forbidden migrations, rollback steps and prior incidents in Knowledge or a managed public markdown git source; validate selected facts against the repo. | Generic accumulated notes can miss the costly local exception. Read several real kicks under an agent card’s Prior Prompts and have a maintainer correct contradictions; Hive does not enforce “enough knowledge” or factual accuracy. Sources/import locations are in curator reference; source wiring is in knowledge boot. |
K3. Supply a maintained checkout if relying on AGENTS.md. Set project.checkouts_dir in runtime YAML; populate <directory>/<bare-repo-name>/AGENTS.md. This filesystem setting is not a dashboard checkout provisioner. Self-hosters mount/update it; hosted operators need hub-operator help. | Without a real root the instructions are not injected. Verify the primary repo’s root instructions appear in a kick (agent card → Prior Prompts) after a checkout update. Hive enforces parsing/injection when present, not freshness of your clone. See AGENTS.md reference and agentsRepoRoot in scheduler. |
Hive settings
Both hosting types use the same spoke dashboard for owner-authorized changes. “Runtime YAML” below means the effective persisted config, not merely a seed ConfigMap; see config layering. Self-hosters manage that file and restart their service; hosted operators ask the hub operator for file/environment/restart changes they cannot perform. Never run repository tests in a live hive to verify configuration.
Each row is a separate practice. Except where marked, the recommendations address the cited shipped behavior; they are not readiness checks that Hive automatically applies.
| Practice: recommended value/rule and change location | Why at L6; verify; enforced versus recommended |
|---|---|
H1. Choose participating repos explicitly. Repo-card Auto-merge → off for every unqualified repo; stored as project.repo_policies[].auto_merge. | The L6 level action enables all active repos. Inspect each card after changes; an off repo must reject a test merge. Hive enforces the switch, not your qualification rule. See repo API, repo policy. |
H2. Declare all critical checks by exact name. Governor Config → Auto-merge → Required checks (auto_merge.required_checks); mirror branch rules, including coverage. Across heterogeneous repos choose contexts all participating repos produce, or standardize a single aggregate gate. | This is a hive-wide list, not per-repo names; a missing name can block every PR. Config takes precedence over protection discovery. Check a red/missing context and a green test PR on each repo. Hive gates observed checks in the declared set, not its completeness; the sweep’s missing-context gap above makes GitHub protection essential. See config, commit CI. |
H3. Leave no-CI exceptions empty. auto_merge.no_ci_ok: [] in runtime YAML, not a dashboard field. | Avoids turning absent evidence into passing evidence on the relay; does not fix the sweep’s no-results behavior. Verify no-evidence merge requests refuse. Hive enforces this exception list; recommendation is to grant none. See CI gate. |
H4. Start with merge per sweep pass. JUDGMENT CALL: Governor Config → Auto-merge → Max merges, auto_merge.max_merges: 1, raising after recovery drills. | Limits a burst’s sweep blast radius; this is not a global parallel-merge cap on all paths. Verify in the dashboard’s Audit Log that merges arrive at the pace you expect. Hive enforces this cap; unset uses 3. Sweep timing adapts to repositories/candidates, not an operator-set interval. See sweep. |
H5. Keep the post-push quiet period. Runtime YAML auto_merge.min_head_age: 3m (not a dashboard field); lengthen if slow check registration demands it. | Avoids trusting a fresh head before checks register. It may be bypassed when a config-declared required set is already successful. Verify fresh-head pending messages, not a guaranteed three-minute delay. Hive enforces this conditional rule. See commit CI and defaults in config. |
H6. Narrow the bot sweep list. Governor Config → Auto-merge bot toggles, auto_merge.trusted_bot_authors: keep CI-qualified exact bot logins; use an explicit empty list to disable the bot lane. | Unset enables dependabot. Verify in Audit Log which bot PRs were merged, and remember scanner merging is separate. Hive enforces sweep membership. See config, sweep. |
H7. Enable reporter trust for public issues. Settings → Labels → Reporter trust (project.issue_filter.reporter_trust); choose trusted associations/logins deliberately, not every historic contributor. Leave github.reporter_trust_hold inherited from that gate unless deliberately making it stricter. | Reporter trust is off by default. It controls whose issues lead to work/unattended merges, not PR authors. Verify an unknown reporter’s issue is triage-only and a PR citing it is held. Hive enforces configured admission and PR hold. See reporter hold, config. |
H8. Decide whether the hive approves its own proposals. JUDGMENT CALL: enable the all-repos self-authorization hold in Governor Config → Repos (github.self_authorization_hold: true), checking per-repo overrides and any environment lock when a human must agree to hive-filed proposals; otherwise retain L6’s off-by-level default. | Off permits the hive to propose and implement without human assent; on can create a large held backlog. Verify a hive-originated proposal’s PR gets hold and the notice, or deliberately does not. Hive enforces the configured hold, not the wisdom of the proposal. See self-authorization, config. |
H9. Decide whether automatic large-plan approval is acceptable. JUDGMENT CALL: if not, stay below L6 or hold the particular epic/children. plan_auto_approve belongs to the shipped pack, not the runtime governor config; there is no per-hive dashboard/YAML override for this boolean. | L6’s pack enables it and the plan sink reads the level’s pack directly, allowing child tasks without human plan approval. Verify the plan/child labels and admission. Hive enforces pack-derived approval policy, not design correctness. This differs from treating the pack key as a general operator knob. See PlanAutoApproveForLevel in pack config, planFromLabeledIssues in runtime wiring. |
H10. Keep input scanning fail-closed. Governor Config → Security → Input Defense → ioscan fail mode, closed (ioscan.fail_mode); retain the L6 inherited default. ioscan screens incoming/outgoing text for injection. | Critical suspect input blocks a kick rather than being redacted; false positives need investigation. Verify in Audit Log that a blocked item shows an ioscan_fail_closed entry and received no kick. Hive enforces the fail mode, not perfect attack detection. See kick input enforcement, pack. |
| H11. Begin with shipped cadences, not continuous issue generation. Agent settings → Cadences; keep the pack’s per-mode matrix, slowing work creators when backlog grows. | The pack records the 2026-09 tuning lesson: 119 issues opened versus 31 closed in 24 hours. Verify creations versus merges and queue age fall after slowing. Hive enforces intervals; no throughput balance is enforced. See the pack comment and governor. |
H12. Set a funded token budget. JUDGMENT CALL: Governor Config → Budget, governor.budget.total_tokens, choose from measured recent use for the displayed period_days window; separately set a monetary cap at your inference provider. | Zero disables budgeting; tiny limits can suppress essentially every kick. Compare tokens used/remaining and provider dollars against the intended window. Hive enforces token kick suppression (subject to exemptions/ignore settings), not a dollar ceiling or a merge stop. See governor. |
| H13. Keep optional lanes paused until their output is wanted. Agent controls/Cadences: retain shipped pauses for supervisor, strategist, outreach, telemetry and operations in all modes. | More issue-filers can worsen saturation; L6 does not mean every lane is active. Verify actual pause/cadence state in each mode. Hive enforces pauses; deciding which work is wanted remains yours. See pack, agent pause. |
| H14. Deliver alerts to someone who can act. JUDGMENT CALL: Settings → Notifications: configure a documented ntfy/Slack/Discord destination and a responsible operator. | A dashboard-only warning may go unseen while merges continue. Send the documented test notification and verify receipt; Hive sends configured notifications, not an acknowledgement/SLA. See notifications, notifier. |
H15. Do not mistake review approval for a universal merge gate. JUDGMENT CALL: if choosing review.require_approval: true, set it in Governor Config → Security → PR Review (Require review approval) and use GitHub rules or literal holds for changes that require human review. | The setting gates the scanner, not the App sweep. Verify both routes with test PRs; Hive enforces the path-specific approval check. See eligibility, sweep. |
H16. Turn issue claims on so workers do not collide. Governor Config → Features → Issue claims (governor.claims.enabled: true); set governor.claims.{human_ttl_s,agent_ttl_s,contributor_ttl_s} to match how long work actually takes. Claim an item yourself with hivectl claim o/r#N before you start on it. | Off by default. With claims off, two of your own agents, a relay contributor, an outside bot and you can all start the same issue and open competing PRs; the duplicate-PR sweep sees the collision after the PRs exist. With claims on, the hub records who is working an issue and ranks holders human > agent > contributor > external, so a lower rank backs off and a higher rank takes over with a preempted:<login> label. The record is a marker comment (“) or the assignee on the GitHub issue itself, so it needs no organization: a single user’s personal repos work, and any other hive or script reading the issue sees the hold. Claims lapse on their own (4h person, 2h agent kick, 30m relay task unless configured). Verify: claim a test issue, confirm claimed appears and that an agent kick on that issue is withheld; let the claim lapse or hivectl unclaim, confirm the issue is actionable again. Hive enforces the ledger and expiry, not the discipline of claiming before you start. See claims, issue claims, claims config, hivectl claim. |
ClankeR settings
ClankeR is the contributor relay offering external compute to a hive. A trust tier is the contributor profile’s server-side standing, distinct from reporter trust and dashboard access roles. Controls below are under Governor Config → Hub on the hive serving /contribute, also exposed on its contribution admin page. They are not the unrelated central hub’s global settings. Hosted owners use that hive’s admin UI; self-hosted owners use their own dashboard. All are owner-controlled; see Hub config API and relay admin reference.
| Practice: what and where | Risk; verify; enforcement |
|---|---|
C1a. Exclude unqualified repositories. JUDGMENT CALL: Hub → Repos for Contribute, put unqualified repos in hub.disabled_repos. | New repos otherwise default on, amplifying unready work. Verify each repo’s ready-work count. Hive enforces repo admission, not qualification. See contribution API/queue. |
C1b. Require a readiness-label mode. JUDGMENT CALL: Hub → Label filter, hub.contribute_labels_mode: allow, with the non-empty list in C1c. | Deny mode can admit untriaged work; an empty allow list also means filter off. Verify unlabeled work is withheld. Hive enforces the mode at queue build, not label correctness. See queue filters. |
C1c. Name the readiness labels. JUDGMENT CALL: Hub → Label filter list, hub.contribute_deny_labels contains your reviewed ready labels (the legacy key name is used in allow mode too). | A wrong/empty list defeats the intended admission policy. Compare ready-work entries to reviewed GitHub labels. Hive enforces list matching, not work quality. See queue filters. |
C1d. Exclude decision/held work independently. JUDGMENT CALL: Hub → Contribute skip labels, hub.contribute_skip_labels, retain decision/blocked exclusions and add your manual hold labels. | Ready labels must not override a later hold/decision. Verify doubly-labelled work stays out of the queue. Hive enforces these skip filters before ordinary filters. See contribution API. |
C2a. Name evaluated models. JUDGMENT CALL: Hub → Allowed Models, hub.contribute_allow_models, use a non-empty list evaluated on your tasks. | Empty accepts all models. Verify accepted patterns against successful task trials. Hive uses relay-declared metadata, not independent proof of model identity. See connection admission. |
C2b. Enforce the model list. Hub → Reject Unknown Models, hub.contribute_reject_unknown_models: true alongside C2a’s non-empty list. | With rejection off the list is not a hard boundary. Verify a disallowed connection fails. Hive enforces connect-time rejection, not actual reasoning quality. See checkModelAllowed in connection admission. |
C3a. Set an effort floor from task trials. JUDGMENT CALL: Hub → Effort floor, hub.contribute_min_reasoning_effort: high, revising from quality/cost measurements. | Empty floor does not constrain effort. Verify low effort refuses and accepted effort passes. Hive enforces the backend-normalized floor at connect time, not reasoning quality. See effort admission. |
C3b. Refuse unclassified effort. Hub → Reject Unknown Effort, hub.contribute_reject_unknown_effort: true with C3a’s floor. | Otherwise unknown/absent effort can pass. Verify an unknown-effort connection refuses. Hive enforces this conditional rejection against declared metadata. See checkEffortAllowed in connection admission. |
C4a. Limit delegated roles. JUDGMENT CALL: Hub → delegated-role controls, hub.contribute_delegatable_roles, keep needed ordinary lanes, not privileged roles. | Contributor execution need not imply authority over every lane. Verify role-claim refusals. Hive enforces role/tier grants, not your confidence judgment. See trust and roles, role enforcement. |
C4b. Review before granting higher trust. JUDGMENT CALL: Operations → Connected clankers tier dropdown: manually grant trusted/merger after reviewing outcomes. | Completed PR tasks establish activity, not safety. Newcomer→contributor promotion occurs after five PR tasks; trusted/merger are operator grants. Verify persisted profile tier and independently reviewed sample. Hive enforces grants, not confidence. See trust and roles, profile updates. |
| C5. Keep queueing separate from authorship. Manage Access: grant merger/owner to designated independent maintainers. | An author must not approve their own queued merge; this is enforced by the queue endpoint and queued sweep. Verify a self-queue request refuses. L6’s scanner route still needs no queue approval, so this is not a general reviewer requirement. See dashboard API, sweep. |
C6a. Rehearse contribution suspension. JUDGMENT CALL: know Hub → Suspend contributions (hub.contribute_suspended). | Suspending offers is not recalling already-open PRs or necessarily killing active tasks. Verify the ready-work queue is paused; stop/revoke active relays separately and use repo merge stops as needed. Hive enforces suspension/admission, not a universal emergency brake. See contribution API and relay reference. |
C6b. Rehearse individual revocation. JUDGMENT CALL: owner uses Operations → Connected clankers → Revoke for an unsafe contributor, and verifies it cannot reconnect. Stop any continuing workload separately and hold/disable merging for its existing PRs; revocation is not a rollback. Undo by deliberately restoring an authorized tier. Hive enforces the revoked-profile connection gate, not incident resolution. See handleAuthResponse in connection admission and trust reference.
Model/effort restrictions apply at the next connection, queue restrictions at the next build. Do not infer that changing them stopped a task already running; see relay reference and connection admission.
Notification hygiene
JUDGMENT CALL: do not make every maintainer watch every Hive write. Comments, labels, claims, reviews, merge messages, un-park notices and work-source activities create continuous noise at L6. Keep actionable alerts assigned to an operator; mute routine chatter, not incident signals.
GitHub Issues/PRs and Projects-backed work. In GitHub’s repository Watch → Custom settings, choose needed event types rather than all activity; use participation/mentions and individual thread subscriptions for focused attention. Filter mail from notifications@github.com by the configured App actor (for example hivecommons-hive[bot], in X-GitHub-Sender) and inspect hidden body markers when your mail client exposes them: , , , , , . Not all markers use the hive: prefix. Unsubscribe from ownership-only threads. Projects is a read source; Hive’s GitHub writes land on backing issues/PRs.
Linear. In Linear’s notification preferences, scope notifications for the Hive app user, delegated/assigned issues, mentions and relevant teams/projects. The agent integration posts as the app (actor=app) and can write thought/action/response session activities, comments/issues and PR links. In Hive Settings → Work Source, narrow Linear enumeration using assigned-only, team states, cycles, projects and hold labels (work_source.linear.*, under governor in runtime YAML). There is no source-neutral Hive mute for Linear session activity.
Jira. In Settings → Work Source, narrow project keys, JQL and hold labels (work_source.jira.*, under governor in runtime YAML). The v5 adapter reads Jira; generic WorkSource is read-only and source-neutral claim/comment/transition writes are not pluggable. If helper writes are enabled later, configure Jira’s project notifications for the credential account; do not assume Hive supplies a Jira-side mute.
Run stages and Wavefront. These additive sources list internal stage/graph work and record receipts; they do not themselves create source-native comments/labels. Noise generally appears on the GitHub issues/PRs opened for that work, so apply the GitHub guidance.
Hive chatter controls. Start in Governor Config → Advisory, Security → PR Review, and Hub; use the runtime config with the deployment operator for controls not exposed in the dashboard. Tune governor.advisory.update_interval_s and governor.advisory.target for digest cadence/destination. Leave review.post_comments off unless public reviews help humans; bound repeat notifications with review.combined_perspectives, review.max_perspectives_per_pr, review.max_reviews_per_head, and per-repo review.revise_repos. Bound duplicate-sweep comments with duplicate_sweep.post_comments/max_comments; turn claim comments off with governor.claims.comment: false. Respect the un-park action cap and repo label-workflow mapping rather than relying on email filters to hide conflicting automation. hive/advisory remains excluded from actionable work.
Verify a routine claim/review no longer floods unrelated maintainers, while a test incident alert and a direct mention still reach the responsible person. Sources: integration guide, work-source providers, work sources, Linear agent, configuration, claim config, un-park.
Readiness, staged switching and confirmation
R1. Use readiness numbers as evidence, not permission. While at L5, open the dashboard’s Advisory section and read the ⬆️ Ready to level up? card. Its checklist covers: quality agent present, coverage ≥90%, ≥12 consecutive non-red default-branch runs, merge success ≥95%, actionable issues ≤10, holds ≤5. These thresholds are only reported, not enforced or configurable. Verify against each repo’s CI and reviewed changes, not just a hive-wide aggregate. They do not measure security, test adequacy, production outcomes or knowledge accuracy. At L6 the advisor reports ready/stay because there is no higher level, not because all readiness criteria remain satisfied. See advisor, input collection.
R2. Stage without an all-repos merge window. JUDGMENT CALL: an owner should use the following sequence; Hive enforces the pause/repo switches, not this rollout discipline. The level action reconciles roster, pack fields and cadences (operator-owned cadences survive), activates L6 merge capability, and enables auto-merge for active repos. It does not add strong CI, change installation permissions, validate coverage or automatically release old holds. Sources: pack API, repo policy.
- Pause all managed repositories with repo-card Pause before applying Level 6. These pauses remove them from active repositories; do not merely disable auto-merge beforehand, because promotion re-enables active repos.
- As owner, click the ACMM level badge in the dashboard’s top bar (or ACMM Eval → Change level), choose Level 6 and Apply. No notice follows, so check the result yourself as in R3.
- While repos remain paused, switch Auto-merge off on every repository card, then look at each card again to confirm it stayed off.
- Resume just qualified repo, then enable its Auto-merge as verified owner. Other repos stay paused or are resumed with Auto-merge explicitly off.
- Verify an eligible test PR merges in the chosen repo; verify another repo rejects merging. Review any old held PR separately before removing its hold.
R3. Confirm intent after every switch, restart and upgrade. On the dashboard, check three things: the ACMM level badge in the top bar shows the level you intended; each agent’s card shows the mode, cadence and paused state you expect; and each repository card shows the Auto-merge and paused state you set. Then open Audit Log and confirm that merges are appearing, or have stopped, as you intended. If you keep settings in the config file, compare it with what the dashboard shows. Use a harmless held test PR to confirm it stays held, then a qualified canary to confirm the intended path works. Without read-back, a saved level alone can hide reconciliation or persistence failure. Hive reports state and errors; this verification discipline is JUDGMENT CALL. Sources: pack API, sweep startup, config layering.
Do not rely on a promotion notice: the checked dashboard defines maybeShowLevelAutoMergeActiveModal but the Apply flow does not call it. This differs from references promising a notice. Check state yourself; see dashboard.
Pre-switch checklist (complete per rollout)
These are confirmations of the practices above, not additional product gates.
- Real weeks at L3–L5 produced reviewed PRs matching your judgment; no calendar interval is enforced, and “not surprised” matters more than elapsed time.
- GitHub installation scope/permissions and every merge destination’s rules checked; App cannot bypass critical tests/coverage. Green CI genuinely means safe to ship, not just a passing harness.
- Each proposed repo meets the 90% coverage target with demonstrated failing gates; below-target repos remain excluded. Advisor readings and their limitations recorded.
- Per-repository opt-out decided and applied: Level 6 is not all-or-nothing. Each repository card’s Auto-merge switch is set deliberately (off for repos that are not ready or must stay human-merged;
project.repo_policies[].auto_mergein config), and a test PR in an opted-out repo was refused while agents kept proposing work there. Remember that re-applying Level 6 re-enables auto-merge for every active repo, so opted-out repos are paused during the switch (R2) or re-checked afterwards (R3). - Reporter-trust posture explicitly decided before promotion. For public issues, trust is on with the intended association set; decide specifically whether
CONTRIBUTORbelongs. Demonstrate admission and PR-side holding. - Knowledge priming enabled and actual prompts inspected; release/test/rollback constraints are accurate. Any relied-on checkout instructions demonstrably reach agents.
- Hive repo scope, required contexts, proposal/plan decisions, cadence, token budget, paused lanes and alert delivery reviewed.
- Issue claims enabled (
governor.claims.enabled) with TTLs that fit real task length; a claimed test issue was withheld from agents and released on lapse/unclaim. Humans know tohivectl claimbefore starting on an item that agents could also pick up. - ClankeR filters, model/effort admission, trust/roles, independent queueing and suspension tested.
- Repository labels mapped to Hive gates; acceptance, hold and un-park canaries do not conflict with lifecycle/Prow automation.
- GitHub/work-source notifications narrowed; routine chatter muted without hiding direct mentions or actionable incident alerts.
- Emergency brake understood: item
hive-pause/<hive-id>/hold, repo merge-off, and level step-down. Agent pause and budget exhaustion are not merge stops. - Outreach remains held at L6; human review is still expected, not removed by a setting or promotion.
- Staged rollout and fresh read-back/canary prepared; old holds will not be batch-released blindly.
Running week to week
W1. Review a small sample and trends every week. JUDGMENT CALL: name a responsible operator and record these readings in an operator log. Hive does not enforce a weekly review or a sample size. Without outcome review, green checks can repeatedly ship the wrong behavior. Verify corrective actions from the last review actually landed. Sources for the displayed mechanisms: fleet health, merge audit, governor budget.
| Look at / where | Healthy | Unhealthy / response |
|---|---|---|
| Merged sample / dashboard Audit Log, and GitHub merged PR search | Diff, required CI and actual outcome agree; inspect human/bot/relay and App lanes | Surprise scope or bypass: hold similar work and strengthen gate |
| Waiting on people / dashboard held/triage bands and GitHub hold/needs-human/needs-decision searches | Each has an owner and explicit next action | Aging ambiguous work: decide, repair, close or keep held with reason |
| Rework / dashboard Governor → PRs by model (review rounds, fix attempts), plus GitHub reverts and follow-up fixes linked to the merged sample | Low/stable rate and regression tests added | Repeat faults despite green CI: stop affected repo and fix blind spots |
Health/alerts / the alert banner at the top of the dashboard and Diagnostics; on a hub, the /fleet page | Known recent merge activity and alerts acknowledged | L6’s 12-hour merge-recency health is a liveness signal, not correctness; idle repo can be red without a defect, busy wrong repo can be green |
| Work opened versus merged / dashboard Throughput, and GitHub time-bounded issue/PR searches | Backlog age stable or falling; CI drains | New work consistently outruns merges: slow creators before adding compute |
| Spend / dashboard Tokens and Cost, the budget under Governor Config, and provider billing | Enough remaining tokens to drain work; expected dollar trend | Exhaustion or unexplained increase: investigate loops/cadence, not blindly raise cap |
W2. Slow creation before accelerating everything. When new issues/PRs outpace merges and oldest queue age rises across successive windows, lengthen creator cadences in Agent settings → Cadences; keep reviewer capacity available and repair CI bottlenecks. The pack already omits/pauses architect/guide work generation when busy/surging and keeps reviewer at 30 minutes. Verify lower arrivals and falling queue age after the change. Hive enforces cadence, does not enforce arrival/merge balance. Evidence: pack’s measured tuning comment.
W3. Use an actual hold for change. Add literal hold on GitHub or use the dashboard item’s Hold action (PR or issue) before a decision-sensitive change becomes eligible. Authors should open unfinished PRs as drafts, not ready PRs with a “please don’t merge” comment. Verify held/draft status and exclusion from eligibility. Hive enforces these states; prose requests, lack of lgtm, reviewer text and needs-human alone are not universal merge stops. The hold matcher is substring-based (threshold also contains hold); provenance hive/<id> is not a hold. See client predicates, item hold API, eligibility, sweep.
When something goes wrong
Stops, smallest to largest
S1. Choose the stop that closes the dangerous path, then read it back. Do not substitute paused workers for revoked merge authority. This practice follows the distinct enforcing paths cited below. Confirm in the dashboard’s Audit Log that no new merges appear after a repo merge stop, accounting for a request already in flight; a stop cannot undo a completed merge.
| Scope / action | What stops; what remains; can open PRs still merge? | Who, undo, verification/source |
|---|---|---|
PR or issue: literal hold or item Hold | That item’s Hive work/merge eligibility; other items continue. Held PR cannot merge via Hive; an issue hold is not a retroactive hold on every existing linked PR, so hold those too. | GitHub label-capable maintainer; dashboard owner/repo-write permission. Remove label/resume item after review; confirm head unchanged or re-review. Item API, client, hold guard. |
| repo: Auto-merge off | All Hive merge paths for that repo; PR creation can continue. Existing PRs cannot merge through Hive. Repo Pause additionally removes repo work enumeration/sweep activity. | Owner or repo-write user may switch off/pause; owner required to restore auto-merge. Resume repo and separately restore chosen merge policy. Confirm card + refused test merge. Repo API, repo policy. |
| agent: Pause | That worker’s execution/scheduling; other workers and App sweep remain. Existing green PRs can still merge. | Dashboard owner; Resume reverses manual pause. Confirm agent paused state. Agent control, pause implementation. |
| Every agent: fleet breaker, plus explicitly pause any remaining on-demand workers | Breaker pauses currently running non-on-demand agents, preserving already-paused states; it is not a merge brake. Existing PRs can merge via sweep. | Owner, using the fleet breaker button in the dashboard’s top bar. Release resumes breaker-owned pauses; manually paused agents stay paused. Confirm captured set and each agent status. Breaker API, pause implementation. |
| All automatic merging: disable Auto-merge on every repo, or step down below L6 | Repo gate blocks Hive merge authority on existing and new PRs. Workers can still create work according to the remaining level/modes. Disabling auto_merge.self_authored stops only the App sweep, not the scanner lane; restarting relays may be necessary for startup-captured sweep flags. | Owner for level change; owner/repo-write for repo off. Restore selected repo switches as owner; re-applying L6 enables active repos again. Confirm each repository card and the Audit Log. Repo policy, pack API, sweep wiring. |
| Contributor work: Suspend contributions, revoke/stop active relays if necessary | Stops offering/admitting contribution work as configured, not Hive’s other workers or automatic merges. Existing contributor PRs can merge; active work must be handled separately. | Owner in contribution admin; contributor can stop their own relay. Unsuspend/re-authorize after triage; confirm queue paused and active leases/workers accounted for. Contribution API, relay reference. |
These controls stop Hive, not a separate GitHub bot or a maintainer manually merging. For an immediate repo-wide incident boundary, a GitHub administrator can also revoke/suspend the App installation’s access; coordinate restoration and verify credential failures, rather than silently weakening branch rules. JUDGMENT CALL: use this larger boundary if Hive’s runtime state cannot be trusted. No Hive setting enforces that incident policy.
After a bad merge
S2. Contain, reverse, prove prevention. JUDGMENT CALL: use this ordered recovery procedure. Hive does not automatically enforce it. Perform changes with an authorized maintainer and keep the incident record on GitHub; verification is the artifact from each step, not “agent says fixed”.
- Prevent further harm. Turn the affected repo’s Auto-merge off; if scope is unknown disable all repos or lower the level. Pause harmful workers/contributions too. Confirm persisted switches and stopped merge activity using S1. Do not merely exhaust a budget or pause agents.
- Record the PR’s head and merge SHA, the merge’s entry in the dashboard’s Audit Log, the required-check results on GitHub, and the deployment revision. Work out whether the sweep, the scanner, a queued merge or another actor landed it. Sources: merge audit, relay merge.
- Revert through a human-reviewed PR (or use the project’s authorized emergency procedure), run CI, and verify the destination branch no longer contains the bad behavior. If deployed, roll back the application too and verify the running revision plus the failing user scenario; a Git revert alone is not a deployment rollback. For Hive itself, use the digest-verifiable rollback runbook.
- Determine the missed protection: absent context, optional coverage, stale base, unchecked integration behavior, bypass, or incorrect scope. Record an accurate knowledge fact and correction so future workers do not repeat the assumption.
- Add or strengthen a required check before restoring automation. Run the new regression/check against the bad PR’s exact head (it must fail) and the reverted/fixed head (it must pass). Verify the context is required on GitHub and in Hive’s declared set, with no App bypass. Then restore the qualified repo. CI gates, not the recovery prose, enforce future merging: commit CI, CI gate.
When work is stuck
S3. Repair the blocking system, not the symptom. Identify the row below from the reason the dashboard or GitHub shows before changing policy; verify recovery at the same PR head or a deliberately repaired head. Hive reports/enforces the cited gates, not an obligation to make every queue item merge.
| Cause / observable sign | Action and confirmation |
|---|---|
Suspected attack / an ioscan_fail_closed entry in Audit Log, and the item gets no kick | Inspect hostile text or false positive, sanitize/remove the input or hold it for a maintainer, then retry a safe prompt. Do not globally fail-open to drain the queue. Verify a safe kick and retained scan protection. Kick input enforcement. |
Escalated repair / needs-human on the PR after repeated failed heads | Read evidence, decide repair versus close; hold the PR if it must not merge meanwhile. Adjudicator may repair/de-escalate hive PRs at L6, but is not a human authorization substitute. Verify the repaired CI and that the label is cleared before releasing a real hold. Escalation, pack. |
| GitHub refused merge / a merge-blocked alert in the dashboard’s alert banner, or the reason shown on the PR; a branch that is behind or in conflict | Fix the specific permission/rule/signature/check; ask fork author to update when Hive cannot push. Retry at the verified new head. Never treat “mergeable” from an old snapshot as a merge result. Block reasons, sweep. |
| Spending limit / budget exhausted or provider-limit alert, no new kicks | Compare token window to provider money/quota; wait for reset or deliberately fund a realistic limit. Verify a successful probe/kick and falling queue. Existing PR merging is separate; use repo-off if that must stop. Governor budget, provider budget. |
| Checking infrastructure broken / same runner/startup failure across unrelated PRs | JUDGMENT CALL: stop affected repo auto-merging, repair runners/workflow plumbing, then rerun existing PRs. Do not ask agents to write unrelated tests or remove required coverage to fix a harness fault. Verify required contexts actually execute and pass, and a seeded failing case still refuses. Hive’s CI gate refuses opaque failed workflows; CI gate. |
S4. Step down when confidence in unattended landing is lost. JUDGMENT CALL: repeated bad merges, unavailable required CI, or inability to explain active authority warrant L5 while investigating. Owner changes the level through the level/pack control; verify as R3. Hive enforces repo merge-off below L6, so already-open PRs lose Hive automatic merge eligibility; it does not revert their commits or retroactively add a level hold to every old PR. Subsequent non-outreach agent PRs at L3–L5 receive the level hold; outreach stays held at all levels. Manual/other-bot merges remain outside this stop. Promotion later leaves old holds intact unless explicitly released, and enables active repos again. See repo policy, shouldHoldAgentPR in eligibility, level hold, pack API.
Maintainer review of this guide and its promotion belong to #10515, not an agent review. Until that sign-off, retain the notice and the index’s awaiting-review label.