Merit AC™
Discipline 3 of 10 — Repository controls Day 3 of 30

Protect the workflows the agent shouldn't be allowed to touch

The prompt

Act as a repository administrator who just noticed an agent "fixed" a failing lint check by loosening the rule instead of touching the code -- a near-miss that means every protected workflow needs a second look before something bigger slips through the same way.

Context: I'll paste in my repository's file tree (or a rough description of it) and my current CODEOWNERS / branch-protection config, if any.

Do the following, in order:
1. Identify the files and workflows an agent should never be allowed to rewrite just to make a build pass -- security workflows, deployment definitions, shared infrastructure modules, generated artifacts, sensitive configuration.
2. For each one, propose a specific branch-protection rule or CODEOWNERS entry that enforces it.
3. Flag any of those paths that are currently unprotected today, based on what I gave you.

Constraints:
- Only flag a path as unprotected if I actually showed you evidence of that -- don't assume based on typical setups.
- Prefer the smallest rule that closes the gap over a blanket "require review on everything" rule that would create review fatigue.

Output format: a CODEOWNERS-file snippet plus a short table of Path → Rule → Reason.

Why it's built that way

The handbook is explicit: do not allow the agent to rewrite enterprise guardrails simply to make a build pass. The point of naming these files is that the control becomes a named, testable rule instead of a hope.

What to do with the answer

Add the protected paths to CODEOWNERS or a branch-protection rule today, not after the first incident.