Review workflow

Modes and requests

The three modes

Each reviewer (each lineage/version/executor) has its own mode, set per repository on /connect:

Wide tables: scroll horizontally to see more columns.

Mode What starts new work
Automatic Eligible PR events (opened, reopened, marked ready for review, or pushed to) and explicit requests.
On request Explicit requests only — a push alone does not start this reviewer.
Off No new review or recheck work. History and non-model actions (deferral, reading past findings) remain available.

Reviewer settings apply to future admissions only; work already accepted can still finish even after you change the mode.

What a newly connected repository starts with

For newly connected repositories, the selected initial mode applies to the configured reviewers. The default selection is Automatic; choose On request before saving to connect without starting automatic reviews. The connect page states the consequence before you save: "Automatic also queues existing open, non-draft pull requests. Before saving, move any PRs you want to exclude to Draft, or choose On request." and "On request connects new repositories without starting automatic reviews. Comment /sigma review on a PR when you want a review." — with the reminder that "With API keys, each review is paid. Changing modes does not cancel reviews already queued." A repository you are re-enabling, or that already has saved reviewer modes, keeps those modes instead of resetting to Automatic.

Requesting a review explicitly

Explicit requests can start enabled Automatic and On request reviewers on a pull request:

  • A comment that is exactly /sigma review (optionally followed by a reviewer selector — see reviewers-and-executors.md).
  • The registered App-mention form, @<the App's actual slug> review.
  • Requesting a review from Sigma's own bot through GitHub's reviewer control. An unrelated requested reviewer does not start Sigma.

These request new model work; API stages incur API usage and subscription stages consume their provider allowance. For comment commands, re-delivering or editing the same old comment does not authorize another run, even on the same head. Re-requesting a review from Sigma's own bot on GitHub is treated the same way, once per request on a head.

Who may call Sigma

A call is accepted from the maintainer who owns this Sigma, or from anyone GitHub reports as having admin, maintain or write access to that repository. Without that access — or if Sigma cannot confirm your permission at that moment — the call is ignored with the closed reason "pilot commands require write access," with no reply, and it is not retried later; write a new comment once the underlying cause is fixed. Sigma caches a checked permission for up to an hour, so a permission change can take up to an hour to take effect.

Replying inside a finding's thread is a separate, narrower case, still owner-only today — see replies-and-rechecks.md.

Drafts

An explicit /sigma review (or the App-mention form) works on a draft PR. Automatic PR events, by contrast, apply to open, non-draft pull requests (opened, reopened, ready-for-review, or a push) — a plain push to a draft does not start an Automatic reviewer.

What a push does

A push to an already-reviewed head does not silently restart the running review. If an older run for that PR is still queued or in progress when a newer head (or a base/state change) arrives, that older run's check reads "Review superseded", with one of these reasons on the summary:

  • "The pull request was closed or merged; this review is no longer needed."
  • "The pull request became a draft, so Sigma stopped this review. Comment /sigma review to review the draft."
  • "A newer change superseded this run; it does not describe the current head." (the default reason for any other source/state change)

A superseded run's history and any cost it already incurred are kept; it is not treated as a completed review of the new head. Automatic reviewers pick up the new head on their own; On request reviewers need a fresh /sigma review.