Using Prow-style OWNERS for agent dispatch authorization
Fullsend can use Prow-style OWNERS files to authorize users to run agents without needing direct collaborator roles on the forge. You can introduce these files whether your project already uses Prow or not.
GitHub only. The
owners_fileprovider is read on the GitHub webhook dispatch path (slash commands, label triggers, and event triggers). The Go poll path used for GitLab and Jira does not read OWNERS — authorization on those platforms uses native forge roles only.
For background on the default forge-permission model (write vs. triage thresholds, dispatch-path differences), see Agent dispatch authorization.
Setup
Add the
owners_fileprovider to.fullsend/config.yaml:yamlauthorization: - provider: owners_fileCreate (or update) an
OWNERSfile at the repository root withapproversand/orreviewerslists:yamlapprovers: - alice - bob reviewers: - carolapproversreceivewrite-equivalent access — all agent slash commands and custom agents registered underagents:. Exception:/fs-fix-stopalways checks the forge's collaborator API (or PR authorship) and does not read OWNERS.reviewersreceivetriage-equivalent access —/fs-triageand/fs-reviewonly (custom agents still requirewrite).(Optional) Define aliases in an
OWNERS_ALIASESfile at the repository root:yamlaliases: backend-team: - alice - bobThen reference the alias key in
OWNERS:yamlapprovers: - backend-team
How OWNERS interacts with forge permissions
OWNERS can only raise a user's effective role, never lower it. Users not found in OWNERS fall through to the forge's permission API. The OWNERS file is read from a trusted ref so that PR authors cannot add themselves: pull_request_target and pull_request_review events use the PR's base-branch SHA; all other events — including slash commands posted on a PR (issue_comment) — use the default branch.
For edge cases (parse failures, alias restrictions, character validation), see the authorization config reference.
See also
- Configuring Agent Behavior — harness overrides, model selection, and agent toggling
- Customizing Agents — overview of all customization approaches
- Authorization Contract — normative role hierarchy and exception rules
