Written by: Mark Hull, Co-Founder and CEO, Exceeds AI | Last updated: August 6, 2026
Key Takeaways for AI-Aware Branch Protection
- GitHub branch protection rules enforce reviews and status checks but cannot tell whether code came from humans or AI tools.
- With 97% of teams using AI coding assistants and only 30% having governance, most organizations lack code-level provenance to measure AI ROI and manage technical debt.
- Exceeds AI adds an observability layer that delivers line-level AI versus human attribution without changing existing branch protection configurations.
- Exceeds Ink captures authoritative, line-level AI provenance at creation time through lightweight Git hooks and portable JSON attestations.
- Connect your repo and start a free pilot with Exceeds AI to gain AI governance insights that branch protection alone cannot provide.
Why Standard Branch Protection Leaves AI Governance Gaps
Executives and boards now ask a specific question: is the AI investment paying off. Branch protection rules were designed to answer a different question entirely, which is whether a change went through the right process. These questions require different instrumentation and different data.
The measurement gap is already affecting how teams evaluate performance. Most engineering dashboards cannot separate AI-assisted commits from human-only commits, which makes before-and-after comparisons of team performance misleading when AI tools are introduced. This happens because enforcement mechanisms were not designed to capture code origin. A branch protection rule that requires two approvals before merge records nothing about whether the 847 lines in that PR were human-authored or agent-generated.
The quality risk compounds over time as AI usage grows. Faros telemetry found that under high AI adoption, bugs per PR are up 54%, median time in PR review is up 441%, and 31% more PRs are merged with no review at all. Branch protection can require a review. It cannot detect that the reviewer was evaluating AI-generated code without knowing that AI produced it.
Security exposure follows the same pattern. IOActive’s April 2026 whitepaper evaluated 27 leading AI models across 730 real-world prompts and found that AI-generated code can contain significant vulnerabilities, particularly in infrastructure and DevOps code such as Dockerfiles and CI/CD pipelines. A required status check that runs a linter will not catch these issues if the linter is not configured to flag the specific vulnerability classes that AI tools introduce at elevated rates.
Long-term outcome tracking is the third dimension that branch protection cannot address. An analysis of 304,362 verified AI-authored commits found that more than 15% introduced quality, security, or maintainability issues, and 24.2% of those issues still existed in the repository’s latest version. Branch protection has no mechanism to monitor what happens to merged code 30, 60, or 90 days later.
Before you extend branch protection with AI-aware observability, you need a clear baseline. The next section walks through standard GitHub branch protection so you can see exactly where AI provenance fits.
Configuring Core GitHub Branch Protection Rules
The following steps apply to any GitHub repository where you want to protect a branch such as main or production. GitHub’s official branch protection documentation covers the full option set. The steps below represent the configuration most engineering teams treat as a baseline.
- Navigate to your repository on GitHub and select Settings from the top navigation bar.
- In the left sidebar, select Branches under the Code and automation section.
- Under Branch protection rules, select Add rule.
- In the Branch name pattern field, enter the branch you want to protect. Use
mainfor an exact match or a pattern such asrelease/*for a group of branches. - Enable Require a pull request before merging. Set the required number of approvals to at least one. Two approvals are standard for production branches at most mid-market engineering organizations.
- Enable Require status checks to pass before merging. Add the specific CI job names, such as build, test, lint, and security scan, that must succeed. Check Require branches to be up to date before merging to prevent stale-branch merges.
- Enable Require conversation resolution before merging so that open review comments must be addressed before a PR can land.
- Enable Restrict who can push to matching branches if you want to limit direct pushes to a specific team or role.
- Enable Do not allow bypassing the above settings to prevent repository administrators from force-merging around the rules.
- Select Create to save the rule.
These settings enforce the merge process and protect your main branches. They do not record anything about the origin of the code that passes through them.
Adding Exceeds AI While Keeping Existing Rules Intact
Every rule configured in the section above stays exactly as it is. Exceeds AI does not modify branch protection settings, does not add required status checks to your existing rules, and does not sit in the merge path. It operates as an observability layer that runs alongside your existing workflow rather than inside it.
The entry point is a GitHub OAuth authorization that takes approximately five minutes. After authorization, you select the repositories you want to analyze. Exceeds AI immediately begins processing historical commit data. A complete 12-month historical analysis is available within four hours, and first insights appear within 60 minutes of authorization.

Start your free pilot and see AI adoption insights in 60 minutes
Configuring Exceeds Ink for Line-Level AI Provenance
The platform-level setup described above delivers AI versus non-AI outcome analytics using repository data. Adding Exceeds Ink upgrades that signal from inference to authoritative, line-level attestation. Ink is a single approximately 10 MB Rust binary that installs on each engineer’s machine and captures AI authorship at the moment work is done, before it reaches the repository.
The additional steps for Ink are straightforward.
- Complete GitHub authorization in the Exceeds AI dashboard, which you already used for the platform setup.
- Select the repositories where you want per-repo Ink hooks enabled. Ink uses per-repo opt-in, and it does not mutate global Git configuration.
- Install the Ink binary on each engineer’s machine using the installer provided in the dashboard. The binary installs in minutes and registers standard Git hooks:
prepare-commit-msg,post-commit, andpost-rewrite. - Allow Ink’s adapters for Claude Code, Cursor, and Codex to activate automatically on first use of each tool. GitHub Copilot and Windsurf adapters follow the same pattern.
Three points matter most for security review and IT approval.
- Ink is never in the request path. It makes no calls to Anthropic, OpenAI, Microsoft, or any AI provider. If Ink stopped collecting tomorrow, every AI tool would continue working exactly as it does today. This architectural isolation means Ink cannot introduce latency, availability risk, or vendor lock-in to your AI tooling.
- Data residency options are available. Enterprise customers can configure US-only or EU-only hosting. A self-host option is also available, because the remote ingest URL is configurable and the same binary works against a customer-operated collector. This flexibility addresses compliance requirements for regulated industries where data must stay within specific geographic boundaries or internal infrastructure.
- Privacy is configurable at four levels, from local-only, where nothing leaves the machine, through aggregate-only, abstracted replay, and full identified replay. Different teams within the same organization can run at different levels. This granularity lets you balance observability needs against privacy constraints on a team-by-team basis.
Ink writes its output as a Git Note at refs/notes/exceeds-ink. This note is a structured, machine-readable JSON attestation that travels with the repository across forks and mirrors and is readable by any Git client. Ink does not modify commit messages.
Validating Exceeds AI and Ink Across Your Repos
Once both the platform authorization and Ink installation are complete, you should confirm that everything works as expected. The following indicators confirm the setup is functioning correctly.

- The Exceeds AI dashboard shows first insights within 60 minutes of authorization, including AI adoption rates by repository and team.
- AI vs. Non-AI Outcome Analytics populate with cycle time, review iteration counts, and rework rates segmented by AI-touched versus human-authored code.
- Ink-attested commits appear in the dashboard with line-level attribution showing the tool, model, session, and interaction mode, such as plan, ask, agent, edit, or headless, for each AI-generated segment.
- Coaching Surfaces become available and surface actionable guidance for managers based on interaction-mode patterns observed across the team.
- Machine Integration Health reporting confirms which machines have Ink installed, which adapters are active, and whether deliveries are succeeding, without exposing prompt content.
Connect your repository to validate your setup
Scaling AI Governance Across Repositories and Teams
For organizations with multiple repositories, Exceeds AI supports per-repo opt-in at the Ink level, which allows a phased rollout. A common pattern is to start with two or three high-activity repositories, establish outcome baselines, and then expand to the full repository set after you validate security and privacy configuration.
Branch protection rules can enforce workflow gates on repositories but cannot reveal the percentage of code originating from AI tools versus human developers, leaving organizations unable to connect AI adoption metrics to actual codebase composition or productivity outcomes. Exceeds AI’s AI Adoption Map fills that gap at the organization level, showing adoption rates by team, individual, repository, and tool.

Risk-tiered policies become possible once Ink attestation is in place. Because the attestation is structured JSON in the repository, policy engines can query it directly. For example, you can require additional review on commits where agent-mode AI produced more than a defined percentage of the diff in sensitive paths such as authentication, payment logic, or data migrations.
Longitudinal outcome tracking runs automatically on Ink-attested code and monitors AI-touched commits over 30 or more days for incident rates, follow-on edits, and maintainability patterns. Some organizations have seen their change failure rate increase by nearly 2 percentage points since adopting AI tools, resulting in up to 50% more defects shipped compared to pre-AI baselines. Longitudinal tracking surfaces that signal before it becomes a production crisis.

Best Practices Insights, powered by a LangGraph-backed analysis pipeline, distill the team’s actual AI-coding patterns into the top skills worth scaling. When one team finds a pattern that works, Skill Transfer distributes it as a versioned skill across the organization and tracks adoption centrally.
Frequently Asked Questions
How long does setup take, and what access does Exceeds AI require?
GitHub OAuth authorization takes approximately five minutes. Repository selection and scoping adds another 15 minutes. The platform delivers insights quickly, and you see initial AI adoption metrics within an hour, with full historical analysis completing in about four hours. Exceeds AI requires read-only repository access. For the highest-security requirements, an in-SCM deployment option is available that keeps analysis within your own infrastructure. Exceeds AI has passed formal enterprise security reviews, including a Fortune 500 retailer’s two-month evaluation process.
Which AI coding tools does Exceeds Ink support?
Exceeds Ink ships five first-class adapters with deep per-tool fidelity: Claude Code, Cursor, Codex (OpenAI), GitHub Copilot, and Windsurf. Lighter-weight detection covers up to approximately 50 AI tools in total. The platform is tool-agnostic by design, because engineering teams in 2026 routinely use multiple AI tools simultaneously, such as Cursor for feature development, Claude Code for large refactors, Codex for batch transforms, and Copilot for autocomplete. Exceeds AI provides aggregate AI impact across all tools and tool-by-tool outcome comparison within a single dashboard.
Does Exceeds AI replace branch protection rules?
No. Branch protection rules and Exceeds AI address different problems. Branch protection enforces the merge process, including required reviews, status checks, and restrictions on force pushes. Exceeds AI supplies code-level provenance and outcome analytics that branch protection cannot provide. The two operate in parallel, and adding Exceeds AI requires no changes to existing branch protection configuration.
How does Exceeds AI prove AI ROI rather than just measuring adoption?
Adoption metrics such as license counts, acceptance rates, and weekly active users describe how many engineers use AI tools. They do not connect AI usage to business outcomes. Exceeds AI analyzes code diffs at the commit and PR level and distinguishes AI-generated lines from human-authored lines using Exceeds Ink’s authoritative, client-level capture. That line-level attribution is then correlated with outcome metrics such as cycle time, review iterations, rework rates, test coverage, and long-term incident rates on AI-touched code. The result is board-ready ROI proof down to the specific commit and PR, not just adoption statistics.
What is the pricing model, and is there a free option?
Exceeds AI uses outcome-aligned pricing with no per-contributor data tax. The Pilot plan is free for seven days and covers one seat, up to ten contributors analyzed, and five repositories. The Pro plan is $49 per manager per month (Early Partner Pricing), with unlimited contributors and repositories and Exceeds Ink available as an add-on. Enterprise pricing is available for custom seat counts and the full integration set including GitHub, GitLab, Azure DevOps, JIRA, and Linear. You pay for manager seats and the insights you use, not for every engineer analyzed.
Conclusion: Branch Protection Plus Proven AI ROI
GitHub branch protection rules remain an essential part of any engineering team’s quality and security posture. Required reviews, status checks, and force-push restrictions enforce the process gates that keep production branches stable. They are necessary, and they are not sufficient.
Automated tracking of AI-generated code matters for any team using AI in production, yet many teams still flag it manually in pull-request comments. Manual flagging is not provenance. It is a convention that engineers can follow inconsistently and that provides no line-level attribution, no outcome correlation, and no longitudinal tracking.
Exceeds AI supplies the code-level truth that branch protection cannot. Exceeds Ink writes a portable, auditable, line-level attestation alongside every commit and records which tool, which model, which session, and which interaction mode produced each line. The Exceeds AI platform connects that attestation to productivity and quality outcomes, giving engineering leaders the specific metrics they need to answer executives with confidence and giving managers the coaching surfaces they need to scale effective AI adoption across teams.
Setup completes in hours, and first insights appear within 60 minutes. Your current branch protection configuration remains untouched, because Exceeds AI operates alongside it, not within it.