SOC 2 Type 2 is sometimes described as a ban on fully agentic merges. The reviewed evidence does not support that blanket claim. The change-management criterion, CC8.1, addresses authorization, testing, approval and controlled implementation. It does not prescribe a person clicking every merge button.
The controls an organization implements can be more specific. If its process requires an independent person’s approval, an agent bypassing that step breaks the stated control. A bot merging after the required approval is a different workflow. Whether an entirely automated approval path is appropriate depends on its risks, controls and evidence, assessed with the responsible control owner and auditor.
Type 2 examines how controls operated over a stated period. Generating code, reviewing it, authorizing a change, merging a branch and deploying production are separate actions to trace. A passing test suite or a second agent identity does not, by itself, establish effective approval or independence.
The workbench’s approval-policy presets change only the fraction requiring human review. Every task sets it to 100%; selected tasks sets it to an illustrative 10%. Your other inputs stay fixed and the previous scenario is pinned for comparison. Neither percentage is a SOC 2 requirement. The model assigns tasks mechanically; it does not classify risk, inspect approval evidence or measure missed defects.
Use the comparison to ask whether the workload fits a chosen policy. A shorter queue cannot tell you whether that policy is sound. Before changing a real approval boundary, examine the applicable controls and the quality of the decisions alongside waiting time.
What this review can establish
Checked 5 October 2026. The full AICPA criteria and new AI TQA downloads require account access and were not read in this review. The interpretation draws on reproduced CC8.1 wording in an issued report and the attributed practitioner analysis. This lab does not assess SOC 2 compliance.