What a review looks like
How heyGRC posts findings on a pull request: neutral Checks status, inline comments, one sticky summary, and /heygrc on demand.
heyGRC is a compliance reviewer, not a merge gate by default. On each review pass it grounds findings in the frameworks and company context you configured. It looks for compliance-relevant changes, not bugs. Summary and finding prose follow the org review language (default English).
What appears on the pull request
-
Checks status
A GitHub check run for heyGRC. By default it is neutral (or success when clean): it informs; it does not fail the PR to block merge. You can make it required in branch protection if you want a gate. -
Inline comments
Findings on the lines that matter: control ID / reasoning where a change touches an obligation. Inline threads are resolvable conversations (see Does heyGRC block merges?). -
One summary per PR (sticky)
heyGRC keeps a single summary for the pull request and edits it in place as you push. It does not stack a new full summary on every commit. A new review notification is posted only when there are new findings at Medium or above. Lower findings appear in the summary. Re-runs with nothing new at Medium or above stay quiet on the conversation. A/heygrcmention that finds nothing new can confirm completion with a reaction on your comment.
When reviews run
Review cadence is set in the console (org default, optional per-repo override):
| Mode | Behavior |
|---|---|
auto | Review when a PR is opened, reopened, or pushed to |
auto_once | Review on open/reopen only (not every push) |
mention_only | Silent until someone comments /heygrc |
Default is auto. Teams that already run a noisy code-review bot often start with auto_once or mention_only.
On-demand: /heygrc
Comment /heygrc on a PR to trigger a review. You must be an Owner, Member, or Collaborator on the repo so a drive-by commenter cannot spend your reviews.
Large pull requests
heyGRC does not skip a pull request for being too large. On a very large PR it reviews the most compliance-relevant files first and names the files it did not review. Lockfiles, generated files and vendored files are excluded first. Orgs that enable EU inference use a smaller review budget, so on huge diffs more files may be left unreviewed.
Inference footer
When an org has EU inference on, the review summary includes Inference: EU (Mistral) so you can see which path ran. Default orgs have no extra inference line.