A concrete pattern for a Playwright/TypeScript project using an AI coding agent (Cursor, Claude Code, GitHub Copilot, or similar):
- Agent A generates the feature and an initial test draft, in its normal working session.
- The PR is explicitly labeled (a simple GitHub label like `ai-generated` or `needs-independent-verification`) so the verification step isn't left to memory. A label-based gate is cheap to implement and easy for a reviewer or CI check to enforce.
- A separate verification pass runs against the labeled PR, using either: a fresh AI agent session with no access to Agent A's chat history or reasoning, prompted specifically to check whether each test asserts the business rule or just the current implementation, or a human reviewer using a short, specific checklist (see below) rather than a general "LGTM" pass.
- CI enforcement, so this isn't optional: a GitHub Actions check that blocks merge on PRs carrying the `ai-generated` label until a second reviewer (human or a distinctly configured verification agent) has approved, separate from the author's own approval.
A minimal GitHub Actions snippet enforcing a second, distinct approval on labeled PRs:
name: independent-verification-gate
on:
pull_request:
types: [labeled, synchronize, opened]
jobs:
require-second-reviewer:
if: contains(github.event.pull_request.labels.*.name, 'ai-generated')
runs-on: ubuntu-latest
steps:
- name: Check for independent approval
uses: actions/github-script@v7
with:
script: |
const reviews = await github.rest.pulls.listReviews({
owner: context.repo.owner,
repo: context.repo.repo,
pull_number: context.payload.pull_request.number,
});
const approvals = reviews.data.filter(r => r.state === 'APPROVED');
const author = context.payload.pull_request.user.login;
const independentApproval = approvals.find(r => r.user.login !== author);
if (!independentApproval) {
core.setFailed('PR is labeled ai-generated and requires an approval from someone other than the author.');
}
This is a starting point, not a complete governance system: it enforces that *someone* other than the author approved, not that the approver actually ran the specific verification checklist. Pair it with the checklist below as a PR template section, so the reviewer has a concrete job rather than a vague sign-off.
A short reviewer checklist to paste into the PR template for anything labeled `ai-generated`:
- Does each new assertion check the business rule, or just that a response came back / no error was thrown?
- If the underlying logic were subtly wrong (not crashed, just wrong), would this test fail?
- Was this test written by the same session that wrote the code it tests? If yes, has an independent pass happened yet?
- For anything customer-facing or compliance-relevant, has a human (not just a second AI pass) signed off?