A software-as-a-service company has a change-management control, checked in its annual audit, that requires a named human engineer to approve every change before it reaches production. Its 60 engineers want Claude Code to review pull requests because the median wait for first feedback is nine hours, and most early comments concern style, missing tests and obvious null-handling errors. Which design best cuts the wait while keeping the control intact?
- ARun Claude Code as an automatic first-pass reviewer that comments on each pull request, with a named human approval still required to merge Correct
- BLet Claude Code approve and merge the pull requests it rates as low risk, and route only the remaining pull requests to a human approver
- CAdd a second mandatory human reviewer to every pull request so that the audit evidence is stronger while the AI review runs
- DHave Claude Code review each pull request and record its approval under the account of the engineer who opened the request
Why A is correct: This is correct because the AI review gives fast feedback on the style, test and null-handling issues that dominate early comments, while the merge still depends on a named human approval, so the audited control is unchanged.
Why B is wrong: This is tempting because it removes the most waiting. It is wrong because the control requires a named human approval on every change, and it also relies on the model's own risk rating to decide what skips human review.
Why C is wrong: This is tempting because it looks like extra assurance. It is wrong because the requirement is to cut the wait, and a second mandatory reviewer lengthens it without addressing the routine issues the AI review could catch.
Why D is wrong: This is tempting because it produces an approval record without any wait. It is wrong because no human has actually approved the change, so the audit evidence would misrepresent who approved it and the control would be defeated.