Also check: GitHub access (the scopes and the boundary), GitHub App setup (registering the app when self-hosting), Scenario tests and evals (what runs in CI on the PR).
How a Langy PR is made
1
Langy drafts the change
After it reads your traces and writes a failing test, Langy drafts a fix on a branch.
2
It opens a bot-authored PR
The GitHub App opens the pull request on the installed repo. The commits are authored by the bot; you are credited with a
Co-authored-by trailer and a “Requested by @<your-login> via LangWatch” note on the PR.3
Your CI runs the tests it wrote
The Scenario simulation tests Langy wrote run in your CI on the PR, so the PR carries its own proof.
4
A human reviews and merges
You review the PR like any other. Langy never merges; a person does.
Langy contributes to your codebase exclusively through pull requests. Nothing touches your code without a human approving the merge.
The install is the access boundary
Langy can only open PRs on repositories the GitHub App is installed on. The install is the boundary: there is no per-user OAuth and no stored personal token. If the app is not installed on a repo, Langy stops the turn the moment it reaches forgit or gh. It shows an Install card in chat, then re-runs the turn once you install it.
For the exact GitHub App permissions (Contents read/write, Pull requests read/write, Metadata read) and the token model, see GitHub access.