Skip to main content
Vexa uses one conscious rights choice at pull-request intake and automates the remaining mechanics. The canonical policy and operational commands live in CONTRIBUTOR_RIGHTS.md. Technical review may continue during rights review. A later push invalidates a corporate verification, and only a designated verifier can bind a private receipt to the new head. Executed agreements, signatures, addresses, and employment information never belong in public PR comments.

Agent-assisted flow

Agents automate Git, not legal judgment. They ask the human to choose the path, check the repository-local Git identity, use --signoff after authorization, identify failing commits by SHA, and prepare safe remediation. They never select the declaration, sign for another person, or rewrite/push history without explicit approval. For the latest unsigned commit:
Shared branches use the DCO App’s individual remediation flow rather than third-party sign-off.

Historical work

The gate is prospective. Earlier contributions are triaged by concrete risk instead of rewritten or subjected to a blanket CLA campaign. Significant ambiguous work may receive a retrospective attestation; corporate-directed work receives a contribution-specific corporate authorization; material work that cannot be cleared is replaced or removed.