How-To: Verify Commit Signatures and Enforce Dual-Custody Review
This guide covers configuring cryptographic commit signature verification (GPG/SSH) and conducting mandatory human dual-custody review sign-offs before autonomous tasks can be completed and merged.
Configuring Compliance Settings
To mandate cryptographic commit signatures and dual custody, configure [security.compliance] in spec-ops.toml:
[security.compliance]
require_signed_commits = true
dual_custody = true
allowed_signers_file = ".ssh/allowed_signers"
authorized_signers = [
"Riley Reviewer <riley@example.com>",
"Jordan Architect <jordan@example.com>",
]
When require_signed_commits = true:
- Every git commit on feature branches must be signed with a valid GPG or SSH key (
%G?inGorU). - Any unsigned commit causes
spec-ops queue completeor worker merge to abort with returncode 1:
```text
Compliance Violation: Commit
```
Signing Off on Autonomous Agent Tasks
When dual custody is enabled, autonomous agent tasks require an authorized human review before completion.
To verify reviewer identity and record sign-off:
spec-ops review sign TASK-0030 --identity "Riley Reviewer <riley@example.com>"
The command:
- Validates the identity format (RFC 2822 or GPG/SSH key ID).
- Verifies the identity against authorized signers in
spec-ops.tomlor the SSHallowed_signerskeyring. - Updates task frontmatter with
signed_off_byand UTC ISO-8601 timestamp:
```yaml
signed_off_by: Riley Reviewer
signed_off_at: '2026-09-29T17:00:00+00:00'
```
Gating Backlog Integration Under Dual Control
Once signed off, complete the task:
spec-ops queue complete TASK-0030
When integrating to the base branch:
- Verified commit signatures are validated.
- Dual-custody review metadata is checked.
- Structured git trailers
SpecOps-Task: TASK-0030andSpecOps-Signed-By:are injected into the squash commit.