That's not SOC 2 compliant
Summary
The article discusses a SOC 2 compliance approach that does not require pull requests. It argues that compliance is about thinking through risks and implementing auditable controls (restricted push access, signed commits, automated CI, and an audit trail) rather than enforcing a PR-centric workflow. It also shares Amp's perspective on scaling a lightweight, risk-based change process while maintaining audit readiness.