Configure the bot
Scopes, comment behavior, review language, and merge gating.
Open Automations and use Review behavior to configure how the bot reports. These settings apply to the workspace default scopes.
Scopes
Assign the certification scopes each repository is checked against, as a workspace default or a per-repository override. To pin scopes in the repository itself, add a .specmcp.yml file on the base branch:
scopes:
- gemAnbT_TIM
- tim-client-ptvThe base-branch configuration takes precedence over the dashboard, and a proposed change to .specmcp.yml only takes effect after it is merged.
Comments
- Only when findings exist posts a comment only when the bot has something to report.
- Always posts a comment on every pull request, including a clean result.
Report language
Choose the language findings are written in, or leave it automatic.
Merge gating
By default the check is advisory: a review outcome is reported as neutral and never blocks a merge. Switch to Block until reviewed to report a review outcome as a failing check. To actually prevent merging, add SpecMCP / Regulatory Impact as a required status check in your branch protection rules. An incomplete analysis never blocks a merge, so a missing scope or a transient error cannot hold up a release.