# CODEOWNERS — domain review encoded in rails, not org charts.
#
# Path-shaped risks belong here: when a PR touches one of these paths, GitHub
# automatically requests review from the owner listed. Behavior-shaped risks
# (deleting data, bulk updates) can't be caught by file paths — the risk
# checklist in the PR template covers those instead.
#
# This file has no teeth until branch protection requires review from Code
# Owners; okrdev's Level 2 install ships a script that turns that on. Honest
# note on plans: enforcing CODEOWNERS via branch protection on a private repo
# requires a paid GitHub plan. Public repos get it free.
#
# Replace the placeholder handles with real people. The last matching pattern
# wins, so put broader patterns first.

# Database migrations — schema changes are the hardest thing to undo.
/drizzle/migrations/   @your-db-reviewer

# Auth and permissions configuration — mistakes lock the right people out or
# let the wrong people in.
/src/auth/             @your-security-reviewer
/middleware.ts         @your-security-reviewer

# Payment code — money moves.
/src/payments/         @your-payments-reviewer
/src/billing/          @your-payments-reviewer

# Deliberately NO owner for okrdev/**: captures are okrdev:parked issues (no
# commits at all), and the weekly okrdev state PRs (triage ledgers, check-in
# files) merge immediately. A Code Owners match here would make them wait on
# review for nothing.
