Reviews are advisory today. Per-branch settings: require N approvals (fresh, not stale) before mr merge; optionally require checks from #1. CODEOWNERS-style path-based reviewer routing as a second step. Enforced server-side in the merge command, same place the signed-commit policy lives.
merge requirements: required approvals and CODEOWNERS #19
Discussion
Shipped: require-approvals (fresh/non-author, latest-review stance, request-changes blocks), CODEOWNERS from the target branch with a tested last-match-wins matcher, and require-resolved for open threads. All enforced server-side in the merge path alongside the checks and signature gates.