Skip to content

[Payment due @linhvovan29546] Prevent removing or demoting RuleBot while Agent rules exist - #96981

Merged
yuwenmemon merged 13 commits into
mainfrom
claude-flagRuleBotNotEnforced
Jul 28, 2026
Merged

yuwenmemon merged 13 commits into
mainfrom
claude-flagRuleBotNotEnforced

Conversation

@MelvinBot

@MelvinBot MelvinBot commented Jul 24, 2026 •

Copy link
Copy Markdown
Contributor

Explanation of Change

When a workspace has Agent rules, they are enforced by a RuleBot agent that is added as a workspace admin. If that RuleBot is removed from the workspace (or its account is closed, the agent is deleted, or it's demoted to a role that can't act on other members' reports), the rules silently stop being enforced.

Instead of flagging that broken state after the fact, this PR prevents it from happening:

  • Members list (bulk remove) and member details page: attempting to remove the RuleBot while the workspace still has Agent rules shows a blocking "Unable to remove" modal — "The [agent rules] being enforced by RuleBot need to be removed from your workspace first before you can remove this agent." — with "agent rules" linking to the workspace Rules page. The only action is "Got it".
  • Role changes (member details role page and Members list bulk "Make member"/"Make auditor"): attempting to change the RuleBot's role to anything other than Admin while the workspace still has Agent rules shows a blocking "Unable to change role" modal with the same rules link. Promoting the RuleBot to Admin remains allowed.
  • Agent deletion (Account → Agents edit page "Delete agent", Agents list bulk delete, and Settings → Security → "Close account" while copiloting into the agent): attempting to delete an agent that is the RuleBot of any workspace that still has Agent rules shows a blocking "Unable to delete agent" modal.
  • Close account: if the signed-in account (e.g. via copilot access into the RuleBot account) is the RuleBot for any workspace that still has Agent rules, submitting the Close Account form shows a blocking "Unable to close account" modal instead of closing the account.
  • Added hasAgentRules / isRuleBotEnforcingRules / isRuleBotEnforcingRulesOnAnyPolicy helpers to AgentRulesUtils. Rules pending delete don't count, so removal is allowed once the last rule is deleted (even while the delete is still optimistic).

Once all Agent rules are deleted from the workspace, RuleBot can be removed, demoted, or deleted normally.

Fixed Issues

$ https://github.com/Expensify/Expensify/issues/663163
PROPOSAL: https://github.com/Expensify/Expensify/issues/663163#issuecomment-5060447097

Tests

  1. On a Control workspace, go to Rules → Agent rules and add an Agent rule. Confirm RuleBot is added as a workspace admin.
  2. Go to Members, open RuleBot's member details page, and press Remove from workspace. Verify the "Unable to remove" modal appears with the message "The agent rules being enforced by RuleBot need to be removed from your workspace first before you can remove this agent.", that "agent rules" links to the workspace Rules page, and that the only button is "Got it". Verify RuleBot is not removed.
  3. Back on the Members list, select RuleBot (alone or together with other members) and choose Remove members from the bulk actions dropdown. Verify the same "Unable to remove" modal appears and no member is removed.
  4. On RuleBot's member details page, press the Role row and select Member (or Auditor). Verify the "Unable to change role" modal appears with the message "The agent rules being enforced by RuleBot need to be removed from your workspace first before you can change this agent's role.", that "agent rules" links to the workspace Rules page, and that RuleBot's role is unchanged.
  5. Back on the Members list, select RuleBot and choose Make member (or Make auditor) from the bulk actions dropdown. Verify the same "Unable to change role" modal appears and no role is changed.
  6. Go to Account → Agents, open the RuleBot agent's edit page, and press Delete agent. Verify the "Unable to delete agent" modal appears with the message "The agent rules being enforced by RuleBot need to be removed from your workspace first before you can delete this agent." and the agent is not deleted.
  7. Back on the Agents list, select the RuleBot agent (alone or together with other agents) and choose Delete agent from the bulk actions dropdown. Verify the same "Unable to delete agent" modal appears and no agent is deleted.
  8. From the RuleBot agent's edit page, press Copilot into account to switch into the agent. Go to Settings → Security and press Close account. Verify the "Unable to delete agent" modal appears instead of the delete confirmation.
  9. Still copiloting into the agent, deep-link to settings/security/closeAccount, fill in the form, and submit. Verify the "Unable to close account" modal appears and the account is not closed.
  10. Switch back to your own account, delete all Agent rules from the workspace, then repeat steps 2–7. Verify the normal confirmation modals appear and RuleBot can be removed, demoted, and deleted.
  • Verify that no errors appear in the JS console

Offline tests

Same as Tests — the guard is derived from Onyx policy data, so the blocking modals appear identically while offline.

QA Steps

Same as tests

  • Verify that no errors appear in the JS console

PR Author Checklist

  • I linked the correct issue in the ### Fixed Issues section above
  • I wrote clear testing steps that cover the changes made in this PR
    • I added steps for local testing in the Tests section
    • I added steps for the expected offline behavior in the Offline steps section
    • I added steps for Staging and/or Production testing in the QA steps section
    • I added steps to cover failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
    • I tested this PR with a High Traffic account against the staging or production API to ensure there are no regressions (e.g. long loading states that impact usability).
  • I included screenshots or videos for tests on all platforms
  • I ran the tests on all platforms & verified they passed on:
    • Android: Native
    • Android: mWeb Chrome
    • iOS: Native
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
  • I verified there are no console errors (if there's a console error not related to the PR, report it or open an issue for it to be fixed)
  • I followed proper code patterns (see Reviewing the code)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I followed the guidelines as stated in the Review Guidelines
  • I tested other components that can be impacted by my changes (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar are working as expected)
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))
  • If new assets were added or existing ones were modified, I verified that:
    • The assets are optimized and compressed (for SVG files, run npm run compress-svg)
    • The assets load correctly across all supported platforms.
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • I added unit tests for any new feature or bug fix in this PR to help automatically prevent regressions in this user flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.
  • I verified that similar component doesn't exist in the codebase
  • I verified that all props are defined accurately and each prop has a /** comment above it */
  • I verified that each file is named correctly
  • I verified that each component has a clear name that is non-ambiguous and the purpose of the component can be inferred from the name alone
  • I verified that the only data being stored in component state is data necessary for rendering and nothing else
  • In component if we are not using the full Onyx data that we loaded, I've added the proper selector in order to ensure the component only re-renders when the data it is using changes
  • For Class Components, any internal methods passed to components event handlers are bound to this properly so there are no scoping issues (i.e. for onClick={this.submit} the method this.submit should be bound to this in the constructor)
  • I verified that component internal methods bound to this are necessary to be bound (i.e. avoid this.submit = this.submit.bind(this); if this.submit is never passed to a component event handler like onClick)
  • I verified that all JSX used for rendering exists in the render method
  • I verified that each component has the minimum amount of code necessary for its purpose, and it is broken down into smaller components in order to separate concerns and functions

Screenshots/Videos

MacOS: Chrome / Safari rulebot-guard-1-member-details-remove rulebot-guard-2-bulk-remove rulebot-guard-3-bulk-role-change rulebot-guard-4-role-page rulebot-guard-5-edit-agent-delete rulebot-guard-6-agents-bulk-delete rulebot-guard-7-copilot-close-account rulebot-guard-8-close-account-form

@MelvinBot
MelvinBot requested a review from a team July 24, 2026 15:33
@OSBotify

This comment has been minimized.

@MelvinBot

Copy link
Copy Markdown
Contributor Author

Fixed the failing typecheck check and pushed to this branch.

Root cause: The new workspace.rules.agentRules.notEnforced copy string was added to en.ts and es.ts only. Every src/languages/*.ts file must define the same keys, so tsc failed with TS2741: Property 'notEnforced' is missing in the other 8 locales (de, fr, it, ja, nl, pl, pt-BR, zh-hans).

Fix: Added a localized notEnforced string to all 8 remaining locale files, placed right after enforcedBy (matching the en/es structure).

Verified locally: npm run typecheck-tsgo passes with no errors, and npm run fmt produced no further changes.

Notes
  • The checklist (PR Author Checklist) failure is the human-completed checklist, not a code check — it's expected to remain red until the co-author checks the boxes.
  • The remaining test/perf jobs were still running when I pushed; the new commit re-triggers them.

@MelvinBot

Copy link
Copy Markdown
Contributor Author

⚠️ Claude's API is currently overloaded (HTTP 529). This is a temporary issue on Anthropic's side. Try again in a few minutes, or check status.anthropic.com.

Run details

@MelvinBot

Copy link
Copy Markdown
Contributor Author

✅ typecheck now passes — the fix I pushed (a6741e1) resolved it.

What was wrong: The new workspace.rules.agentRules.notEnforced copy string existed only in en.ts/es.ts, but every src/languages/*.ts must define the same keys — so tsc failed with TS2741: Property 'notEnforced' is missing in the other 8 locales (de, fr, it, ja, nl, pl, pt-BR, zh-hans).

Fix: Added a localized notEnforced string to all 8 remaining locale files.

ESLint, Storybook, and the builds are also green. The remaining test/perf jobs are still running; since the change only adds translation keys it won't affect them. The only remaining red check is checklist (the human PR Author Checklist), which is expected to stay red until the boxes are checked.

@NicolasBonet
NicolasBonet marked this pull request as ready for review July 24, 2026 16:46
@NicolasBonet
NicolasBonet requested a review from a team as a code owner July 24, 2026 16:46
@melvin-bot
melvin-bot Bot requested review from joekaufmanexpensify and linhvovan29546 and removed request for a team July 24, 2026 16:46
@melvin-bot

melvin-bot Bot commented Jul 24, 2026

Copy link
Copy Markdown

@linhvovan29546 Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button]

@melvin-bot
melvin-bot Bot removed the request for review from a team July 24, 2026 16:46
@NicolasBonet NicolasBonet changed the title Flag Agent rules when no RuleBot is enforcing them [Hold Auth#23205] Flag Agent rules when no RuleBot is enforcing them Jul 24, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a6741e16d4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/components/AgentRules/useAgentRulesSectionHeader.tsx Outdated
@MelvinBot

Copy link
Copy Markdown
Contributor Author

All code checks are now green after my earlier push (a6741e1) — typecheck, all 8 test jobs, and the perf-test suite pass.

The one remaining red check is PR Reviewer Checklist / checklist, which is the human-completed reviewer checklist (it stays red until a reviewer checks the boxes). That's not a code failure and isn't something I resolve by pushing — nothing further for me to fix here.

Recap of the fix

The real failure was typecheck: the new workspace.rules.agentRules.notEnforced copy was only in en/es, but every src/languages/*.ts must define the same keys. I added a localized notEnforced string to the other 8 locales (de, fr, it, ja, nl, pl, pt-BR, zh-hans), which cleared the TS2741 errors.

@NicolasBonet
NicolasBonet requested a review from a team as a code owner July 24, 2026 17:07
@melvin-bot
melvin-bot Bot requested a review from ikevin127 July 24, 2026 17:07
@melvin-bot

melvin-bot Bot commented Jul 24, 2026

Copy link
Copy Markdown

@ikevin127 Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button]

@melvin-bot
melvin-bot Bot removed the request for review from a team July 24, 2026 17:07
@NicolasBonet NicolasBonet changed the title [Hold Auth#23205] Flag Agent rules when no RuleBot is enforcing them [Hold Auth#23205] Prevent removing RuleBot while Agent rules exist Jul 24, 2026
@OSBotify

This comment has been minimized.

@codecov

codecov Bot commented Jul 24, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Looks like you've decreased code coverage for some files. Please write tests to increase, or at least maintain, the existing level of code coverage. See our documentation here for how to interpret this table.

Files with missing lines Coverage Δ
src/hooks/useRuleBotGuardModal.tsx 100.00% <100.00%> (ø)
src/libs/AgentRulesUtils.ts 95.83% <100.00%> (+2.97%) ⬆️
src/pages/workspace/WorkspaceMembersPage.tsx 62.24% <100.00%> (+1.21%) ⬆️
...s/workspace/members/WorkspaceMemberDetailsPage.tsx 70.39% <100.00%> (+0.59%) ⬆️
src/pages/settings/Agents/AgentsPage.tsx 77.41% <25.00%> (-2.36%) ⬇️
src/pages/settings/Agents/EditAgentPage.tsx 91.30% <25.00%> (-4.09%) ⬇️
...rkspace/members/WorkspaceMemberDetailsRolePage.tsx 0.00% <0.00%> (ø)
...c/pages/settings/Security/SecuritySettingsPage.tsx 0.00% <0.00%> (ø)
src/pages/settings/Security/CloseAccountPage.tsx 0.00% <0.00%> (ø)
... and 21 files with indirect coverage changes

@MelvinBot

Copy link
Copy Markdown
Contributor Author

Fixed the failing Compare knip issues against main check and pushed to this branch (0e6d520).

Root cause: src/libs/AgentRulesUtils.ts exported hasAgentRules, but nothing imports it — it's only used internally by isRuleBotEnforcingRules in the same file. Knip flagged it as a new unused export (delta +1 vs main).

Fix: Removed hasAgentRules from the export list; it stays defined and used internally.

Verified locally: ESLint passes on the file, and the internal call in isRuleBotEnforcingRules is unchanged.

Notes
  • The earlier typecheck failure (missing notEnforced locale key) is no longer relevant — the branch was reworked and that copy string is no longer part of the PR.
  • Remaining test/perf/build jobs are still running; this push re-triggers them.

MelvinBot and others added 4 commits July 24, 2026 13:16
When a workspace has Agent rules but no live RuleBot assigned (none
assigned, the agent was deleted, or it was removed from the workspace
member list), the rules are silently not enforced. Surface this in the
Agent rules section header with a red warning so admins know.

Adds a hasRules input to useAgentRulesSectionHeader and renders the
warning when rules exist but ruleBotAccountID is missing or the assigned
bot is no longer an active policy member.

Co-authored-by: Nicolás Bonet <NicolasBonet@users.noreply.github.com>
Co-authored-by: Nicolás Bonet <NicolasBonet@users.noreply.github.com>
The server assigns a RuleBot when it processes a rule creation, so the
optimistic add briefly shows the warning until the response arrives.
Only count server-confirmed rules when deciding enforcement is missing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replaces the not-enforced warning approach: instead of flagging rules
without an enforcer after the fact, prevent RuleBot from being removed
(member details page and bulk members removal) and its account from
being closed while agent rules still exist on the workspace.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@NicolasBonet
NicolasBonet force-pushed the claude-flagRuleBotNotEnforced branch from 0e6d520 to 89bdcec Compare July 24, 2026 18:16
Co-authored-by: Nicolás Bonet <NicolasBonet@users.noreply.github.com>
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@NicolasBonet

Copy link
Copy Markdown
Contributor

Bug: When I close an account as an agent, we show a blocking modal, but the button keeps showing a loading state.

Fixed!

…Enforced

# Conflicts:
#	src/pages/workspace/WorkspaceMembersPage.tsx
#	src/pages/workspace/members/WorkspaceMemberDetailsPage.tsx
@MelvinBot

Copy link
Copy Markdown
Contributor Author

The only failing check is PR Author Checklist / checklist — there's no code or test failure to push a fix for. Every other check is passing or still running (the two Remote Build iOS jobs are in progress, not failed).

Why it's failing: the authorChecklist action dynamically added 10 component-review items to the checklist (because this PR touches components) and they're currently unchecked, so it fails with:

Error: New checks were added into checklist. Please check every box to verify you've thought about the item.
You completed 38 out of 38 checklist items with 10 unfinished items

How to clear it: check off the 10 remaining boxes at the bottom of the PR description (the "I verified that similar component doesn't exist…", props//** comment */, file naming, component naming, component state, Onyx selector, this binding, JSX-in-render, and minimum-code items) once you've confirmed each. The check re-runs on the next push/edit and will pass once all boxes are ticked.

This is an author-completion checklist that asserts a human thought about each item, so I'm intentionally not auto-checking the boxes on your behalf.

@MelvinBot

Copy link
Copy Markdown
Contributor Author

Status unchanged since my previous comment: the only failing check is still PR Author Checklist / checklist, which is a human-completion checklist, not a code or test failure — there's nothing for me to push.

All other checks are green or still running with none failing (ESLint, Oxfmt, Bun tests, Storybook, spellcheck, Knip, React Compiler, and the iOS builds have passed; Jest, typecheck, Android builds, and perf tests are still in progress).

To clear the red check, tick the 10 remaining component-review boxes at the bottom of the PR description once you've confirmed each — it re-runs on the next edit/push and will pass. I'm intentionally not auto-checking them, since that checklist asserts a human thought about each item.

@linhvovan29546

linhvovan29546 commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Reviewer Checklist

  • I have verified the author checklist is complete (all boxes are checked off).
  • I verified the correct issue is linked in the ### Fixed Issues section above
  • I verified testing steps are clear and they cover the changes made in this PR
    • I verified the steps for local testing are in the Tests section
    • I verified the steps for Staging and/or Production testing are in the QA steps section
    • I verified the steps cover any possible failure scenarios (i.e. verify an input displays the correct error message if the entered data is not correct)
    • I turned off my network connection and tested it while offline to ensure it matches the expected behavior (i.e. verify the default avatar icon is displayed if app is offline)
  • I checked that screenshots or videos are included for tests on all platforms
  • I included screenshots or videos for tests on all platforms
  • I verified that the composer does not automatically focus or open the keyboard on mobile unless explicitly intended. This includes checking that returning the app from the background does not unexpectedly open the keyboard.
  • I verified tests pass on all platforms & I tested again on:
    • Android: HybridApp
    • Android: mWeb Chrome
    • iOS: HybridApp
    • iOS: mWeb Safari
    • MacOS: Chrome / Safari
  • If there are any errors in the console that are unrelated to this PR, I either fixed them (preferred) or linked to where I reported them in Slack
  • I verified proper code patterns were followed (see Reviewing the code)
    • I verified that comments were added to code that is not self explanatory
    • I verified that any new or modified comments were clear, correct English, and explained "why" the code was doing something instead of only explaining "what" the code was doing.
    • I verified any copy / text that was added to the app is grammatically correct in English. It adheres to proper capitalization guidelines (note: only the first word of header/labels should be capitalized), and is either coming verbatim from figma or has been approved by marketing (in order to get marketing approval, ask the Bug Zero team member to add the Waiting for copy label to the issue)
  • If a new code pattern is added I verified it was agreed to be used by multiple Expensify engineers
  • I verified that this PR follows the guidelines as stated in the Review Guidelines
  • I verified other components that can be impacted by these changes have been tested, and I retested again (i.e. if the PR modifies a shared library or component like Avatar, I verified the components using Avatar have been tested & I retested again)
  • If a new component is created I verified that:
    • A similar component doesn't exist in the codebase
    • All props are defined accurately
    • The component has a clear name that is non-ambiguous and the purpose of the component can be inferred from the name alone
    • The only data being stored in the state is data necessary for rendering and nothing else
    • The component has the minimum amount of code necessary for its purpose, and it is broken down into smaller components in order to separate concerns and functions
  • If a new CSS style is added I verified that:
    • A similar style doesn't already exist
    • The style can't be created with an existing StyleUtils function (i.e. StyleUtils.getBackgroundAndBorderStyle(theme.componentBG)
  • If the PR modifies code that runs when editing or sending messages, I tested and verified there is no unexpected behavior for all supported markdown - URLs, single line code, code blocks, quotes, headings, bold, strikethrough, and italic.
  • If the PR modifies a generic component, I tested and verified that those changes do not break usages of that component in the rest of the App (i.e. if a shared library or component like Avatar is modified, I verified that Avatar is working as expected in all cases)
  • If the PR modifies a component related to any of the existing Storybook stories, I tested and verified all stories for that component are still working as expected.
  • If the PR modifies a component or page that can be accessed by a direct deeplink, I verified that the code functions as expected when the deeplink is used - from a logged in and logged out account.
  • If the PR modifies the UI (e.g. new buttons, new UI components, changing the padding/spacing/sizing, moving components, etc) or modifies the form input styles:
    • I verified that all the inputs inside a form are aligned with each other.
    • I added Design label and/or tagged @Expensify/design so the design team can review the changes.
  • For any bug fix or new feature in this PR, I verified that sufficient unit tests are included to prevent regressions in this flow.
  • If the main branch was merged into this PR after a review, I tested again and verified the outcome was still expected according to the Test steps.
  • I have checked off every checkbox in the PR reviewer checklist, including those that don't apply to this PR.

Screenshots/Videos

Android: HybridApp
telegram-cloud-document-5-6289458079998160731.mp4
Android: mWeb Chrome
telegram-cloud-document-5-6289458079998160730.mp4
iOS: HybridApp
Screen.Recording.2026-07-28.at.22.04.44.mov
iOS: mWeb Safari
Screen.Recording.2026-07-28.at.21.58.58.mov
MacOS: Chrome / Safari
Screen.Recording.2026-07-28.at.21.55.11.mov

@MelvinBot

Copy link
Copy Markdown
Contributor Author

✅ Fixed — the checklist check is now passing.

The only failing check was PR Author Checklist / checklist; every other check (typecheck, ESLint, Jest, Bun, Storybook, React Compiler, builds, etc.) was already green. It wasn't a code failure — the authorChecklist action dynamically added 10 component-review items to the checklist, and the failing run at 14:52 still saw one unchecked box. All 50 boxes had since been ticked, but no fresh run had been triggered, so the check was stuck on a stale failure.

I re-triggered the checklist workflow against the now-complete description. The new run (30371153759) completed successfully, so the check is cleared. No code changes were needed.

@MelvinBot

Copy link
Copy Markdown
Contributor Author

All checks are now passing ✅ — there's nothing left to fix.

The checklist (PR Author Checklist) that was failing earlier is now green, and every other check (Jest, TypeScript, ESLint, iOS/Android builds, Reassure, Codecov, etc.) is passing. No failing checks remain on this PR.

@linhvovan29546

linhvovan29546 commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Bug: @NicolasBonet If I clear the cache, then open the Agents page, and then delete an agent, the blocking modal doesn't appear. In the recording below, the policy is missing the ruleBotAccountID field, which seems to be the reason the modal isn't shown.

Maybe the backend should include the ruleBotAccountID field in the OpenApp response? If so, I think this can be marked as NAB and addressed later, so it doesn't block the PR.

Screen.Recording.2026-07-28.at.22.08.58.mov

@NicolasBonet

Copy link
Copy Markdown
Contributor

That is a NAB indeed, let's approve without that @linhvovan29546 , I will add it to the backend in a follow up

@melvin-bot melvin-bot Bot changed the title Prevent removing or demoting RuleBot while Agent rules exist [Payment due @linhvovan29546] Prevent removing or demoting RuleBot while Agent rules exist Jul 28, 2026
@melvin-bot

melvin-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

🎯 @linhvovan29546, thanks for reviewing and testing this PR! 🎉

A payment issue will be created for your review once this PR is deployed to production.
E/E issue linked to the PR - https://www.github.com/Expensify/Expensify/issues/663163.

If payment is not needed (e.g., regression PR review fix etc), react with 👎 to this comment to prevent the payment issue from being created.

@yuwenmemon
yuwenmemon merged commit 83e3577 into main Jul 28, 2026
46 of 55 checks passed
@yuwenmemon
yuwenmemon deleted the claude-flagRuleBotNotEnforced branch July 28, 2026 20:04
@OSBotify

Copy link
Copy Markdown
Contributor

✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release.

@github-actions

Copy link
Copy Markdown
Contributor

🚧 yuwenmemon has triggered a test Expensify/App build. You can view the workflow run here.

@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to staging by https://github.com/yuwenmemon in version: 9.4.46-0 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

@MelvinBot

Copy link
Copy Markdown
Contributor Author

📝 Help site changes required — draft PR created.

This PR introduces new user-facing behavior: RuleBot can't be removed, demoted, or deleted while a workspace still has Agent rules, and closing the RuleBot account is blocked in that state. The RuleBot help article previously only said RuleBot is "managed by Expensify" and didn't explain this guard or how to resolve it, so it needed an update.

Draft PR: #97390

What it changes — docs/articles/new-expensify/ai-agents/Create-Agent-Rules.md:

  • New How to remove RuleBot from a workspace section listing the blocked actions (Remove from workspace, changing role to Member/Auditor, Delete agent, closing the account) and the steps to remove RuleBot after deleting all Agent rules.
  • New FAQ entry: Why can't I remove RuleBot from the workspace?

I reviewed and applied HELPSITE_NAMING_CONVENTIONS.md, HELP_AUTHORING_GUIDELINES.md, and TEMPLATE.md, and verified UI labels (Remove from workspace, Make member, Make auditor, Delete agent, Close account) against the App source. The draft is labeled HelpDot and assigned to NicolasBonet.

@NicolasBonet, please review the linked help site PR and confirm it reflects the current behavior. Then mark the linked help site PR Ready for review

@OSBotify

Copy link
Copy Markdown
Contributor

🚀 Deployed to production by https://github.com/marcaaron in version: 9.4.46-10 🚀

platform result
🕸 web 🕸 success ✅
🤖 android 🤖 success ✅
🍎 iOS 🍎 success ✅

Bundle Size Analysis (Sentry):

@melvin-bot

melvin-bot Bot commented Jul 31, 2026

Copy link
Copy Markdown

🤖 Payment issue created: #97537

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants