How to Write GitHub CODEOWNERS and Branch Protection from a Team Map

CODEOWNERS files rot when someone adds @org/everyone and a deploy check that does not exist. GitHub will enforce fiction. The team map you pasted is the only owner list.
The matching generator is the GitHub CODEOWNERS and Branch-Protection from a Team Map prompt. Browse related cards in the PromptDig library (Browse more prompts). When a filled run survives, share the version you actually use (Share a prompt).
Print every team slug before the file
Turn a team map into CODEOWNERS and branch-protection JSON for GitHub. No invented teams, user logins, or required checks. Start by filling Inputs, not by asking the model to remember last week's run. If a field is blank, write NONE or NOT IN INPUTS and leave it blank through Generate. The card is built so the model cannot honestly invent a number, owner, URL, or command that you did not paste.
Paste these fields before you hit run:
Org and default repo: [OrgRepo]
Default branch name: [Branch]
Team map (path glob -> GitHub team slug or user): [Map]
Fallback owners if a path has no team: [Fallback or NONE]
Required status checks I can prove exist: [Checks or NONE]
Review count and dismiss-stale setting I want: [Reviews]
Admin enforcement and linear history flags: [Flags]
Paths that must not have owners (generated, vendor): [Exclude]
GitHub plan feature I may use (classic protection vs rulesets): [Mode]
Words I must not use: [Banned]
That inventory is the honesty ledger. Anything that does not appear there is forbidden in the draft. If you catch yourself adding a nice-to-have after the run, you are no longer using the card. You are ghostwriting. Put the extra fact in Inputs and run again.
Leave unmatched paths unowned if fallback is NONE
Generate is numbered on purpose. Do not skip a step because the first paragraph looked done. The early steps exist to stop later prose from smuggling claims.
Walk the Generate list in order:
- Honesty ledger: org, repo, branch, every team slug and login in Map, every check in Checks. Forbidden: teams and checks not listed.
- CODEOWNERS file: header comment naming OrgRepo and Branch. One rule per Map row. Exclude paths as unowned comments, not fake teams.
- Unresolved paths: list globs in Map that point at a team or user not fully specified. Do not invent @org/unknown.
- Branch protection or ruleset JSON sketch for Mode. Required reviews from Reviews. Required checks only from Checks. If Checks is NONE, omit the checks array rather than inventing CI.
- Bypass list: only if Flags or Map names bypass actors. Else none.
- Apply notes: gh or REST endpoints you would call, no invented tokens.
- Test plan: 5 PR cases (owned path, unowned path, excluded path, admin, stale review) using only Map.
- Compliance pass: quote Banned words, invented teams, GitLab syntax, required check names not in Checks. Cut them.
If a step asks for a version lock, quote the version from Inputs in the output. If a step asks for a refuse list, keep the refuse list in the published artifact, not in a sidebar you delete. Reviewers should see what the model was not allowed to do.
Required checks only from the checks you named
Most failures are the same shape: a missing field gets a confident fill. A conversion rate appears. A Gradle task appears. A flash point appears. A caption appears on a job that asked for slide text only. Your review is to search the draft for numbers, names, and commands, then grep Inputs. No match means cut.
Honor the constraints as hard stops, not vibes:
- GitHub CODEOWNERS. Do not emit GitLab sections or Bitbucket ownership files.
- Never invent a team slug, user login, or required check.
- If Mode is classic protection, do not use ruleset-only fields. If Mode is rulesets, do not mix classic-only fields.
- Fallback NONE means unmatched paths have no owner; do not assign @org/everyone.
- No emojis.
When the card says not legal advice, not certification, not an exam dump, or not a caption engine, that sentence belongs at the top of the output. Deleting it to look more finished is how you inherit risk.
Pick classic protection or rulesets, not both
Finish with the compliance pass the prompt already asks for. Quote the banned-word hits. Cut them. Print character counts when the job has a cap. Print word counts when the job has a budget. List gaps as gaps. Five missing facts are more useful than one smooth paragraph.
Tags on the card (github codeowners file, branch protection from team map, github rulesets) are a reminder of the job shape, not an invitation to wander into a neighboring cluster. If you need a different surface, open a different PromptDig card rather than stretching this one.
Fill the card, then run
Replace every bracket. Run on ChatGPT, Claude, or Gemini. Read the ledger first, then the artifact. If the model invents a commit, KPI, DOI, PEL, bid, or logo, discard the run. Tighten Inputs. Run again. Share the filled card that survived, not the first draft that sounded done.