How to connect a Git repository and get pull requests
Give the AI colleagues somewhere to write code: a repository, a branch naming rule derived from the work item, and pull requests you review and merge yourself.
Everything except the code work runs without a repository. Connect one and the dev agent gets a working directory, a branch and a way to hand its work back: a pull request with the work item on it. What it does not get — not with any combination of roles — is the ability to merge that pull request.
Connecting one
Add the repository
Under repositories, point Turnado at the repository and the default branch. Reading a public repository works without a token; a private one needs one, and the error message says exactly which scope is missing rather than failing vaguely.
Check what the read side shows
The screen Code and reviews lists branches, folders, files and commits straight from the host. If that is empty or refuses, fix it here — an agent will hit the same wall a minute later and it is easier to debug on a screen than in a run log.
Let an agent pick up a story
The branch name is derived from the work item, so a branch is traceable back to its ticket without a naming convention anybody has to remember.
Review the pull request
The gate facts — CI green, pull request open, review approved — are derived from the pull request itself. Not from what the agent claims about it.
Where an agent may write
Each run gets its own working directory with a hard path boundary: an agent cannot read or write outside it, however a path is spelled or encoded. That check is a plain function with its own test rather than a feature of the sandbox it happens to run in.
Who does not write code
The reviewing agent is a different actor from the developing agent, and the status machine enforces the split: whoever wrote the code cannot be the one whose review opens the review gate. If you run one AI colleague for both jobs you have a rubber stamp, which is why the default team has an AI-Dev and an AI-Review as separate colleagues.

Which Git hosts are supported?
GitHub today, for both the read side (branches, files, commits) and the write side (create a branch, open a pull request). The delivery configuration is separately pluggable, so your pipeline can live somewhere else entirely — see Set up delivery.
Do I need a token to read a public repository?
No. Reading a public repository works without one. A private repository needs a token, and if it is missing the message tells you which permission is required instead of returning an empty list.
Can I keep using my existing branch conventions?
The branch an agent creates is derived from the work item so that the link back to the ticket always exists. Your own branches are untouched — Turnado reads the repository, it does not take it over.