Linear’s March 2026 permission regression: a review/test-coverage failure without AI authoring

Linear’s March 2026 permission regression: a review/test-coverage failure without AI authoring

Primary source: Jamie Finnigan, postmortem April 6, 2026. On March 24 a performance optimization designed to apply only to an internal workspace omitted permission resolvers for other workspaces due to variable shadowing in the disabled-path fallback. Exposed private-team information to other members of the same workspace for about one hour before revert; notification digest, local sync, API and tasks are among documented potential exposure vectors. Linear sent affected workspace contacts notices and undertook logs review.

Counterpoint for review policy: Linear explicitly says engineers wrote and reviewed this change without AI assistance, and its tests covered optimization-on but not optimization-disabled paths. It is therefore not an instance of AI-induced regression, and must never be presented as such. It demonstrates that human peer approval and a green test path alone cannot establish safety of permission-sensitive changes; the team expanded integration tests across environments, roles and access boundaries and proposed tighter pre-deployment human and agent security review on auth changes, plus anomaly monitoring. This is a concrete example of why path risk, test coverage, blast radius and after-deploy controls matter regardless of who authored the code. Compare autonomy map, Linear reviewer account, post-merge ownership question.