GitHub Permissions control what users and teams can do with repositories and other GitHub resources. Permissions help repository owners and organizations manage access according to each person's responsibilities.
GitHub permissions determine what a user or team is allowed to do with a repository.
User
↓
Role / Permission
↓
Allowed Actions
↓
Repository
Permissions help protect repositories while allowing authorized users to perform their required work.
| Authentication | Authorization |
|---|---|
| Verifies who the user is | Determines what the user can do |
| Login and identity | Permissions and access |
| Example: GitHub account sign-in | Example: Permission to push code |
Repository access determines what a user can do with a specific repository.
Repository
↓
User / Team
↓
Access Level
↓
Allowed Actions
Access should be provided according to the person's project role.
GitHub supports repository roles that provide different levels of access. In organization repositories, common roles include:
Each role provides a different collection of permissions.
Read access is intended for users who need to view and inspect a repository without needing write access.
Read access is useful when someone needs to understand or monitor a project without modifying its contents.
Triage access provides permissions useful for managing and organizing issues and pull requests without providing the full write access of a developer role.
It can be useful for people who help manage project work, issues, and pull requests.
Write access allows users to perform development activities that require writing to the repository.
Developer
↓
Modify Code
↓
Commit
↓
Push
↓
Repository
Write access is commonly appropriate for developers who actively contribute code.
Maintain access is designed for users who manage many aspects of a repository without having the full administrative control provided by the Admin role.
It can be useful for project maintainers who need to manage repository work without managing all repository security settings.
Admin access provides the highest level of repository management among the standard repository roles.
Administrative users may manage repository settings, access, and other administrative features according to the repository configuration.
| Role | General Purpose |
|---|---|
| Read | View and inspect repository |
| Triage | Manage issues and pull requests |
| Write | Contribute code |
| Maintain | Maintain repository operations |
| Admin | Manage repository and administrative settings |
Permissions can be assigned to individual users through repository access management.
Repository
↓
Add Person
↓
Select Access
↓
User Receives Permission
This approach can be useful for smaller projects.
Organizations can use teams to manage repository access for multiple members.
Organization
↓
Team
↓
Repository
↓
Team Permission
↓
Team Members
This makes access management easier when many developers work on multiple repositories.
The least privilege principle means giving a user only the access required to perform their work.
Required Access
↓
Give Necessary Permission
↓
Avoid Unnecessary Access
For example, someone who only needs to review project information may not need administrative access.
Important branches can be protected using repository rules so that certain changes must follow required workflows.
Developer
↓
Pull Request
↓
Required Review
↓
Required Checks
↓
Protected Branch
Branch protection helps control how changes reach important branches.
Different users may have different abilities related to pull requests depending on their repository permissions and rules.
Repository rules may require approvals or successful checks before merging.
Permissions can affect how users interact with GitHub Issues.
Depending on their access, users may be able to:
Repository settings can affect security, access, branches, automation, and other project features.
Administrative permissions are therefore more powerful than normal development permissions.
Normal Developer
↓
Code Development
Administrator
↓
Repository Management
Repository permissions should not be treated as a replacement for proper secret management.
// Do not store secrets in source code
API_KEY = "secret-value"
Instead:
Use secure secret management.
Passwords, API keys, tokens, and other sensitive credentials should not be committed to source code.
Private repositories restrict access to authorized users and teams. A user generally needs appropriate permission before accessing private repository content.
Private Repository
↓
Authorized User / Team
↓
Allowed Access
A public repository can be viewed publicly, but public visibility does not automatically provide everyone with permission to modify the repository.
Public Repository
↓
Public Viewing
↓
Separate Write Permission
Write and administrative actions still depend on authorization.
Collaborators receive access based on the permission level assigned to them.
Collaborator
↓
Assigned Permission
↓
Allowed Actions
↓
Repository
The permission should match the work the collaborator needs to perform.
Repository administrators should review access regularly, especially when team members change responsibilities or leave a project.
Project Owner
↓
Define Team Responsibilities
↓
Assign Appropriate Access
↓
Developers Work on Branches
↓
Pull Requests
↓
Code Review
↓
Required Checks
↓
Merge
Permissions work together with the development workflow to control how changes are made.
| Team Member | Possible Access |
|---|---|
| Project Viewer | Read |
| Issue Manager | Triage |
| Developer | Write |
| Project Maintainer | Maintain |
| Repository Administrator | Admin |
This is an example of how different responsibilities can be matched with different repository roles.
Developer
↓
Write Permission
↓
Create Feature Branch
↓
Push Changes
↓
Pull Request
↓
Reviewer
↓
Review
↓
Required Approval
↓
Merge
Repository rules can define which reviews or checks are required before changes are merged.
GitHub permissions control what users and teams can do with repositories. Understanding access levels helps teams organize development while protecting project resources.
User / Team
↓
Permission
↓
Repository Access
↓
Allowed Actions
↓
Secure Collaboration
Common repository roles include Read, Triage, Write, Maintain, and Admin. The appropriate role depends on the responsibilities of the user or team.
Question: What do GitHub permissions control?