Lesson 45 of 60 – GitHub Permissions
75%

GitHub Permissions

GitHub Permissions control what users and teams can do with repositories and other GitHub resources. Permissions help repository owners and organizations manage access according to each person's responsibilities.

Note: Permissions define which actions a user can perform. The available roles and exact permissions can vary depending on whether the repository belongs to a personal account or an organization.

1. What Are GitHub Permissions?

GitHub permissions determine what a user or team is allowed to do with a repository.

User
  ↓
Role / Permission
  ↓
Allowed Actions
  ↓
Repository

2. Why Are Permissions Important?

Permissions help protect repositories while allowing authorized users to perform their required work.

  • Control repository access
  • Protect source code
  • Manage team responsibilities
  • Protect important branches
  • Limit administrative actions
  • Improve project security

3. Authentication vs Authorization

Authentication Authorization
Verifies who the user is Determines what the user can do
Login and identity Permissions and access
Example: GitHub account sign-in Example: Permission to push code

4. Repository Access

Repository access determines what a user can do with a specific repository.

Repository
    ↓
User / Team
    ↓
Access Level
    ↓
Allowed Actions

Access should be provided according to the person's project role.

5. GitHub Repository Roles

GitHub supports repository roles that provide different levels of access. In organization repositories, common roles include:

  • Read
  • Triage
  • Write
  • Maintain
  • Admin

Each role provides a different collection of permissions.

6. Read Permission

Read access is intended for users who need to view and inspect a repository without needing write access.

  • View repository content
  • Read issues
  • Read pull requests
  • Inspect project information

Read access is useful when someone needs to understand or monitor a project without modifying its contents.

7. Triage Permission

Triage access provides permissions useful for managing and organizing issues and pull requests without providing the full write access of a developer role.

It can be useful for people who help manage project work, issues, and pull requests.

8. Write Permission

Write access allows users to perform development activities that require writing to the repository.

Developer
    ↓
Modify Code
    ↓
Commit
    ↓
Push
    ↓
Repository

Write access is commonly appropriate for developers who actively contribute code.

9. Maintain Permission

Maintain access is designed for users who manage many aspects of a repository without having the full administrative control provided by the Admin role.

It can be useful for project maintainers who need to manage repository work without managing all repository security settings.

10. Admin Permission

Admin access provides the highest level of repository management among the standard repository roles.

Administrative users may manage repository settings, access, and other administrative features according to the repository configuration.

Important: Administrative access should be limited to people who actually need it.

11. Permission Levels Example

Role General Purpose
Read View and inspect repository
Triage Manage issues and pull requests
Write Contribute code
Maintain Maintain repository operations
Admin Manage repository and administrative settings

12. Individual Permissions

Permissions can be assigned to individual users through repository access management.

Repository
    ↓
Add Person
    ↓
Select Access
    ↓
User Receives Permission

This approach can be useful for smaller projects.

13. Team Permissions

Organizations can use teams to manage repository access for multiple members.

Organization
      ↓
Team
      ↓
Repository
      ↓
Team Permission
      ↓
Team Members

This makes access management easier when many developers work on multiple repositories.

14. Least Privilege Principle

The least privilege principle means giving a user only the access required to perform their work.

Required Access
      ↓
Give Necessary Permission
      ↓
Avoid Unnecessary Access

For example, someone who only needs to review project information may not need administrative access.

15. Branch Protection

Important branches can be protected using repository rules so that certain changes must follow required workflows.

Developer
    ↓
Pull Request
    ↓
Required Review
    ↓
Required Checks
    ↓
Protected Branch

Branch protection helps control how changes reach important branches.

16. Pull Request Permissions

Different users may have different abilities related to pull requests depending on their repository permissions and rules.

  • View pull requests
  • Comment
  • Review
  • Create pull requests
  • Merge pull requests when permitted

Repository rules may require approvals or successful checks before merging.

17. Issue Permissions

Permissions can affect how users interact with GitHub Issues.

Depending on their access, users may be able to:

  • View issues
  • Create issues
  • Comment
  • Assign issues
  • Manage issue labels
  • Close or reopen issues

18. Repository Settings Access

Repository settings can affect security, access, branches, automation, and other project features.

Administrative permissions are therefore more powerful than normal development permissions.

Normal Developer
       ↓
Code Development

Administrator
       ↓
Repository Management

19. Permission and Sensitive Data

Repository permissions should not be treated as a replacement for proper secret management.

// Do not store secrets in source code

API_KEY = "secret-value"

Instead:
Use secure secret management.

Passwords, API keys, tokens, and other sensitive credentials should not be committed to source code.

20. Permissions for Private Repositories

Private repositories restrict access to authorized users and teams. A user generally needs appropriate permission before accessing private repository content.

Private Repository
       ↓
Authorized User / Team
       ↓
Allowed Access

21. Permissions for Public Repositories

A public repository can be viewed publicly, but public visibility does not automatically provide everyone with permission to modify the repository.

Public Repository
       ↓
Public Viewing
       ↓
Separate Write Permission

Write and administrative actions still depend on authorization.

22. Collaborator Permissions

Collaborators receive access based on the permission level assigned to them.

Collaborator
      ↓
Assigned Permission
      ↓
Allowed Actions
      ↓
Repository

The permission should match the work the collaborator needs to perform.

23. Reviewing Access Regularly

Repository administrators should review access regularly, especially when team members change responsibilities or leave a project.

  • Check active collaborators.
  • Review team membership.
  • Remove unnecessary access.
  • Check administrative users.
  • Review important repository settings.

24. Common Permission Mistakes

  • Giving everyone administrative access.
  • Giving write access when read access is sufficient.
  • Forgetting to remove former team members.
  • Ignoring branch protection.
  • Sharing account credentials.
  • Committing secrets to repositories.
  • Not reviewing organization team access.

25. Permissions and Team Workflow

Project Owner
      ↓
Define Team Responsibilities
      ↓
Assign Appropriate Access
      ↓
Developers Work on Branches
      ↓
Pull Requests
      ↓
Code Review
      ↓
Required Checks
      ↓
Merge

Permissions work together with the development workflow to control how changes are made.

26. Example Permission Setup

Team Member Possible Access
Project Viewer Read
Issue Manager Triage
Developer Write
Project Maintainer Maintain
Repository Administrator Admin

This is an example of how different responsibilities can be matched with different repository roles.

27. Permissions and Pull Request Review

Developer
   ↓
Write Permission
   ↓
Create Feature Branch
   ↓
Push Changes
   ↓
Pull Request
   ↓
Reviewer
   ↓
Review
   ↓
Required Approval
   ↓
Merge

Repository rules can define which reviews or checks are required before changes are merged.

28. GitHub Permission Best Practices

  • Follow least privilege.
  • Use teams for larger organizations.
  • Protect important branches.
  • Review repository access regularly.
  • Limit administrative access.
  • Use secure authentication.
  • Never share passwords.
  • Never commit sensitive credentials.
  • Use pull requests for important changes.
  • Document the team's access policy.

29. Permission Checklist

  • Identify who needs repository access.
  • Determine what each person needs to do.
  • Choose an appropriate permission level.
  • Use teams when managing many users.
  • Protect important branches.
  • Review collaborators regularly.
  • Remove unnecessary access.
  • Protect sensitive information.
  • Review repository security settings.
  • Keep administrative access limited.

30. Summary of GitHub Permissions

GitHub permissions control what users and teams can do with repositories. Understanding access levels helps teams organize development while protecting project resources.

User / Team
     ↓
Permission
     ↓
Repository Access
     ↓
Allowed Actions
     ↓
Secure Collaboration

Common repository roles include Read, Triage, Write, Maintain, and Admin. The appropriate role depends on the responsibilities of the user or team.

📌 Key Points

  • Permissions determine what users and teams can do.
  • Authentication verifies identity, while authorization controls access.
  • Common organization repository roles include Read, Triage, Write, Maintain, and Admin.
  • Read access is primarily for viewing repository content.
  • Triage access is useful for managing issues and pull requests.
  • Write access supports development activities.
  • Maintain access supports repository maintenance.
  • Admin access provides powerful repository management capabilities.
  • The least privilege principle helps limit unnecessary access.
  • Teams can simplify access management for organizations.
  • Branch protection can add controls around important branches.
  • Repository permissions should be reviewed regularly.
  • Passwords, tokens, and API keys should not be committed to source code.

🧠 Quick Quiz

Question: What do GitHub permissions control?