Teams and access

Access is closed by default: organization owners and admins see every repository, and everyone else sees only the repositories they have been granted.

Organization roles

Every person in an organization has one of three roles. A role is chosen when you invite someone, and can be changed later — but only by an owner.

Role What it can do
owner Everything, including changing member roles — the only role that can.
admin Manages repositories, teams, members, policies, and connections. Cannot change roles.
member Sees only the repositories they have been granted.

Invite people from Members → Invite: enter an email and a role, and optionally place them on one or more teams. Invitations expire if they are not accepted.

Repository grants

On any repository, the Access panel — open to owners and admins only — grants one of two levels to a person or a team:

Grant What it can do
maintainer Manage the tracked branches and the attached policy, and trigger scans.
viewer Read-only — results, issues, and history.

Teams

A team is a named group of members you use as a grant target. Grant a repository to a team once, and everyone in the team gets that access.

Every organization has a built-in team called all that contains every member. It cannot be edited or deleted.

A teammate cannot see a repository? They have the member role and no grant. Grant their team, or them directly, on the repository's Access panel — or ask an admin to.