Teams and access
Access is closed by default: organization owners and admins see every repository, and everyone else sees only the repositories they have been granted.
Organization roles
Every person in an organization has one of three roles. A role is chosen when you invite someone, and can be changed later — but only by an owner.
| Role | What it can do |
|---|---|
owner |
Everything, including changing member roles — the only role that can. |
admin |
Manages repositories, teams, members, policies, and connections. Cannot change roles. |
member |
Sees only the repositories they have been granted. |
Invite people from Members → Invite: enter an email and a role, and optionally place them on one or more teams. Invitations expire if they are not accepted.
Repository grants
On any repository, the Access panel — open to owners and admins only — grants one of two levels to a person or a team:
| Grant | What it can do |
|---|---|
maintainer |
Manage the tracked branches and the attached policy, and trigger scans. |
viewer |
Read-only — results, issues, and history. |
Teams
A team is a named group of members you use as a grant target. Grant a repository to a team once, and everyone in the team gets that access.
Every organization has a built-in team called all that contains every member. It cannot be edited or deleted.
A teammate cannot see a repository? They have the member role and no grant. Grant their team, or them directly, on the repository's Access panel — or ask an admin to.