GitHub 29 separates what someone may do to the organization from what they may do to each repository. Organization roles cover the first: owners can do everything, including billing and deletion; members are the default; moderators can also block non-member contributors; billing managers see payments but no code; security managers manage security alerts and features in every repository; app managers manage the organization's GitHub App registrations; and outside collaborators are not members at all, only people with access to specific repositories. Repository access comes from five roles, each including the one above it:
| Repository role | Adds | Intended for |
|---|---|---|
| Read | Clone, view, open issues and comment | Non-code contributors |
| Triage | Label, assign, close issues and pull requests | Issue wranglers |
| Write | Push, merge pull requests, manage releases | Active developers |
| Maintain | Settings except sensitive or destructive ones | Project managers |
| Admin | Security, collaborators, deletion, transfer | Repository owners |
Effective access is the highest of the base permission, every team grant (including inherited ones) and any direct grant. Access only adds up, so a team can never take away what the base permission gives; that is why the base is usually Read or No permission. A personal account has none of this: invited collaborators all get write access. Enterprise Cloud organizations can also define custom roles, such as Triage plus "manage labels".