Organization Roles

Organization Roles and Permissions

GitHub 29 separates what someone may do to the organization from what they may do to each repository. Organization roles cover the first: owners can do everything, including billing and deletion; members are the default; moderators can also block non-member contributors; billing managers see payments but no code; security managers manage security alerts and features in every repository; app managers manage the organization's GitHub App registrations; and outside collaborators are not members at all, only people with access to specific repositories. Repository access comes from five roles, each including the one above it:

Repository roles, from least to most access
Repository role Adds Intended for
Read Clone, view, open issues and comment Non-code contributors
Triage Label, assign, close issues and pull requests Issue wranglers
Write Push, merge pull requests, manage releases Active developers
Maintain Settings except sensitive or destructive ones Project managers
Admin Security, collaborators, deletion, transfer Repository owners

Effective access is the highest of the base permission, every team grant (including inherited ones) and any direct grant. Access only adds up, so a team can never take away what the base permission gives; that is why the base is usually Read or No permission. A personal account has none of this: invited collaborators all get write access. Enterprise Cloud organizations can also define custom roles, such as Triage plus "manage labels".