GitHub Teams hierarchy and repository permissions
See how parent grants, child teams, and direct team permissions combine into effective repository access.
Practical guidance for understanding who can access each GitHub repository, why that access exists, and how to change it without creating a new permission problem.
Start with the job in front of you: explain the access model, audit the live state, fix drift, or choose the right operating approach.
Use these guides when the problem is terminology, inheritance, effective permissions, or an unexpectedly broad audience.
See how parent grants, child teams, and direct team permissions combine into effective repository access.
Use GitHub's exact access labels to separate durable team access from justified individual exceptions.
Distinguish a repository's visibility setting from the teams, roles, and direct grants that define its real audience.
Assess broad Write against branch controls, Actions, packages, secrets, and a safer contribution model.
Start with the free audit, or use the manual guides when you need to define the review before connecting a tool. For a product overview, see the GitHub access audit tool; consultants can use the fractional CTO workflow.
Find direct grants, private repositories without team coverage, and high-privilege teams before signup.
Review stale admins, direct grants, collaborators, inherited access, service accounts, and evidence.
Follow a practical sequence for inventory, exceptions, effective roles, evidence, and remediation decisions.
Define ownership, least privilege, repository lifecycle, review cadence, and the evidence that proves the model.
Use these workflows after the current access paths and desired ownership model are understood.
Edit the current mapping, preview the proposed diff, and apply only after the change set is clear.
Move broad parent access toward narrower ownership teams while preserving the access people still need.
Separate day-to-day access work from organization ownership and keep changes reviewable.
Remove team membership, direct access, outside collaboration, tokens, and temporary exceptions coherently.
Separate native team management, local audit scripts, organization-as-code, settings enforcement, and access operations before comparing features.
Compare GitHub Teams, Enterprise controls, Terraform, safe-settings, organization-as-code, and repod.
Decide whether the immediate need is settings enforcement, access-policy review, or both controls together.
Compare a local access report with a persistent, delegated review and remediation workflow.
Compare a configuration source of truth with an access review, delegation, and evidence workflow.