GitHub PAT Scope Guidance

This page explains the minimum and recommended Personal Access Token (PAT) scopes for using the platform. Tokens are encrypted at rest; only limited operational metadata is stored. Rotate tokens at any time from the Organisation Management page.

Core Required Scopes

ScopeWhySurface Impact
repoEnumerate repositories (private + public) and read permissions for access planning previews.Repo list, orphan detection, mapping export.
admin:orgRead teams / memberships structure; required for producing accurate Access Planner mapping templates.Team hierarchy, team lookup during mapping import.

If you only sync public repositories you may drop private repo access, but unified permission logic will show reduced completeness.

Optional / Situational Scopes

ScopeWhen NeededNotes
read:orgIf using fine-grained PATs and only read access is permitted.May substitute for admin:org in some limited visibility cases (reduced write capabilities).
workflowIf future features need CI workflow inspection for security posture.Currently not required; defer granting until feature enabled.

Least Privilege Tips

Troubleshooting

Need another scope documented? Raise a ticket or open an issue referencing this page.