Free GitHub Access Audit

Find GitHub repo access drift before signup

repod's free GitHub access audit gives private engineering orgs a fast first pass on repo access drift: direct grants, private repos without team coverage, high-privilege teams, and unclear ownership.

No write access
Read-oriented audit mode
Before signup
Preview the risk signals first
24 hours
Unclaimed audit sessions expire

What it answers

Which access decisions need attention first?

The audit identifies repositories outside the team model, durable access held as individual exceptions, and teams with elevated permissions. It gives a platform lead a concrete starting queue rather than another inventory export.

For the complete operating workflow, see how the GitHub access audit tool moves from evidence to reviewed changes.

Signals

Four checks with a clear review decision

Each signal corresponds to a permission or ownership decision that can be verified in GitHub.

01

Team coverage

Which repositories have at least one team-based permission path?

02

Private unassigned repos

Which private repositories have no team grant or clear owning group?

03

Direct staff mappings

Which user-to-repository grants sit outside the normal GitHub Team model?

04

High-privilege teams

Which teams hold Maintain or Admin and need an explicit justification?

Synthetic example

A report that turns drift into a review queue

These sample figures illustrate the report structure. A live audit calculates them from the selected GitHub organization.

68%

Team coverage

Review repositories outside the team model first.

11

Private unassigned repos

Assign an owning team or document the exception.

52

Direct staff mappings

Move durable access into teams where practical.

7

High-privilege teams

Confirm that Maintain or Admin is still justified.

Manual worksheet

Run the same decisions in a spreadsheet

Use the template for a small review or to agree the fields your team needs before automating the process.

Download CSV worksheet
RepositoryVisibilityOwning teamDirect accessReview decision
acme-platform/deployment-controllerPrivateplatform-engineeringalice-dev, vendor-reviewerReplace durable direct access with team access; verify the vendor exception.

The download also includes exception owner, expiry, permission, and notes columns. For a full manual process, use the GitHub repository permissions audit checklist or the GitHub repo access audit guide.

Permissions needed

Read access is enough for the audit

A fine-grained PAT lets repod read organization members, repository metadata, teams, team membership, and repo-team permissions. The free audit does not need write access.

Check the exact fine-grained PAT permissions.

  • Organization members: Read
  • Organization administration: Read
  • Repository metadata: Read
  • Repository access: selected repositories or all repositories