For an organization-owned GitHub repository, choose the lowest role that lets someone do their assigned work: Read for viewing and discussion, Triage for managing issues and pull requests, Write for pushing and merging code, Maintain for selected repository-management tasks, and Admin for full control. The roles run from least to most access; check GitHub’s current permission matrix when a particular action matters.
What each GitHub repository role allows
GitHub recommends these roles for organization repositories. The boundaries below are practical summaries, not exhaustive permission lists.
| Role | Recommended for | Practical boundary |
|---|---|---|
| Read | People who need to view or discuss a project without contributing code. | Provides viewing and discussion access, but not the issue-management or code-writing powers of higher roles. |
| Triage | People who manage issues, discussions, and pull requests without writing code. | Can apply milestones, mark duplicates, request pull-request reviews, and hide discussion comments. Cannot push code or merge pull requests in GitHub’s documented matrix. |
| Write | Contributors who actively push code to the project. | Adds the ability to push to assigned repositories and merge pull requests, as well as Triage-level work. |
| Maintain | Project managers who need repository-management powers without certain sensitive or destructive controls. | Includes code-contribution powers and selected management actions. For example, Maintain can limit interactions, but cannot change repository settings or manage access. |
| Admin | People responsible for full repository control. | Can change settings and manage access, change repository visibility, manage webhooks and deploy keys, and transfer or delete the repository, among other administrative actions. |
For security features and enterprise-only functions, use GitHub’s full role matrix. For example, writers and maintainers can directly view secret-scanning alert information for their own commits, but cannot access the alert list view.
Which role should you assign?
Start with the task the person must perform, not their job title. Moving up the ladder grants additional capabilities; select a higher role only when a lower one blocks necessary work.
#1 Best Overall
- Viewing or discussing only: Read.
- Handling issues, discussions, or pull-request coordination without code changes: Triage.
- Pushing changes or merging pull requests: Write is the first role in this ladder with those permissions.
- Managing selected repository operations without settings and access control: Maintain.
- Changing settings, managing access, or performing sensitive or destructive administration: Admin, limited to people who need that authority.
If none of the five built-in roles fits, GitHub Enterprise Cloud organizations can create custom repository roles. This is a plan-specific option, not a feature to assume is available to every organization.
How Triage, Write, and Maintain differ
Can someone with Triage push code or merge a pull request?
No, not according to GitHub’s documented organization-repository role matrix. Triage is intended for issue and pull-request management without code-writing access. Choose Write when the person needs to push or merge.
What is the least role that can merge a pull request?
Write. Triage does not include merge or push permissions in the documented matrix.
Does Maintain let someone change repository settings?
No. Maintain provides selected repository-management capabilities but does not grant the Admin controls for changing repository settings or managing access.
Repository roles and organization roles are different
A repository role controls access to a particular organization-owned repository. An organization role concerns organization-level permissions and may also grant repository permissions across repositories. GitHub defines a role as a set of permissions assigned to an individual or team; a repository role alone therefore does not describe every permission that person may have in the organization. See GitHub’s explanation of roles in an organization.
Organization owners have Admin access to every repository owned by that organization. GitHub also provides predefined organization roles that can grant repository access across all repositories, including Read, Triage, Write, Maintain, or Admin. When checking effective access, account for those broader grants as well as the role assigned directly to a repository.
Rank #4
How base permissions affect access
Organization owners can set base repository permissions for organization members. The setting applies across the organization’s repositories, but not to outside collaborators. GitHub says organization members have Read permission to public repositories in their organization by default. A repository-specific higher permission overrides the base permission.
Changing the base permission affects existing and new members. It does not automatically update permissions on private forks. Consult GitHub’s instructions for setting base permissions for an organization before changing the organization-wide default.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Review or change a person’s repository access
Repository administrators can review access and adjust a person’s or team’s role in repository settings.
- Open the repository and select Settings.
- Under Access, open Collaborators & teams.
- Review the listed people and teams. Change a role or remove access as appropriate.
- If GitHub shows Mixed roles, inspect the indicated access sources before deciding what permissions the person effectively has.
GitHub documents this process on its page about managing teams and people with access to a repository.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




