What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To audit GitHub access, compare each person or integration’s identity, resource scope, role, and specific permissions with the work it needs. Review people and teams, inspect recent organization activity, then separately check personal access tokens and installed apps. Reduce or revoke a grant only after its owner confirms that dependent work will continue to function.
What “read-only” means in GitHub
“Read-only” is not one universal GitHub role. The required access depends on the task: reading source code, reviewing issues, or viewing security alerts may involve different capabilities. GitHub Docs distinguishes a permission—the ability to perform a specific action—from a role, which is a set of permissions assignable to individuals or teams. Review what the grant enables, not just the role’s label. See GitHub’s access-permissions overview.
As an Amazon Associate I earn from qualifying purchases.
Inventory human and programmatic access separately. For people, account for organization roles, teams, repository roles, outside collaborators, and personal-account collaborators where relevant. For automation, consider fine-grained and classic personal access tokens (PATs), GitHub Apps, and OAuth apps. Personal and organization repositories also use different models: GitHub describes owner and collaborator permission levels for personal-account repositories, while organization accounts have owner, billing manager, and member roles, with teams available to manage access for multiple members.
Recommended Free Tools
Use a six-step audit workflow
1. Define the access the work requires
For every person or service, record its identity, the repositories or other resources it needs, the actions it must perform, and the person responsible for confirming that need. A concrete task such as “read source in these repositories” is more useful than a broad label such as “developer access.” Documentation can explain role and permission models, but only your organization can establish whether a particular grant is still needed.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
2. Review people, teams, and repository access
Inspect organization members and their roles, teams, repository access, and direct grants, including outside collaborators where applicable. Compare each grant with the person’s current responsibilities. Check team-derived access as well as access assigned directly: removing a direct grant will not necessarily remove access inherited through a team.
Verify the role and permission behavior in your organization before changing a grant. GitHub’s documentation describes custom organization roles as an Enterprise Cloud feature, so do not assume they are available on every plan. Start with GitHub’s organization roles documentation.
3. Use the audit log to investigate recent activity
An organization audit log can help answer who performed an action and when. GitHub documents filters for repository (repo), actor (actor), action (action), and date or time (created). Search with the organization-qualified repository name, then export narrowed results as JSON or CSV if needed. GitHub documents that the organization audit log contains only the last 180 days of data; it is not a permanent history. See GitHub’s organization audit-log guide.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
The log records activity; it is not a complete view of current permissions. Pair it with the live membership, repository-access, token, and app settings.
4. Inspect personal access tokens
For an organization, an owner can open the organization settings and go to Personal access tokens → Active tokens. Review each listed fine-grained token’s owner, repository access, and permissions; GitHub documents filters for these fields. Confirm with the token owner and service maintainer whether the access is still needed before revoking a token. GitHub says the token creator receives an email when it is revoked. See GitHub’s guide to reviewing and revoking organization PATs.
Understand the limits of that view and of revocation:
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- The documented organization view lists fine-grained tokens, not classic PATs. Unless the organization restricts classic-token access, classic PATs can access organization resources until they expire.
- Revoking a fine-grained token does not disable SSH keys created by that token.
- A revoked fine-grained token can still read public resources in the organization.
For new or replaceable automation, consider fine-grained PATs. GitHub recommends them instead of classic PATs whenever possible. They can be limited to one selected resource owner, selected repositories, and specific permissions. However, they do not support every classic-token use case: documented gaps include certain outside-collaborator and multiple-organization access patterns, enterprise-level APIs, Packages, the Checks API, and user-owned Projects. Check the relevant endpoint’s compatibility before replacing a working credential. See GitHub’s personal access token guidance.
5. Review installed apps and organization policies
Review installed GitHub Apps separately from human accounts and PATs. Organization owners can inspect an app’s permissions, change which repositories it can access, and temporarily or permanently prevent it from accessing organization resources. Confirm the app’s owner and business purpose before reducing its scope; integrations may depend on access to particular repositories. Use GitHub’s installed-app review guide.
Also check the organization’s programmatic-access controls for applicable OAuth app and PAT policies, including whether users may request app access and whether token approval or restriction settings are configured.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
6. Change access and verify the result
Use your organization’s normal change process to record the identity, resource, existing grant, intended change, approver, and date. Remove stale direct grants or narrow token and app scopes only after the responsible owner confirms dependencies. Then verify that required read workflows still work and that the access you meant to remove no longer appears.
Do not infer that a permission is unnecessary from its name alone. The right change depends on actual role inheritance, current work, integrations, and required API endpoints. If an automation needs a classic PAT because a required workflow is not supported by fine-grained tokens, document that constraint and revisit it if the integration changes.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Compare access across the boundaries that matter
| Audit question | What to establish |
|---|---|
| Principal | Is access held by a person, team, PAT, GitHub App, or OAuth app? |
| Resource boundary | Does it apply to one repository, selected repositories, organization resources, a personal account, or an enterprise? |
| Action boundary | Which specific actions must the work perform, beyond the broad role label? |
| Management and revocation | Who can inspect or change the grant, where is it managed, and what remains active after revocation? |
| Compatibility | Does the API endpoint or collaborator workflow support the narrower credential being considered? |
| Evidence window | Are you checking live access settings or activity within the organization audit log’s last 180 days? |
Where to look for each kind of access
| Access type | Review focus |
|---|---|
| People and teams | Organization membership and roles, team membership, repository roles, direct grants, and outside collaborators where applicable. |
| Fine-grained PATs | Organization settings → Personal access tokens → Active tokens; check owner, selected repositories, and permissions. |
| Classic PATs | Do not assume they appear in the documented fine-grained-token view; check organization restrictions and the token owner’s account. |
| GitHub Apps | Installed apps: review permissions and repository access, then reduce or block access only after confirming the integration’s purpose. |
| OAuth apps and policies | Review the organization’s programmatic-access controls and applicable app access and token approval or restriction policies. |
| Recent activity | Organization audit log: filter by repository, actor, action, or date/time; use it alongside—not instead of—current access settings. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




