DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk4 min

How to Configure Least-Privilege Access in GitHub Enterprise

Choose the narrowest GitHub Enterprise role for each task, then audit the grants, team inheritance, and keys that determine effective access.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure GitHub Enterprise access by matching each person’s or team’s required actions to the narrowest role and scope that allows the work. Then audit effective access—not just the role you assigned—because independent grants, inherited team access, organization base permissions, and deploy keys can preserve broader access.

Start with the scope and task

Write down what the person or team needs to do, then choose the scope where that work belongs: enterprise account, organization, team, or individual repository. GitHub permissions represent specific actions; roles bundle permissions. Enterprise roles govern enterprise settings, while organization roles govern organization settings and repositories. A user can have roles at both levels. See GitHub’s explanation of enterprise roles.

Do not use seniority or job title as a substitute for defining the task. Someone who manages issues may need Triage, not Write; someone responsible for a repository may need Maintain, not Admin.

Choose a repository role by the work required

For repositories owned by an organization, the standard role ladder runs from Read to Admin. Choose the lowest level that covers the required actions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Role Suitable work Access boundary
Read View and discuss repository content. No write access.
Triage Manage issues, discussions, and pull requests without writing to the repository. No write access.
Write Contribute actively, including pushing code. Broader than view and triage work.
Maintain Manage a repository without sensitive or destructive actions. Less control than Admin.
Admin Exercise full repository control. Broadest repository role.

Organization owners also have admin access to every repository in their organization. Keep organization ownership to the people who need that broad control. The role descriptions are in GitHub’s organization repository permission documentation.

Use custom roles for specific exceptions

Custom repository roles: narrow the grant to selected repositories

If the standard repository roles are too broad, create a custom repository role for the particular repositories where it is needed. A custom role starts from an inherited role and adds selected permissions. GitHub’s examples include giving a community manager Read plus community-management permissions, or giving a contractor Write plus webhook management. This approach is designed for repository-specific needs rather than access across an organization. GitHub’s custom repository role guidance describes the feature and its limits.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Custom organization roles: selected settings permissions, with a wider repository option

Use a custom organization role when someone needs selected organization settings permissions but should not become an organization owner. A custom organization role does not grant repository access by itself unless it includes repository permissions or a repository base role. If you add a base role, repository access applies to all current and future repositories in that organization, so the blast radius is much larger than a role assigned to selected repositories. The Enterprise Server 3.21 custom organization role documentation identifies repository permissions in these roles as public preview and subject to change.

Assign organization roles through settings

  1. Open the organization’s Settings.
  2. Go to Access > Organization roles > Role assignments.
  3. Select New role assignment.
  4. Choose the people or teams and the role, then add the assignment.

The documented route applies to Enterprise Cloud and Enterprise Server; exact availability and labels can vary by deployed version. Users and teams can hold multiple organization roles, but assign them one at a time. Permission to manage custom roles does not, by itself, grant permission to assign them. Check GitHub’s organization role assignment guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Audit effective access, not just the role you added

Access grants are additive. A custom repository role based on Read does not cancel a separate Write grant from an organization base permission or a team. A narrow role can therefore coexist with broader access.

  1. Open the repository’s access page and review the effective access shown for the person or team.
  2. Trace each grant to its source: direct repository assignment, team membership, organization base permissions, or a role assignment.
  3. Remove or adjust the broader grant at its source. Do not expect a new, narrower role to override it.
  4. Recheck the repository after the change to confirm the intended access remains and the unwanted grant is gone.

Pay particular attention to custom organization roles with repository base roles: they apply to all current and future repositories. Repository custom roles, by contrast, are limited to the repositories where they are assigned. GitHub describes these role behaviors in its custom repository role documentation and custom organization role documentation.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check inherited access and credentials

Team-parent inheritance

A child team may have repository access through its parent team. Inspect the team structure before changing a grant; if access is inherited, change the parent grant to affect the inherited permission. GitHub’s team access documentation covers repository access through teams.

Deploy keys and retained copies

Review deploy keys separately from user and team roles. GitHub warns that anyone holding a repository deploy key’s private key can read or write, depending on the key’s settings, even after that person is removed from the organization. Also, removing someone’s access to a private repository can delete their private forks, but it does not remove local clones. Revoking access therefore does not establish that retained confidential material has been deleted. See GitHub’s repository permission guidance and team access guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Confirm Enterprise Cloud or Server support

Custom-role availability and limits differ between GitHub Enterprise Cloud and Enterprise Server releases. The current GitHub documentation describes up to 20 custom organization roles; Enterprise Server releases earlier than 3.19 have a limit of up to 10. Custom repository roles are available on Enterprise Cloud, and the cited guidance describes a limit of up to 20; Enterprise Server releases earlier than 3.19 have a limit of up to five. For Server 3.21, repository permissions within custom organization roles are documented as public preview. Confirm the deployed edition and version before designing roles, and check the applicable current documentation: organization roles, Server 3.21 custom organization roles, and custom repository roles. The Cloud pages use a moving “latest” version path, so feature details may change.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.