BrainyBeeBrainyBee
ExploreBlogStart Studying
HomeDesigning and Implementing Microsoft DevOps Solutions (AZ-400)Permissions and roles in GitHub
Lesson231 words

Permissions and roles in GitHub

Design and implement permissions and roles in GitHub

Repository roles

RoleCan
ReadPull, view and discuss, and open issues
TriageManage issues, discussions, and pull requests without write access
WriteActively push changes, subject to branch/ruleset controls
MaintainManage the repository without sensitive or destructive actions
AdminFull repository access, including sensitive/destructive actions

These are GitHub's five standard organization-repository roles; Enterprise Cloud can also define custom roles. Choose the least-privileged role that fits the work.

Teams

Prefer teams for reusable organization-member access and lifecycle management. Direct person grants remain supported. A child team inherits its parent team's repository access, so every parent grant must be safe for all child-team members.

Outside collaborators

An outside collaborator is not an organization member and receives a chosen role on specific repositories. Outside collaborators cannot join organization teams, and organization base permissions do not apply to them.

Branch protection and rulesets

A repository role grants baseline capabilities. Branch protection and rulesets layer on branch/tag restrictions, required reviews or checks, signed-commit or deployment requirements, and bypass controls. They can also restrict who may push, so role and rule configuration must be evaluated together.

Primary sources

  • https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/az-400
  • https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/repository-roles-for-an-organization
  • https://docs.github.com/en/organizations/organizing-members-into-teams/about-teams
  • https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-outside-collaborators/adding-outside-collaborators-to-repositories-in-your-organization
  • https://docs.github.com/en/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/setting-base-permissions-for-an-organization
  • https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches
  • https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/about-rulesets
  • https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/managing-repository-settings/managing-teams-and-people-with-access-to-your-repository
All Designing and Implementing Microsoft DevOps Solutions (AZ-400) Study Resources

Related Notes

  • Agent and runner infrastructure533 words
  • Agent and runner infrastructure — quick notes222 words
  • Alerting on pipeline events255 words
  • Alerting on pipeline events — quick notes94 words
  • Analyzing usage and application performance241 words
  • Analyzing usage and application performance — quick notes73 words
  • Appropriate access levels294 words
  • Appropriate access levels — quick notes180 words
  • Automating container scanning277 words
  • Automating container scanning — quick notes96 words
  • Automating documentation from Git history191 words
  • Automating documentation from Git history — quick notes55 words

Ready to study Designing and Implementing Microsoft DevOps Solutions (AZ-400)?

Practice tests, flashcards, and all study notes — free, no sign-up.

Start Studying

Ready to study Designing and Implementing Microsoft DevOps Solutions (AZ-400)?

Practice tests, flashcards, and all study notes — free, no sign-up needed.

Start Studying — Free
Designing and Implementing Microsoft DevOps Solutions (AZ-400) ResourcesExplore All HivesBlogHome

© 2026 BrainyBee. Free AI-powered exam prep.