Teams, Members, Roles, and Access
Document: INF-103Type: Guide / SOPStatus: ApprovedOwner: Engineering OperationsVersion: 4.2.0Updated: 2026-07-17
Recommended Initial Teamsโ
| Team | Purpose | Typical access |
|---|---|---|
| Leadership | Business and technical oversight | Maintain or Admin only where justified |
| Engineering | Application development | Write |
| Design | Design assets and UI collaboration | Read/Triage; Write only where required |
| Operations | Manual, processes, deployment coordination | Write on operational repositories |
| Marketing | Website and campaign content | Triage/Write on approved repositories |
Create a Teamโ
- Open the organization.
- Select Teams โ New team.
- Enter the approved team name and description.
- Select visibility according to policy; use visible teams unless secrecy is necessary.
- Optionally choose a parent team for nested structures.
- Create the team.
- Add organization members.
- Assign repository access at the lowest suitable role.
Repository Rolesโ
| Role | Use |
|---|---|
| Read | View and clone; suitable for observers and limited stakeholders |
| Triage | Manage issues and pull requests without writing code |
| Write | Push code and collaborate normally |
| Maintain | Manage repository workflows without destructive administrative powers |
| Admin | Full repository control; restrict carefully |
Outside Collaboratorsโ
Use outside collaborators for contractors who require access to specific repositories but should not become organization members. Outside collaborators cannot be added to organization teams, so grant repository-level access directly and review it on a defined end date.
Quarterly Access Reviewโ
- Review organization owners.
- Review members and outside collaborators.
- Remove dormant or completed contractor access.
- Review team memberships and repository roles.
- Confirm every privileged user retains 2FA.
- Record the review date in the Infrastructure Register.