Skip to main content

Teams, Members, Roles, and Access

Document: INF-103Type: Guide / SOPStatus: ApprovedOwner: Engineering OperationsVersion: 4.2.0Updated: 2026-07-17

TeamPurposeTypical access
LeadershipBusiness and technical oversightMaintain or Admin only where justified
EngineeringApplication developmentWrite
DesignDesign assets and UI collaborationRead/Triage; Write only where required
OperationsManual, processes, deployment coordinationWrite on operational repositories
MarketingWebsite and campaign contentTriage/Write on approved repositories

Create a Teamโ€‹

  1. Open the organization.
  2. Select Teams โ†’ New team.
  3. Enter the approved team name and description.
  4. Select visibility according to policy; use visible teams unless secrecy is necessary.
  5. Optionally choose a parent team for nested structures.
  6. Create the team.
  7. Add organization members.
  8. Assign repository access at the lowest suitable role.

Repository Rolesโ€‹

RoleUse
ReadView and clone; suitable for observers and limited stakeholders
TriageManage issues and pull requests without writing code
WritePush code and collaborate normally
MaintainManage repository workflows without destructive administrative powers
AdminFull repository control; restrict carefully

Outside Collaboratorsโ€‹

Use outside collaborators for contractors who require access to specific repositories but should not become organization members. Outside collaborators cannot be added to organization teams, so grant repository-level access directly and review it on a defined end date.

Quarterly Access Reviewโ€‹

  • Review organization owners.
  • Review members and outside collaborators.
  • Remove dormant or completed contractor access.
  • Review team memberships and repository roles.
  • Confirm every privileged user retains 2FA.
  • Record the review date in the Infrastructure Register.