Skip to content

Base and effective access

Every namespace has a base permission: the role every namespace member receives on all of its current and future repositories. A change applies immediately, including to repositories created later.

To change it, open the namespace workspace, select Members, and choose a role under Base permission. Choose No base permission when members should get access only through Teams, direct grants, or administration. Organization and namespace administrators can change it.

Organization administrators can review every namespace in one place: open organization settings, select Access, then Base permissions, and choose Manage for a namespace.

The base permission applies only to namespace members. People who are in the organization but not in the namespace receive nothing from it. There is no organization-wide base permission; use an organization Team attached to every namespace when a group needs access everywhere.

New namespaces start with Reader as their base permission. To change the default, open Access → Policies and choose a role under Base permission for new namespaces, or No base permission. The default is copied into each new namespace and never changes existing namespaces.

A member’s effective access to a repository combines:

  • organization administration, which gives full access everywhere;
  • namespace administration, which gives full access in that namespace;
  • the namespace base permission;
  • grants to organization Teams attached to the namespace;
  • grants to the namespace’s Teams; and
  • direct grants to the member.

Access exists only in namespaces the member belongs to. For example, a member of payments might download through the Reader base permission, publish through the Release Engineering Team, and delete versions of one repository through a direct Maintainer grant.

View Shows
Member page → Access Every repository the member can use, their combined role, and each source, plus their direct grants
Namespace Members Each member’s membership sources and whether they are an administrator
Team page → Repositories The access the Team gives its members, grouped by namespace
Repository Access Your access, the roles on this repository and those inherited from the organization and namespace, and everyone with access

Members can check their own access: open organization Members and inspect your own row to see Your access.

Because access is additive, removing one source may not end it. In the example above, removing the direct Maintainer grant still leaves Publisher through the Team and Reader through the base permission. To remove every permission in a namespace, remove the person from the namespace; to remove them from the organization entirely, suspend or remove the member.