Base and effective access
Base permission
Section titled “Base permission”Every namespace has a base permission: the role every namespace member receives on all of its current and future repositories. A change applies immediately, including to repositories created later.
To change it, open the namespace workspace, select Members, and choose a role under Base permission. Choose No base permission when members should get access only through Teams, direct grants, or administration. Organization and namespace administrators can change it.
Organization administrators can review every namespace in one place: open organization settings, select Access, then Base permissions, and choose Manage for a namespace.
The base permission applies only to namespace members. People who are in the organization but not in the namespace receive nothing from it. There is no organization-wide base permission; use an organization Team attached to every namespace when a group needs access everywhere.
Base permission for new namespaces
Section titled “Base permission for new namespaces”New namespaces start with Reader as their base permission. To change the default, open Access → Policies and choose a role under Base permission for new namespaces, or No base permission. The default is copied into each new namespace and never changes existing namespaces.
Effective access
Section titled “Effective access”A member’s effective access to a repository combines:
- organization administration, which gives full access everywhere;
- namespace administration, which gives full access in that namespace;
- the namespace base permission;
- grants to organization Teams attached to the namespace;
- grants to the namespace’s Teams; and
- direct grants to the member.
Access exists only in namespaces the member belongs to. For example, a member of
payments might download through the Reader base permission, publish through
the Release Engineering Team, and delete versions of one repository through a
direct Maintainer grant.
See why someone has access
Section titled “See why someone has access”| View | Shows |
|---|---|
| Member page → Access | Every repository the member can use, their combined role, and each source, plus their direct grants |
| Namespace Members | Each member’s membership sources and whether they are an administrator |
| Team page → Repositories | The access the Team gives its members, grouped by namespace |
| Repository Access | Your access, the roles on this repository and those inherited from the organization and namespace, and everyone with access |
Members can check their own access: open organization Members and inspect your own row to see Your access.
Remove access completely
Section titled “Remove access completely”Because access is additive, removing one source may not end it. In the example above, removing the direct Maintainer grant still leaves Publisher through the Team and Reader through the base permission. To remove every permission in a namespace, remove the person from the namespace; to remove them from the organization entirely, suspend or remove the member.

