Skip to content

Organizations and access

An organization is the shared account for a group of people: members, seats, billing, private mirrors, automation, and organization-wide policies. Inside it, namespaces hold repositories and decide who works with them.

If you know GitHub, an organization works like an enterprise account and each namespace works like a GitHub organization inside it.

organization
├─ members and organization administrators
├─ organization Teams (attached to some or every namespace)
├─ policies, custom roles, private mirrors, automation
└─ namespace
├─ namespace members and namespace administrators
├─ namespace Teams
├─ base permission and grants
└─ repositories
  • Joining the organization gives no repository access on its own. A member works in a namespace only after joining it: an administrator adds them, an invitation places them there, the namespace adds new members automatically, an attached organization Team includes them, or they administer it.
  • Each namespace has a base permission that every namespace member receives on its current and future repositories, such as Reader.
  • Grants add more. A Team or a member can receive a repository role on every repository in a namespace or on specific repositories. Organization Teams can also receive a role on every repository in the organization.
  • Organization administrators have full access everywhere, without needing namespace membership. Namespace administrators have full access inside the namespaces they administer.

Access is additive. Ravenstash combines the base permission, every Team grant, and every direct grant; nothing reduces or denies access that another source provides.

Administration and repository roles are different

Section titled “Administration and repository roles are different”

Organization and namespace administration control settings boundaries. Repository roles control what somebody can do with repositories. For example, a member with the Admin repository role on the payments namespace can change and delete its repositories, but cannot manage organization members, billing, Teams, or private mirrors.

Start with members and administrators, or go directly to roles and grants.