Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Manager org-level role - cloud beta #238

Open
github-product-roadmap opened this issue Sep 8, 2021 · 0 comments
Open

Security Manager org-level role - cloud beta #238

github-product-roadmap opened this issue Sep 8, 2021 · 0 comments

Comments

@github-product-roadmap
Copy link
Collaborator

@github-product-roadmap github-product-roadmap commented Sep 8, 2021

Summary

We are creating an org-level "Security Manager" role. Users will be able to apply the security manager role to any team. When applied it will grant the team's members the following permissions:

  • Read permission on all repositories in the organisation
  • Write permission on all security alerts in the organisation (i.e., the ability to resolve them)
  • Access to Security Center in the org Security tab
  • Write permission on security settings at the organisation level (including the ability to enable/disable GHAS)
  • Write permission on security settings at the repository level (including the ability to enable/disable GHAS)

Intended Outcome

This new role is intended to be used by members of a security team. It will remove the need for security team members to be organisation owners, which is a common workaround but provides these team members with more permissions than they would like (such as the ability to delete any repository).

How will it work?

Organisation owners and security managers will be able to grant the security manager role to teams. The team's members will then gain the permissions described above. If the security manager role is removed from a team its members will lose those permissions (unless they have them by virtue of another role, such as being an organisation owner, or a repository admin).

@github github locked and limited conversation to collaborators Sep 8, 2021
@github-product-roadmap github-product-roadmap added this to Q4 2021 – Oct-Dec in GitHub public roadmap Sep 8, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
GitHub public roadmap
Q4 2021 – Oct-Dec
Status: Q4 2021 – Oct-Dec
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant