Create engagement
The client engagement, confidentiality terms and authorised contacts are established before repository access.
Install with consent
GitHub shows the requested permissions and the client chooses the organisation/account and selected repositories.
Freeze exact scope
Repository IDs, exact commit SHA, included/excluded paths and build evidence are captured in the Preflight Engagement Manifest.
Use short-lived access
The audit platform creates repository-restricted, short-lived installation access only when an isolated worker needs it.
Review and remediate
Findings, evidence and remediation are tied to the frozen candidate; a changed commit becomes a new review candidate.
Revoke cleanly
Repository removal or app uninstall prevents new access and triggers controlled workspace cleanup and retention handling.
Default permission posture
Read-only by default.
Repository content access is limited to the customer-selected repositories. Administrative, workflow-write and repository-content-write access are not part of the default audit mode. Optional checks, statuses or SARIF write-back require a separate client-enabled permission tier.
