Dashboard › publish › approval-authorizer GitHub roles
01a043ee-6db5-7c89-adb7-b023a45b59ccChose live GitHub collaborator permission checks over private security-as-code because Publish is public and GitHub reflects effective target-repository access without exposing RBAC. Humans authorize only with write, maintain, or admin; triage never authorizes. getsantry[bot] must never fall through to collaborator lookup: it authorizes only when its exact parsed repository/release path is in auto-approve-repos.txt, because bot repository access does not prove the event followed an allowlisted auto-approval path.