Impact GateDocs

Connect & index

Connect the GitHub App

Install Impact Gate, verify organization access, and connect the intended installation to your workspace.

On this page

Requirements#

  • A signed-in Impact Gate account with a verified email.
  • A GitHub account that owns or administers the intended organization installation.
  • Approval to install the App and grant access to the intended repositories.
  • An organization enabled for this pilot deployment.

Install and connect#

  1. Open workspace setup

    Go to Connect your workspace and choose Connect GitHub. If you already have a workspace, use Manage GitHub connection in Repositories or Manage connection in Settings.

  2. Authorize the intended GitHub account

    Complete the GitHub authorization screen using the account that administers your organization. Stay in the same browser while completing this flow.

  3. Install Impact Gate if needed

    On Choose a GitHub installation, choose Install GitHub App if the intended organization is missing. In GitHub, select the organization, review the permissions, and grant access to the repositories you plan to analyze.

  4. Refresh available installations

    Return to Impact Gate and use Refresh installations after installing or updating access. Only installations verified for your GitHub account and enabled deployment appear.

  5. Confirm the organization

    Choose Connect beside the intended organization. Setup should show its account name and an active installation status.

  6. Choose repositories

    Continue with Select and index repositories. App installation access defines what can be selected; your workspace selection defines what is analyzed.

Requested permissions#

ScopePermissionPurpose
Repository contentsReadRead supported contracts and consumer source at immutable commits.
Pull requestsRead and writeRead PR state and update an advisory report comment.
ChecksRead and writePublish and update the Impact Gate check for a PR head.
Repository metadataReadIdentify repositories, owners, and installation access.
Organization membersReadVerify that the connecting GitHub user administers the organization.
Account email addressesReadIncluded in the App's GitHub user authorization; website sign-in still uses its own verified identity.

The application reads repository source without executing it. It does not request repository contents write access. PR comments and checks are the publication actions performed by the App.

Change or remove access#

Manage repository permissions from your organization's GitHub App installation settings. After granting additional repositories, return to Manage GitHub connection, reconnect if needed, and refresh the repository choices.

Removing repository access, suspending the installation, uninstalling the App, or revoking GitHub authorization can stop eligible analysis. Pending work rechecks selection and authorization before publishing. GitHub App access and website sign-out are separate controls.

Explore the documentation

↑↓ NavigateEnter Open guideSearch stays in your browser