Reference
Permissions and data handling
Understand workspace roles, repository scope, recorded evidence, and retention controls.
On this page
Identity and access#
Website identity is verified through Firebase authentication. GitHub authorization separately verifies access to an enabled App installation. Workspace requests require a valid signed-in identity and an active workspace membership; an installation ID alone does not grant access.
| Role | Read workspace data | Change selection, settings, and reviews |
|---|---|---|
| Owner | Yes, within the authorized workspace | Yes, with a verified email and active access |
| Admin | Yes, within the authorized workspace | Yes, with a verified email and active access |
| Viewer | Yes, within the authorized workspace | No |
The current interface does not include self-service member invitations or role management. Ask your deployment owner about workspace membership needs. A website account or ordinary GitHub organization membership alone does not automatically grant a workspace role.
Repository scope#
GitHub installation permissions limit which repositories the App can access. Saved workspace selection narrows that scope further. The backend rechecks repository availability when changing selection or requesting an index, and analysis checks current authorization before publication.
The App uses repository contents read access to fetch supported files at immutable commits. Repository code is not executed. It publishes advisory checks and, when enabled, report comments using their dedicated write permissions.
What the workspace records#
- Your authenticated identity and workspace membership needed for access decisions.
- Connected installation metadata and protected authorization material needed for GitHub access.
- Selected repository metadata, index status, commit SHAs, and parser coverage notes.
- Discovered service and endpoint records, extracted schemas, and source references.
- Analysis jobs, PR findings, explanations, settings, and snapshot-specific evidence reviews.
- Verified webhook delivery records needed for processing and deduplication.
GitHub App keys and authorization tokens are managed on the server. The website receives workspace data for the signed-in membership. Current production analysis is deterministic and does not send consumer slices to an external model provider.
Source links open in GitHub under your GitHub permissions. Dashboard exports and screenshots can contain private repository names or paths; share them with the same care as the corresponding engineering documents.
Retention and removal#
| Data | Retention behavior |
|---|---|
| Job and PR analysis history; evidence reviews | Controlled by History retention in days, from 7 to 365 days; periodic cleanup applies. |
| Current repository snapshots | Remain while the repository is selected; removed from the live workspace when deselected. |
| GitHub report comments and checks | Remain in GitHub under GitHub's controls; workspace cleanup does not remove them. |
| Encrypted database backups | Daily backups use a separate 35-day retention policy, with a further 7-day soft deletion period. |
Removing a repository from a workspace or revoking App access changes live analysis eligibility. It is not a promise of immediate removal from existing backups or from GitHub publications. Contact your deployment owner for account removal or a retention request outside the available workspace controls.