Back to work

Product · Live

Repod

GitHub access governance for finding risky permissions, planning cleanup, and producing audit-ready evidence.

Open Repod
Role
Product direction, systems, and delivery
Timeframe
Current
01

The problem

GitHub permissions become difficult to reason about as organisations grow. Teams need a practical way to find access risk, plan cleanup, and prepare evidence without adopting heavyweight enterprise tooling.

02

The audience

Engineering managers, platform teams, and technical leaders who need practical access-governance work without turning the job into a heavyweight enterprise programme.

My responsibility

Built and operated end to end.

  1. 01

    Set the product direction and positioning.

  2. 02

    Designed the GitHub access-governance workflow.

  3. 03

    Built the application and its GitHub data integration.

  4. 04

    Operate the infrastructure, deployment, and ongoing delivery.

Shipped capabilities

A workflow for the whole governance job.

  1. 01

    Synchronise GitHub organisation access state.

  2. 02

    Surface unassigned, direct, and privileged access risk.

  3. 03

    Preview and apply team-to-repository changes.

  4. 04

    Establish governance baselines, run access reviews, and export audit evidence.

Shipped workflow

Understand, preview, then apply.

Repod · Team–Repo Access Planner

Workflow overview
  1. 01

    Export current mapping

    Download the current team-to-repository access state as a working document.

  2. 02

    Import and preview

    Review proposed changes and their effect before anything is written to GitHub.

  3. 03

    Apply approved changes

    Write only the reviewed changes, then retain the evidence of what changed.

Decisions and constraints

Clarity before automation.

  1. 01

    Preview before write

    Repository access is consequential, so the workflow separates understanding and approval from the write back to GitHub.

  2. 02

    Keep the operating model legible

    The product connects risk discovery, cleanup planning, access reviews, and evidence instead of leaving them as unrelated tools.

  3. 03

    Work within the source system

    Repod synchronises GitHub state and produces a controlled change plan; it does not invent a second permissions model to maintain.

Current status

Live product.

Repod is live and actively operated. Product direction, application delivery, infrastructure, and the governance workflow remain one connected responsibility.

Visit the project

See the work in context.

Open Repod