Product · Live
Repod
GitHub access governance for finding risky permissions, planning cleanup, and producing audit-ready evidence.
Open Repod- Role
- Product direction, systems, and delivery
- Timeframe
- Current
- Product
- Governance
- Delivery
The problem
GitHub permissions become difficult to reason about as organisations grow. Teams need a practical way to find access risk, plan cleanup, and prepare evidence without adopting heavyweight enterprise tooling.
The audience
Engineering managers, platform teams, and technical leaders who need practical access-governance work without turning the job into a heavyweight enterprise programme.
My responsibility
Built and operated end to end.
- 01
Set the product direction and positioning.
- 02
Designed the GitHub access-governance workflow.
- 03
Built the application and its GitHub data integration.
- 04
Operate the infrastructure, deployment, and ongoing delivery.
Shipped capabilities
A workflow for the whole governance job.
- 01
Synchronise GitHub organisation access state.
- 02
Surface unassigned, direct, and privileged access risk.
- 03
Preview and apply team-to-repository changes.
- 04
Establish governance baselines, run access reviews, and export audit evidence.
Shipped workflow
Understand, preview, then apply.
Repod · Team–Repo Access Planner
Workflow overview- 01
Export current mapping
Download the current team-to-repository access state as a working document.
- 02
Import and preview
Review proposed changes and their effect before anything is written to GitHub.
- 03
Apply approved changes
Write only the reviewed changes, then retain the evidence of what changed.
Product evidence
The workflow in use.

The exported workbook makes current access and proposed ownership visible in one review surface.

Approved changes are applied as a controlled batch with a clear repository-by-repository result.

The governance map exposes team structure, direct grants, and unassigned repositories that are hard to reason about in lists.
Decisions and constraints
Clarity before automation.
- 01
Preview before write
Repository access is consequential, so the workflow separates understanding and approval from the write back to GitHub.
- 02
Keep the operating model legible
The product connects risk discovery, cleanup planning, access reviews, and evidence instead of leaving them as unrelated tools.
- 03
Work within the source system
Repod synchronises GitHub state and produces a controlled change plan; it does not invent a second permissions model to maintain.
Current status
Live product.
Repod is live and actively operated. Product direction, application delivery, infrastructure, and the governance workflow remain one connected responsibility.
Visit the project