diff --git a/docs/organizations/roles-and-permissions-for-organizations.md b/docs/organizations/roles-and-permissions-for-organizations.md index 73d6736cca..914a8dc002 100644 --- a/docs/organizations/roles-and-permissions-for-organizations.md +++ b/docs/organizations/roles-and-permissions-for-organizations.md @@ -13,12 +13,14 @@ Organization admins can also grant additional permissions: - To roles, by [configuring repository management permissions](#change-analysis-configuration) - To individual members, by [assigning the organization manager role](#managing-the-organization-manager-role) -To review the permissions granted by each role, see the tables for each Git provider: +To find your Codacy role, see the roles for your Git provider: - [Permissions for GitHub](#permissions-for-github) - [Permissions for GitLab](#permissions-for-gitlab) - [Permissions for Bitbucket](#permissions-for-bitbucket) +Then see what that role can do in [Permissions by Codacy role](#permissions-by-codacy-role). + To list and manage the members of your Codacy organization, see the [Managing people](managing-people.md) page. ## Configuring repository management permissions {: id="change-analysis-configuration"} @@ -42,7 +44,7 @@ To change this, open your organization **Settings**, page **Roles and permission To grant an organization member additional permissions, you can assign that member the organization manager role. This role isn't influenced by a member's Git provider role. -To review the additional permissions granted by the organization manager role, see the tables for each Git provider ([GitHub](#permissions-for-github), [GitLab](#permissions-for-gitlab), [Bitbucket](#permissions-for-bitbucket)). +To review the additional permissions granted by the organization manager role, see [Organization manager](#organization-manager). !!! note Organization managers can access the **Policies** and **Integrations** settings sections of your organization and can therefore impact some repository settings for all repositories of your organization, even repositories that they can't access on the Git provider. However, they can't access the repositories themselves and can only see the repository names. @@ -72,489 +74,86 @@ To revoke the organization manager role: ## Permissions for GitHub -The table below maps the GitHub Cloud and GitHub Enterprise roles to the corresponding Codacy roles and the operations that they're allowed to perform: +The following GitHub Cloud and GitHub Enterprise roles map to these Codacy roles: -
| GitHub role | -Outside collaborator1 |
- Repository read |
- Repository triage |
- Repository write |
- Repository maintain |
- Repository admin |
- - | -Organization Owner |
-
|---|---|---|---|---|---|---|---|---|
| Codacy role | -- | -Repository read |
- Repository write |
- Repository admin |
- Organization manager |
- Organization admin |
- ||
| Join organization | -No | -Yes2 | -Yes2 | -Yes2 | -Yes | -Yes2 | -||
| View and follow private repository | -No | -Yes | -Yes | -Yes | -Yes | -Yes | -||
| Access Security and risk management | -No | -Yes3 | -Yes3 | -Yes3 | -Yes | -Yes | -||
| Access AI Risk Hub Overview | -No | -Yes | -Yes | -Yes | -Yes | -Yes | -||
| Access AI Risk Hub AI assets and Tools & workflows | -No | -No | -No | -No | -Yes | -Yes | -||
| Ignore issues and files, configure code patterns, reanalyze branches and pull requests |
- No | -Configurable | -Configurable | -Yes | -Inherits original permission | -Yes | -||
| Upload coverage using an account API token, see the coverage report logs |
- No | -No | -Yes | -Yes | -Inherits original permission | -Yes | -||
| Configure repository Git provider integration settings | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -||
| Configure repository quality gates and goals | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -||
| Enable repository analysis to run on a local build server, manage repository API tokens | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -||
| Add and remove repository | -No | -No | -No | -Yes4 | -Inherits original permission | -Yes | -||
| Manage organization gate policies and coding standards | -No | -No | -No | -No | -Yes | -Yes | -||
| Configure organization default settings for Git provider integration | -No | -No | -No | -No | -Yes | -Yes | -||
| Obtain audit logs for organization events5 | -No | -No | -No | -No | -Yes | -Yes | -||
| Invite and accept members, modify billing |
- No | -No | -No | -No | -No | -Yes | -||
| Assign and revoke the organization manager role | -No | -No | -No | -No | -No | -Yes | -||
| GitLab role | -External user1 |
- Project guest |
- Project reporter |
- Project developer |
- Project maintainer |
- Project owner |
- - | -Group owner |
- Administrator | -
|---|---|---|---|---|---|---|---|---|---|
| Codacy role | -- | -Repository read |
- Repository write |
- Repository admin |
- Organization manager |
- Organization admin |
- |||
| Join organization | -No | -Yes2 | -Yes2 | -Yes2 | -Yes | -Yes2 | -|||
| View and follow private repository | -No | -Yes | -Yes | -Yes | -Yes | -Yes | -|||
| Access Security and risk management | -No | -Yes3 | -Yes3 | -Yes3 | -Yes | -Yes | -|||
| Access AI Risk Hub Overview | -No | -Yes | -Yes | -Yes | -Yes | -Yes | -|||
| Access AI Risk Hub AI assets and Tools & workflows | -No | -No | -No | -No | -Yes | -Yes | -|||
| Ignore issues and files, configure code patterns, reanalyze branches and pull requests |
- No | -Configurable | -Configurable | -Yes | -Inherits original permission | -Yes | -|||
| Upload coverage using an account API token, see the coverage report logs |
- No | -No | -Yes | -Yes | -Inherits original permission | -Yes | -|||
| Configure repository Git provider integration settings | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -|||
| Configure repository quality gates and goals | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -|||
| Configure repository to run analysis on local build server, manage repository API tokens | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -|||
| Add and remove repository | -No | -No | -No | -Yes | -Inherits original permission | -Yes | -|||
| Manage organization gate policies and coding standards | -No | -No | -No | -No | -Yes | -Yes | -|||
| Configure organization default settings for Git provider integration | -No | -No | -No | -No | -Yes | -Yes | -|||
| Obtain audit logs for organization events4 | -No | -No | -No | -No | -Yes | -Yes | -|||
| Invite and accept members, modify billing |
- No | -No | -No | -No | -No | -Yes | -|||
| Assign and revoke the organization manager role | -No | -No | -No | -No | -No | -Yes | -|||
| Bitbucket role | -Read | -Write1 | -- | -Admin | +Operation | +Repository read | +Repository write | +Repository admin | +Organization manager | +Organization admin |
|---|---|---|---|---|---|---|---|---|---|---|
| Codacy role | -Repository read |
- Organization manager |
- Organization admin |
- |||||||
| Join organization | -Yes2 | -Yes | -Yes2 | -|||||||
| View and follow private repository | -Yes | -Yes | -Yes | -|||||||
| Access Security and risk management | -Yes3 | -Yes | -Yes | -|||||||
| Access AI Risk Hub Overview | -Yes | -Yes | -Yes | -|||||||
| Access AI Risk Hub AI assets and Tools & workflows | -No | -Yes | -Yes | -|||||||
| Ignore issues and files, configure code patterns, reanalyze branches and pull requests |
- Configurable | -Inherits original permission | -Yes | -|||||||
| Upload coverage using an account API token, see the coverage report logs |
- No | -Inherits original permission | -Yes | -|||||||
| Configure repository Git provider integration settings | -No | -Inherits original permission | -Yes | -|||||||
| Configure repository quality gates and goals | -No | -Inherits original permission | -Yes | -|||||||
| Configure repository to run analysis on local build server, manage repository API tokens | -No | -Inherits original permission | -Yes | -|||||||
| Add and remove repository | -No | -Inherits original permission | -Yes | -|||||||
| Manage organization gate policies and coding standards | -No | -Yes | -Yes | -|||||||
| Configure organization default settings for Git provider integration | -No | -Yes | -Yes | -|||||||
| Obtain audit logs for organization events4 | -No | -Yes | -Yes | -|||||||
| Invite and accept members, modify billing |
- No | -No | -Yes | -|||||||
| Assign and revoke the organization manager role | -No | -No | -Yes | -|||||||
| Join organization | Yes1 | Yes1 | Yes1 | Yes | Yes1 | |||||
| View and follow private repository | Yes | Yes | Yes | Yes | Yes | |||||
| Access Security and risk management | Yes2 | Yes2 | Yes2 | Yes | Yes | |||||
| Access AI Risk Hub Overview | Yes | Yes | Yes | Yes | Yes | |||||
| Access AI Risk Hub AI assets and Tools & workflows | No | No | No | Yes | Yes | |||||
| Ignore issues and files, configure code patterns, reanalyze branches and pull requests | Configurable | Configurable | Yes | Inherits original permission | Yes | |||||
| Upload coverage using an account API token, see the coverage report logs | No | Yes | Yes | Inherits original permission | Yes | |||||
| Configure repository Git provider integration settings | No | No | Yes | Inherits original permission | Yes | |||||
| Configure repository quality gates and goals | No | No | Yes | Inherits original permission | Yes | |||||
| Configure repository to run analysis on a local build server, manage repository API tokens | No | No | Yes | Inherits original permission | Yes | |||||
| Add and remove repository | No | No | Yes3 | Inherits original permission | Yes | |||||
| Manage organization gate policies and coding standards | No | No | No | Yes | Yes | |||||
| Configure organization default settings for Git provider integration | No | No | No | Yes | Yes | |||||
| Obtain audit logs for organization events4 | No | No | No | Yes | Yes | |||||
| Invite and accept members, modify billing | No | No | No | No | Yes | |||||
| Assign and revoke the organization manager role | No | No | No | No | Yes | |||||