Skip to main content
Pullfrog takes every permission from GitHub. There is no user list, invite step or seat to manage: a teammate signs in with GitHub and sees the organizations and repositories they can already reach.
The organization console as an org member, with the Billing card locked

Roles

Each repo role includes the ones above it, so an admin can do everything a write user can. Organization roles are separate from repo roles: an org member still needs write access to change a repo’s settings. On a personal account, the account owner holds every role.

Notes

  • Repo setup. Adding pullfrog.yml needs write access to that repo, not an organization role. The commit is made as you; if the default branch is protected, Pullfrog opens a pull request from pullfrog[bot] instead. A private repository in an organization still needs a plan that covers it.
  • Locked cards. A card you cannot edit stays in place with a lock icon and a short message naming who can change it, so links into the console still resolve. The API enforces the same rules, so billing data never reaches a non-owner’s browser.
The Billing card as a non-owner sees it, with the ask-an-owner message
  • Organization-wide reach. Organization standing instructions and flags apply to every run in every repository of the organization, including flags that set the model or timeout. Any org member can edit them; outside collaborators cannot.
  • Org owners. Pullfrog reads the owner role from GitHub again before billing changes instead of trusting a cached value. GitHub’s API calls this role admin.