GOVERNANCE_SPECIFICATION
Governance that auditors love and developers don't feel
DevHub was built governance-first: least-privilege roles, mandatory approvals for risky operations, and an audit log that answers 'who did what' instantly.
Talk to us about EnterpriseRole-based access control
Nine organization roles scope exactly who can read, write, review, approve and deploy. Permissions are enforced server-side on every operation.
Complete audit trail
Every action — commands, merges, deploys, even denied attempts — is recorded with actor, capability, risk level, result and duration. Nothing is off the record.
Approval workflows
Production deployments, protected merges and mutation commands require explicit approval from authorized roles, stored with reason and expiry.
Risk classification
Every capability carries a P0–P4 risk level. High-risk operations demand stronger roles and confirmations; read-only operations stay frictionless.
Organization management
Group repositories and members under organizations with per-org membership and roles — clean boundaries between teams and clients.
Your own execution runner
Code never executes on DevHub's infrastructure. You connect your own isolated runner with a fixed operations allowlist and bearer-token auth.
ROLE_MATRIX
