GOVERNANCE_SPECIFICATION

Governance that auditors love and developers don't feel

DevHub was built governance-first: least-privilege roles, mandatory approvals for risky operations, and an audit log that answers 'who did what' instantly.

Talk to us about Enterprise

Role-based access control

Nine organization roles scope exactly who can read, write, review, approve and deploy. Permissions are enforced server-side on every operation.

Complete audit trail

Every action — commands, merges, deploys, even denied attempts — is recorded with actor, capability, risk level, result and duration. Nothing is off the record.

Approval workflows

Production deployments, protected merges and mutation commands require explicit approval from authorized roles, stored with reason and expiry.

Risk classification

Every capability carries a P0–P4 risk level. High-risk operations demand stronger roles and confirmations; read-only operations stay frictionless.

Organization management

Group repositories and members under organizations with per-org membership and roles — clean boundaries between teams and clients.

Your own execution runner

Code never executes on DevHub's infrastructure. You connect your own isolated runner with a fixed operations allowlist and bearer-token auth.

ROLE_MATRIX

OwnerAdminSecurity AdminDeveloperReviewerDeployment ApproverAuditorProject ManagerViewer