GitHub permissions explained
Markdown
JSON
Why we request the permissions you'll see when connecting GitHub to Escape Velocity.
Read permissions: Read your code, pull requests, and CI results
Escape Velocity understands your product by reading files, discussions, metadata, task tracking, and alerts. This information is used to ground understanding in your product, how the product is run and secured - and to help produce regular proposals for improvement.
Permission
Access
Purpose
metadata
Read
Reads the names, descriptions and settings of the repositories you pick, so you can choose which ones to connect. GitHub attaches this to every app.
issues
Read
Reads issues and their comments. Teams record decisions there as often as in documents, so issues often hold the reasoning.
checks
Read
Reads whether your checks passed on a commit, so work is only put in front of you once checks pass.
statuses
Read
Reads commit status from older CI integrations, which is how some repositories still report a build result.
members
Read
Maps commit authors to the people on your team, so a teammate is told apart from a bot.
discussions
Read
Reads GitHub Discussions, where many teams work through a design before an issue exists.
deployments
Read
Reads your deployment history, so what is actually running is known rather than assumed from the default branch.
environments
Read
Reads your configured environments, so staging and production are told apart.
packages
Read
Reads the packages published from your repositories, which is how a library release is distinguished from an application deploy.
repository_projects
Read
Reads the project boards attached to a repository, which carry the order of work that commits alone do not show.
organization_projects
Read
Reads the project boards your organization owns, where planning that spans several repositories usually lives.
organization_custom_properties
Read
Reads the custom properties your organization sets on repositories, which many teams use to mark tier, owner or lifecycle.
issue_types
Read
Reads the issue types your organization defines, so a bug is told apart from a feature in your own vocabulary rather than a guessed one.
issue_fields
Read
Reads the custom issue fields your organization defines, which carry the priority and sizing your team already agreed on.
administration
Read
Reads repository settings such as branch protection, so work is proposed the way your rules require instead of failing against them.
security_events
Read
Reads code scanning alerts, so a security finding is surfaced alongside the work that touches the affected code.
secret_scanning_alerts
Read
Reads alerts about secrets found in your code, so an exposed credential is raised as urgent rather than sitting in a list nobody opens.
vulnerability_alerts
Read
Reads Dependabot alerts about vulnerable dependencies, so an upgrade is proposed against a real advisory rather than as a routine version bump.
Write permissions: Open pull requests, update branches, and re-run checks
Escape Velocity opens a pull request for your review and never merges without your approval.
Permission
Access
Purpose
contents
Read and write
Commits to a branch Escape Velocity opened for you, never to yours. Also reads your files at a specific commit, to understand your notes and documents.
pull_requests
Read and write
Opens a pull request for your review, and merges one you approved. Also reads each pull request's changes, reviewers and discussion, to learn how your team works.
workflows
Read and write
Changes files under .github/workflows when you ask for a change to your CI, which cannot be done through an ordinary commit. No automated job is ever given this.
actions
Read and write
Re-runs a check on a pull request Escape Velocity opened, so a flaky failure does not need you. Also reads your workflow run history, to tell a flaky check from a real failure.
What Escape Velocity will never do
We value your trust and hold ourselves accountable to these commitments.
Our commitment
Our enforcement
We will never merge anything you have not approved
Merging runs only against a pull request you approved, with a token carrying pull_requests write and checks read, and no contents grant at any level.
We will never change your CI without you asking
No least-privilege scope grants workflows, so no automated job can mint a token that carries workflows. A CI change happens only when you ask for one.
We will never access a repository you did not choose
Only the repositories you select are visible to Escape Velocity, through GitHub's own installation scope. You can change which ones at any time.
© 2026 Escape Velocity AI, Inc.
2261 Market Street, STE 71349, San Francisco, CA 94114