Skip to content

GitHub Access Policy

This policy defines the access control framework designed to protect the confidentiality, integrity, and availability of our codebase and repository resources.

This policy applies to all employees, contractors, consultants, temporary staff, and other workers at Cadence OneFive who require access to GitHub repositories. It encompasses all repositories created, maintained, or utilized for Cadence OneFive business operations.

  1. All access to GitHub repositories must follow the principle of least privilege
  2. Default access state for any team member is no access
  3. Access must be explicitly granted based on job function requirements
  4. Access rights must be reviewed quarterly
  5. Access must be revoked during off-boarding

Cadence OneFive organizes repository access through the following team structure:

  1. All Perm Staff: For handbook access only, no direct repository access by default
  2. Code Committers: Parent group with all-repository write access for all development teams
    • Momentum Coders: Application development team (inherits write access from Code Committers)
    • Data Service Coders: Knowledge base and data services team (inherits write access from Code Committers)
  3. QA: Quality assurance team with all-repository triage access
  4. Security: Security oversight team with security manager role
  5. Auditors: Placeholder team with all-repository read access for security auditors (e.g. during SOC2 audit)
  • All-Repository Write: Grants write access to all repositories
  • All-Repository Triage: Grants issue management capabilities without write access
  • All-Repository Read: Grants view-only access to repositories
  • Security Manager: Grants ability to manage security policies, alerts, and configurations

Access is controlled exclusively through Organizational Roles and group membership, not direct access to individual repositories.

  1. Access to GitHub repositories will be granted during the onboarding process, based on team role and responsibilities:
    • Developers should be added to specific coding teams:
      • “Momentum Coders” for those working on the main application
      • “Data Service Coders” for those working on data services and knowledge base
    • QA personnel should be added to the “QA” team
  2. All permanent staff should be added to the “All Perm Staff” team for handbook access
  3. GitHub access must be removed as part of the offboarding procedure when a team member leaves the organization
  4. All provisioned access must be documented in the user onboarding checklist
  5. Team membership changes must be processed promptly when a team member changes roles

Auditors are added to the Auditors team only when access is required as part of the audit process and promptly removed. Auditor access is managed by CISO.

This policy will be reviewed annually and updated as necessary to reflect changes in technology, business practices, and regulatory requirements.

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.