Verified source-access workflow
Submit identity and intended use, accept the Community Source rules, receive manual owner review, and receive a manual GitHub invitation after approval.
Application
The applicant provides legal identity, email, GitHub username, country or region, intended use, technology domains, expected users, contribution intent, recognition preference, and organization information when applicable.
Do not submit customer incidents, credentials, logs, tickets, private architecture, export-controlled information, or secrets.
Consent record
The applicant checks the current Community Source acknowledgements and types the same legal name entered in the identity section.
The application records:
- Rules version
- Typed legal name
- Consent time
- No-unapproved-commercial-use acknowledgement
- No-redistribution acknowledgement
- No-unapproved-product-integration acknowledgement
- Confidentiality acknowledgement
- Manual-approval acknowledgement
- Privacy consent
- Accuracy confirmation
Manual review
The owner checks identity, organization, intended use, access category, expected users, GitHub username, contribution plans, organizational authority, recognition preference, and risk concerns.
Manual invitation
After approval, the owner sends the invitation directly through GitHub. OGO Admin records invited, active, role, review, and revoked states but does not call GitHub.
Least privilege
Most adopters and evaluators begin with Read. Contributors normally begin with Triage. Write is limited to active implementation. Maintain is limited to trusted maintainers.
Recognition
Public recognition is separate from source access. Private and ask-later choices must not be published.