Chapter 24 · build contribute

Verified source-access workflow

Submit identity and intended use, accept the Community Source rules, receive manual owner review, and receive a manual GitHub invitation after approval.

1 min read·Updated 2026-07-26·3 role paths
01

Application

The applicant provides legal identity, email, GitHub username, country or region, intended use, technology domains, expected users, contribution intent, recognition preference, and organization information when applicable.

Do not submit customer incidents, credentials, logs, tickets, private architecture, export-controlled information, or secrets.

02

The applicant checks the current Community Source acknowledgements and types the same legal name entered in the identity section.

The application records:

  • Rules version
  • Typed legal name
  • Consent time
  • No-unapproved-commercial-use acknowledgement
  • No-redistribution acknowledgement
  • No-unapproved-product-integration acknowledgement
  • Confidentiality acknowledgement
  • Manual-approval acknowledgement
  • Privacy consent
  • Accuracy confirmation
03

Manual review

The owner checks identity, organization, intended use, access category, expected users, GitHub username, contribution plans, organizational authority, recognition preference, and risk concerns.

04

Manual invitation

After approval, the owner sends the invitation directly through GitHub. OGO Admin records invited, active, role, review, and revoked states but does not call GitHub.

05

Least privilege

Most adopters and evaluators begin with Read. Contributors normally begin with Triage. Write is limited to active implementation. Maintain is limited to trusted maintainers.

06

Recognition

Public recognition is separate from source access. Private and ask-later choices must not be published.