Permissions

Limit the GitHub and Ellipsis operations a session can perform.

Permissions limit what a session's GitHub and Ellipsis credentials can do. The environment decides which repositories are checked out and which secrets are set.

Read-only GitHub access

1
session:
2
claude_code:
3
model: claude-opus-5-5
4
permissions:
5
github:
6
repositories: [api-repo]
7
permissions: read_only

The agent can read api-repo but can't push commits or comment on issues and pull requests. It can still edit files in its sandbox.

Allow code and pull request changes

1
session:
2
claude_code:
3
model: claude-opus-5-5
4
permissions:
5
github:
6
repositories: [api-repo]
7
permissions:
8
contents: write
9
pull_requests: write
10
issues: read

Use this for tasks that push a branch and open a pull request. Permissions can't exceed what the GitHub App is installed with.

permissions.github.repositories limits the credential; environment.repositories decides what is checked out. Set both when you need both.

Limit Ellipsis access

1
session:
2
claude_code:
3
model: claude-opus-5-5
4
permissions:
5
ellipsis:
6
sessions: read
7
environments: read
8
secrets: read

Anything not listed is denied. write includes read, and delete includes both. Reading secrets returns their names, never their values.

Secrets

The agent and its tools can read every secret the environment sets, and GitHub permissions don't limit what those credentials can do. Keep secret values out of prompts, committed YAML, and command output; session logs record what tools print.

On this page

Schedule a demo