> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# GitHub

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/github.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=197c81811dbbdfe03b90b954fea0e08f" alt="" noZoom width="24" height="24" data-path="images/connectors/github.svg" />

  <h1>GitHub</h1>
</div>

## Connection

Connecting sends you to GitHub to approve Klef's access.

### Permissions

Minimum permissions the connection requires.

| Capability               | Required | Granted by (any one)       |
| ------------------------ | -------- | -------------------------- |
| Read members             | Yes      | `Members (read)`           |
| Manage members and teams | Yes      | `Members (read and write)` |

## github.member

### Fields

| Field              | Type             | Required | Description                                                           |
| ------------------ | ---------------- | -------- | --------------------------------------------------------------------- |
| `login` (Username) | string, up to 39 | Yes      | The person's GitHub username. The account belongs to them.            |
| `member`           | bool             |          | Whether the person belongs to the organization.                       |
| `role`             | enum             |          | Role in the organization. Values: `member` (Member), `admin` (Owner). |
| `teams`            | grant            |          | Teams the member belongs to. One row grants one team.                 |
| `teams[]`          | string           |          | Team slug.                                                            |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in GitHub, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field   |
| ------------- | -------------- |
| `login`       | `worker.login` |

## Examples

### Engineering access

The engineering group, a seat on the GitHub engineering team and the incident channels, with GitHub removed when they leave.

```hcl theme={null}
stage active {
  target github.member {
    login  = lookup(table.github_usernames, worker.business_email)
    member = true
    role   = "member"
    teams  = ["engineering"]
  }
}
```

### Leaver offboarding

Ask the manager to plan the handover, then close Microsoft, Slack and GitHub access on the last day and tell security.

```hcl theme={null}
stage terminated {
  target github.member {
    login  = lookup(table.github_usernames, worker.business_email)
    member = false
    teams  = []
  }
}
```
