Docs

Reconcile repository access with reporting

Repos starts with the repositories granted to the RepoOps GitHub App, then places telemetry, a published brain, 30-day cost, current open risks, and collaborator observations beside that inventory. A row proves App access, not that every reporting source has arrived.

For: the team owner or administrator connecting GitHub and reconciling keys, and the member checking which evidence has arrived

What it does, and why it helps

Connect your GitHub account, then install the RepoOps GitHub App on an organization you control. RepoOps stores each granted repository by GitHub id and a lowercased owner/repo key. Installation events add, update, rename, and remove inventory rows. The table shows Owner, Visibility, Default branch, Last activity, Telemetry, Brain, Cost (window), Open risks, and Link.

Those columns do not share one source. Inventory comes from GitHub. Desktop telemetry and brain publishing use the local repository id from repos.config.json. Cost is a 30-day rollup. Open risks come from the latest risk row. RepoOps tries the full GitHub key, the basename, and explicit local slug links. A missing match stays unknown.

The pain. A GitHub App can see a repository while desktop telemetry, brain, cost, or risk evidence is absent. A local id can also differ from the GitHub name, leaving real reports unmatched.

The point of view. Inventory access and reporting coverage are separate facts. Read each source on its own terms, then reconcile repository keys before deciding that a source is missing.

What gets easier. Finding the gap. One row distinguishes GitHub metadata from activity, brain, cost, and risks. The detail page adds rollup scope and recorded collaborator access.

When it helps. After connecting an organization, while onboarding a repository, when a column stays blank, before using a rollup, or when a manager needs a current GitHub collaborator observation.

Its limits. The list does not infer coverage from App access. Telemetry events count all stored telemetry rows even though the detail label says Telemetry events (window); only cost has the coded 30-day window here. Collaborator observations do not establish grant origin, tech-stack access, or incident cause.

Understand it in 30 seconds

30.1 s, captions on. Narration: Microsoft Zira Desktop (provisional voice; an approved narration source is pending).Transcript
Read the narration
  1. 0:00 A repository row can look monitored before any machine has reported from it.
  2. 0:06 Treat GitHub access and reporting coverage as separate facts, then reconcile their keys.
  3. 0:13 RepoOps joins GitHub inventory with telemetry, brain, cost, and current risk stores.
  4. 0:19 Owners and admins link local slugs; gaps stay blank.
  5. 0:23 Open the repository, verify scope, then investigate whichever source is still missing.

Synthetic example. Read the guide

Where to find it

  • Hosted: repoops.ai/team/repos, from Repositories in the sidebar, under Workspace tools.
  • Desktop: hosted only.

When to use it

A connected repository has blank reporting columns

Situation. The App inventory contains acme/service, but the desktop reports that checkout as service-api.

What you do. As an owner or administrator, use Link telemetry to bind service-api, then open the detail page.

What you see. The row can join evidence held under service-api. The control reads linked: service-api and offers unlink.

What it establishes. The keys are explicitly reconciled. Any column still blank represents a source gap, not proof that the repository was never connected.

Choose what may enter a rollup

Situation. A repository should stay outside team totals or be eligible for the wider company view.

What you do. Open the repository and set Repo rollup scope to personal, team, or company. Reset to default clears the override.

What you see. An absent scope resolves to team. Personal is excluded from rollups; company stays in its team rollup and is eligible for the company view.

What it establishes. Rollup readers receive the intended scope. The inventory row remains because App access and rollup scope are separate.

Review current repository collaborators

Situation. A manager needs GitHub's current effective roles and recent stored observations.

What you do. Choose a Repository. Use Load observations, or Refresh from GitHub for a new provider read.

What you see. Observed collaborators lists Identity, Type, and Effective role. Observation history exposes up to the latest 20 stored rows.

What it establishes. The manager has a dated provider observation, not an exact permission-change time or proof of who caused an event.

Before you start

Supported versions
RepoOps v0.3.1. This is a hosted surface; the desktop has an On repoops.ai pointer rather than a local inventory page.
Where it runs
Hosted at /team/repos, Repositories under Workspace tools in the sidebar. The dashboard requires a signed-in account, an entitled hosted, team, or enterprise subscription, and a paid seat for non-owner members.
Permissions
A signed-in user may start connection. Link telemetry, Repo rollup scope, and collaborator reads or refreshes require owner or administrator. Members can read inventory and detail without those controls.
Connections
A GitHub account connection is required before App installation. The callback verifies that the signed-in GitHub user controls the installation. The App must be granted each expected repository.
Plan
The shared hosted layout admits active hosted, team, and enterprise plans. Collaborator observations persist only for hosted, team, or enterprise teams whose subscription is active or trialing.

Configure it

  1. Connect your GitHub account.

    Press Connect your GitHub account. The App callback needs that connection to verify installation ownership.

  2. Grant repository access to the GitHub App.

    Press Connect your GitHub organization and choose repositories in GitHub. RepoOps reads pages of 100, up to 50 pages, and stores their GitHub metadata.

  3. Read coverage columns independently.

    A row confirms inventory only. A dash means no joined source row, except Telemetry also renders a stored zero as a dash.

  4. Reconcile a local slug when needed.

    RepoOps saves an unambiguous basename match automatically. A manager uses Link telemetry for the remainder. One inventory repository may have several local slugs.

  5. Set repository sharing scope.

    Open the repository and choose personal, team, or company. The default is team. Reset to default clears the stored override.

  6. Load collaborator observations when they answer the question.

    Load observations reads stored rows. Refresh from GitHub stores a new row. Refresh is limited to six requests per minute per team; the sweep selects at most five due repositories and revisits after one hour.

SettingWhereA sensible choiceWhy it matters
Connect your GitHub accountRepos empty stateThe account that controls the installationThe callback verifies ownership and fails closed without this connection.
GitHub App repository accessConnect your GitHub organization, then GitHub's pickerOnly the repositories this team should inventoryThe table follows what the installation can see.
Link telemetryRepos table, Link columnA confirmed local repos.config.json idThe alias is an additive join key. A wrong link can sum unrelated evidence.
Repo rollup scopeRepository detail, Repository sharing scopeteam (default), personal, or companyIt controls which rollups may include the repository.
Refresh from GitHubCollaborators and repository accessLoad stored rows first; refresh when current access mattersA refresh stores a dated complete, partial, or unavailable observation.
ⓘ
To stop or undo
Use unlink to clear a slug link and Reset to default to clear scope. Change or remove repository access in the GitHub App to remove inventory after the signed webhook arrives. No direct inventory refresh or one-row delete control is provided in RepoOps.

What you should see

Inventory present, reporting absent

Configuration. The App sees acme/service, but no source matches its key, basename, or aliases.

Expect. GitHub metadata appears while activity, brain, cost, and risks remain blank or unknown.

Verify. Open the repository. Telemetry events reads Unknown, Brain published reads Not received, and cost stays unknown until a rollup arrives.

A slug link reconciles sources

Configuration. service-api is bound to acme/service and source rows exist.

Expect. The row includes service-api. Multiple candidate keys are added for events, cost, and risks; brain is combined; newest activity wins.

Verify. The Link cell reads linked: service-api. Unlink any mapping that combines keys you did not intend.

GitHub access is only partly observable

Configuration. A collaborator request stops at a provider error, rate limit, or the 5,000-record bound.

Expect. Status is complete, partial, or unavailable. Prior observations remain.

Verify. Read status, reason, time, and history. Do not infer grant origin or access after that timestamp.

Data and cost

What is captured
RepoOps stores the installation mapping and repository id, name, owner, visibility, default branch, key, URL, archive flag, and timestamps. Optional rows store slug links and rollup scope. Collaborator snapshots store provider ids, logins, actor types, effective roles, status, reason, and time.
Who can see it
Reads are team-scoped. Any entitled team member can read inventory and detail. Only owners and administrators can link slugs, change scope, or load and refresh collaborator observations. The inventory page itself queries the whole team inventory; per-member repository scope applies in downstream rollup readers.
How long it is kept
Inventory remains while App access is granted and is removed by signed removal events. Cost reads 30 days. Collaborator history returns the latest 20 rows, but no retention or purge control for its stored table is provided.
What leaves the machine
RepoOps uses short-lived installation tokens with GitHub to list repositories and collaborators; tokens are not persisted. This page makes no model call. Reporting sources arrive through their own publish paths.
What it costs
No separate model cost is created. The feature uses GitHub API calls and hosted storage. Access follows hosted subscription and seat checks. Cost (window) is reported repository spend, not the cost of opening this page.

When the result differs

SymptomLikely causeNext action
The page asks for a GitHub account before the organization.The signed-in account has no GitHub user connection.Connect the account first, return to Repos, then connect the organization.
The App is installed, but no repositories appear.Access is pending, no repositories were granted, or no usable event reached inventory.Read the banner, confirm the GitHub grant, and wait for sync. No direct refresh button is provided.
A repository appears, but reporting stays blank.No source arrived, or the local slug differs from both GitHub keys.Confirm desktop publishing, then use Link telemetry only after confirming the offered slug.
A total looks too high after linking.Full name, basename, and aliases are additive, so overlapping rows can be counted together.Inspect each linked slug, unlink the wrong one, and compare the remaining keys.
Telemetry events says Unknown when zero was expected.The UI shows a count only above zero, so zero and no match share the empty state.Treat the value as not established and inspect Telemetry before concluding it is zero.
Collaborator refresh is partial or unavailable.GitHub was unreachable, denied or rate-limited the request, returned bad data, or reached the page bound.Keep the dated status and reason. Retry later; prior observations remain.
Disable
Remove or narrow access in the GitHub App. Signed removal events delete inventory rows. Removing an installation deletes its mapping and inventory rows.
Roll back
No inventory version rollback is provided. Use unlink for an alias or Reset to default for scope. Restore a removed repository by granting it to the App again.
Revoke access
Revoke repository access or uninstall the RepoOps GitHub App in GitHub. Disconnecting the user account does not revoke the App installation grant.
Delete
Not provided as a RepoOps one-row control. Inventory deletion follows GitHub events. No purge control was found for collaborator observations, aliases, or scope rows; those tables cascade when the team is deleted.

Maintenance evidence

Feature id
repos (spine leaf repos)
Owner
GitHub connect program, Phase 2 company repository rollup. Guide: LDG-0717.
Supported product version
RepoOps v0.3.1
Last verified
2026-09-15, read against origin/main at 52366bb6d; labels read from the served hosted page source; install, sync, join, scope, access and plan modules checked
Example fixtures
website/lib/github/repos-sync.test.ts; website/app/api/github/install/install-security.integration.test.ts; website/app/api/team/repos/repos.integration.test.ts; website/lib/github/repo-activity.test.ts; website/lib/github/repo-activity-cost-risk.integration.test.ts; website/lib/github/repo-key-alias.test.ts; website/lib/repo-scope.test.ts; website/lib/github/collaborator-inventory.test.ts; website/lib/repository-access.integration.test.ts; website/lib/github/repository-access-sweep.integration.test.ts
Source references
lib/canonical-spine.json, lib/canonical-tabs.mjs, website/app/team/(home)/repos/page.tsx, website/app/team/(home)/repos/[repo]/page.tsx, website/lib/github/repos-sync.ts, website/lib/github/repo-activity.ts, website/lib/github/repo-key-alias.ts, website/lib/cost/cost-rollup.ts, website/lib/risk/risk-rollup.ts, website/lib/repo-scope.ts, website/lib/repository-access.ts, website/lib/github/collaborator-inventory.ts, website/lib/github/repository-access-sweep.ts, website/components/repository-access-panel.tsx
Documentation review
Independent review requested on the slice pull request; not yet recorded.
Video review
Narrated story rendered and published 2026-09-26 (render 46b026a5a3b8, LDG-1012) with the breadcrumb Repositories, checked against main at b0bb02812. Six frames, the captions and the transcript were reviewed by the authoring agent, not an independent reviewer; the audio was not listened to by a person. Narration is the provisional Windows voice until LDG-0721.

Last updated