Skip to content
Lobby
Esc
navigateopen⌘Jpreview
On this page

Identity and access

Understand Lobby accounts, team roles, GitHub authorization, and revocation.

Access to repository work requires two independent checks: membership in the selected Lobby account and the person’s own permission to the GitHub repository. Installing the Lobby GitHub App does not give every account member repository access.

Add and manage members

Open Members from Lobby to manage team membership and invitations.

  • Owners can invite members and change joined members between member and admin.
  • Admins can invite members.
  • Members can collaborate within the repositories their own GitHub account permits.

Invitations are sent for the member role. The recipient must sign in with the invited email address and accept before they join. If a person belongs to several accounts, use the account switcher before opening team work.

Connect repository access

An owner or administrator selects repositories when installing the Lobby GitHub App. Each teammate then authorizes their own GitHub account. Lobby checks that person’s current repository permission when they open a conversation, send work, use source control, access attachments, or publish.

Repository readers can inspect shared work and ask read-only questions. Repository writers can edit and publish. A shared run cannot borrow broader rights from the person who started it or from another contributor.

Choose conversation visibility

Shared conversations are visible to members who also pass the repository check. Private conversations are visible only to the person who created them and use an isolated workspace. Shared project workspaces do not support private conversations.

Remove access

Remove a person from the Lobby account and remove or reduce their GitHub repository permission when both boundaries should close. Lobby rechecks GitHub rights on protected operations and publication.

Some browser grants and live connections refresh on bounded intervals rather than instantaneously. Removing active account membership during an already running agent turn is not currently documented as immediate revocation. For urgent containment, also revoke the underlying GitHub or customer-cloud permission and stop the affected work.

Lobby does not currently provide customer SSO, SCIM, verified-domain enrollment, or device policy. See Teams and enterprise for the supported rollout path.

Was this page helpful?