Teams and enterprise
Roll out Lobby with clear identity, repository, workspace, and security boundaries.
Lobby organizes work around an account and the GitHub repositories each person is allowed to use. Start with a small team and one repository, verify the access boundaries below, then expand the rollout.
Roll out a team
- Choose an account owner. The owner manages roles; owners and admins can invite members.
- Invite a pilot group. Each person accepts the invitation using the invited email address and selects the team account.
- Connect one GitHub repository. Install the Lobby GitHub App on selected repositories. Each person also needs their own GitHub authorization.
- Run a shared task. Confirm the intended members can open the conversation, and that read-only and no-access users cannot edit or open it.
- Review the operating boundaries. Decide whether Lobby’s current workspace, network, credential, regional, and revocation behavior fits your requirements before adding more repositories.
Continue with Identity and access and Security and connectivity.
Current administration model
| Concern | Current owner |
|---|---|
| Membership, invitations, roles, account switching | Lobby |
| Repository selection | Lobby GitHub App installation |
| Each person’s repository permission | Their GitHub authorization |
| Conversation visibility | Shared by default; private conversations stay with their creator |
| Source publication | GitHub, after Lobby rechecks write access |
| Cloud workspace region | Selected when a shared project is created |
Lobby currently uses invitations and the owner, admin, and member roles described in Identity and access. It does not currently expose customer SSO, SCIM, domain-based enrollment, audit-log export, or device-management policy. Do not plan a deployment around those controls until they are documented here.
Evaluate before a wider rollout
- Confirm which repositories the GitHub App may access and which people have personal access.
- Use private conversations for work that must not be visible to other account members.
- Treat people sharing a project workspace as trusted peers on its checkout, Docker daemon, localhost network, and persistent volume.
- Keep secrets out of repositories and agent prompts. Use supported managed-service credentials where available.
- Review Security and connectivity before relying on private services, data residency, or immediate revocation.