Security / GitHub

What Planloom can see in your GitHub.

Planloom connects through a GitHub App you install on the repositories you choose. GitHub stays the source of truth; Planloom keeps references and compact snapshots so cards stay readable.

Repository permissions

PermissionAccessWhy
MetadataRead-onlyGranted by GitHub to every app. Lists the repositories you chose to share.
ContentsRead-onlyNeeded to show commits and repository context on repository and commit cards.
Pull requestsRead-onlyNeeded for pull request cards, reviews and review comments, and the review-queue board.
ChecksRead-only, optionalLets pull request cards show CI status. If you do not grant it, cards simply omit CI status.

No account-level permissions are requested.

How access is handled

  • You choose which repositories to share. Selected-repository installs are preferred; sharing every repository in an organisation is an explicit choice for an administrator.
  • Only Co-Space owners and admins can start a connection. The installation request is single-use and expires after ten minutes.
  • Planloom verifies with GitHub that the installation belongs to the person connecting it.
  • Short-lived installation tokens are kept in server memory only and refreshed before they expire.
  • Planloom does not clone your repository. It stores references and compact snapshots for the cards on your canvas.
  • Planloom does not write to GitHub without an explicit action from you.
  • Linked tasks can move to Done automatically when the pull request that delivers them is merged.

See the security overview for encryption and AI data flow, or how GitHub works on the canvas. You can revoke access any time from your GitHub installation settings.