GitHub App access remains limited to the repositories selected during installation
Setup path
Setup remains administrator-controlled inside the authenticated workspace.
Authorize the GitHub connection
Choose the organization or approved App installation
Run the first read-only collection
Review the resulting checks and proposed evidence
Collection limitations
A limited or failed read stays visible and never becomes a passing result.
Results cover only organizations and repositories visible to the authorized connection
Collection of repository, branch-protection, and Dependabot data follows documented resource and reporting limits
Unavailable permissions are reported as limited coverage, not a passing result
Disconnect and deletion behavior
An administrator can disconnect the integration. vCISO.ai removes stored access locally, expires connector-derived evidence, and records the change. GitHub authorization can also be removed in GitHub.
Existing historical records remain available as review history
Connector-derived evidence is marked expired when the source is disconnected
Disconnect is organization-scoped and audit logged
A provider observation can support a control only after the right relationship and evidence are reviewed. Connecting GitHub does not automatically verify a control, complete a framework, or produce an audit conclusion.
Start with the roadmap
Put GitHub into a prioritized readiness plan.
Build the free roadmap first, then activate the AI vCISO when you are ready to connect the provider.