Security and access

Understand repository scope, team access, webhook security, and data boundaries.

Fullbeam keeps access within the selected GitHub repositories and the connected team workspace.

Repository access

  • The GitHub App can access only the repositories selected during installation.
  • Fullbeam also checks workspace entitlements when a user opens a PR Story.
  • A copied link does not grant access to someone who is not entitled to the repository.
  • Removing a repository or uninstalling the GitHub App stops future events for that repository.

Team roles

Workspace owners manage the GitHub connection, members, policies, Harness Packs, assignments, and rollouts. Members use the workspace features allowed by their role.

Webhooks and runtime data

  • GitHub webhook signatures are verified before events are processed.
  • Raw local agent transcripts are not required for GitHub-only PR review.
  • Runtime sources can be unavailable or redacted without blocking diff-based analysis.
  • Citations connect AI explanations to changed lines; GitHub and the diff remain authoritative.

Use the Security page for the current security and data-handling summary.