GitHub workflow · Controlled pilot

Private-code assessments without broad repository access.

This page explains the workflow publicly. Connecting a repository remains restricted to an approved organization, eligible Business workspace, and explicit codebase-pilot approval.

Step 1

Approve the pilot

Buglyst confirms the organization, Business entitlement, security configuration, and permitted use.

Step 2

Choose an exact scope

Your team selects a repository, commit SHA, and explicit included and excluded paths.

Step 3

Scan and retrieve briefly

A short-lived read-only token retrieves only approved files after secret and file-policy checks.

Step 4

Review a private draft

Generation produces a frozen draft for technical and company review before any candidate can receive it.

Exact scope

Your team chooses the repository, commit SHA, and allowed paths.

Read-only access

Short-lived read tokens are never stored by Buglyst.

Approval required

Generated drafts stay private until your team approves them.