Setting Up Accounts
Before we can start learning and demonstrating all of the major concepts that you'll need to know in order to be an effective Github admin, we'll need a solid test setup. In this video, we see how to create 2 accounts, one organization, and one enterprise, all of which we'll be using for the rest of the course.
Knowledge Check
In order to create an enterprise or organization, we must create an entirely new Github account - i.e. you can't create these under your personal Github account.
Personal Accounts vs. Managed Users
Now that we have a good setup for all the demonstrations we'll be doing in this course, let's move on to the first important choice that you'll have to make when managing a Github enterprise: should you use personal accounts or managed users? In this video, we'll talk about what these are and how they differ.
Knowledge Check
When you were hired at Acme Inc., your accounts for Github, Gmail, Slack, and so on were set up for you by the company. This most likely means the company is using __________.
A Closer Look At Managed Users
Next, let's go into a little more detail on the implications of choosing to use personal accounts or managed users in a Github enterprise.
Knowledge Check
Which of the following can a managed user account do on Github?
A First Look At Enterprise, Organization, and Repo Roles
Finally, with multiple users operating across multiple levels (Enterprises, Organizations, and Repos), we need a way to control who is allowed to do what at each of these levels. For this purpose, Github provides us with something called "roles". Let's take an introductory look at roles and how they work.
Knowledge Check
If someone is the enterprise owner, this automatically makes them the sole admin of all organizations and repos in the enterprise.
Challenge & Solution: Adding Organization and Repo Members
Now it's time for a challenge! In this challenge, you'll need to add the other Github account we set up to the organization and repo. Watch the video for more information.
And now that you've attempted the challenge, I'll show you how to solve it.
Knowledge Check
After adding the user to the organization, but before adding the user directly to the repo, do a quick check - does the user already have access to the repo? If so, what kind of access?
View Transcript
Setting Up Accounts
0:00Hi, Sean here and welcome to this skill where we're going to be taking our first look at the
0:04basics of user identities and authentication from the point of view of a GitHub admin. Now,
0:10because this is the first skill in this course, what we're going to need to do first is get
0:15ourselves set up for all of the demonstrations that will follow. Again, I highly recommend that
0:22you follow along with me here. Ideally, you won't need to put in any of your credit card information,
0:27but that seems to change on a fairly regular basis, whether they let you do a truly free trial
0:32or a free trial where you get 30 days free, but then have to pay for the other 11 months.
0:37Kind of depends on the exact timing that you're watching this, but whatever the case,
0:43if you want to follow along with me in this course, I would highly recommend that you,
0:47you know, walk through the steps that I'm about to show you here because, well,
0:51that'll give you the basic setup that I'll be using. So the first thing that we're going to
0:55need to do here is we're going to create two GitHub accounts. All right. So I'm going to start
1:01here. This is just literally plain old github.com. Chances are you probably already have a GitHub
1:07account. So if you really want to use that as one of the accounts here, um, feel free to go ahead
1:12and do so. I was a little bit hesitant to use my own personal account here, just because I want to
1:16keep the setup as clean as possible as, as close to what you're likely to have as possible. And so
1:22what I'm going to do is I'm going to click this sign up button in the top right-hand corner,
1:26and that will take us directly to this, uh, create your free account screen
1:32where we're going to need to put in our email address and password and username.
1:38Now, honestly, from a demonstration point of view, this is probably one of the more annoying
1:41demonstrations that exists because, you know, you need to either screen share your email address
1:48or create a new email address, which Gmail is not real, um, keen on doing. And so what I'm going
1:53to do here is I'm just going to skip over this part. I'm sure you know how to do this already,
1:58and I'll see you on the other side. And there we go. So here's what I did just so that you're
2:04aware of the current setup that I have. I created this new account called Sean WCBT Nuggets. That's
2:11my username here. And then up here in the very top right-hand corner, if you expand your little
2:16profile dropdown, you can use what they call the account switcher, very apt name. And I have this
2:22other account that I set up actually about three years ago that I forgot about using another email
2:27address. And, uh, so I'm just going to use this one as the other account. So the next thing that
2:33we need to do, and I'm going to use my new shiny account for this is I'm going to create an
2:39organization. Now we'll be talking a lot about organizations in this course, but for now,
2:45literally, it's just going to be a container that we'll use for demonstrations. So I'm going to
2:50open this up. We're going to go down to organizations. And now that we've done this,
2:55we're going to create a new organization by clicking new organization up here in the top
3:00right-hand corner. And now that we've done that, we're going to start off by creating a free
3:06organization. We might need to upgrade again, um, kind of depends on how the GitHub marketing and
3:14pricing strategies have evolved since I've recorded this, but for now, I'm just going to
3:19click on, create a free organization. And what we're going to do here is we're going to say that
3:24this organization for now belongs to my personal account. Now, this is the point at which you would
3:31put in a business or institution. If you're setting this one up for, well, a business or
3:36institution, but because that is not my case, I'm going to enter that in. And in order for this to
3:42work, we're also going to need to enter an organization name. So I'm just going to open
3:45that one up here. We'll call this something like Sean's software ink, something like that, right?
3:51You can feel free to name it, whatever you want. You do not have to use my name. In fact, you
3:55probably shouldn't because well, unless your name is also Sean, it doesn't make a whole lot of sense.
4:00And for the contact email, you're going to need to fill this out. I'm going to fill this out,
4:03but I'm going to skip over this. And once you filled it out and checked the little checkbox
4:08that says, I hereby agree to blah, blah, blah, blah, blah. You should be able to click on next,
4:12which will bring you to this page where it's going to ask you to add organization members.
4:18Now we're going to talk about this in a little bit more detail. Uh, but for now, we're just going to
4:23skip this step and that will bring us to the organization. Now, the last thing that we're
4:28going to do here is there are a lot of features that require you to have, uh, some sort of
4:34enterprise subscription. And just to keep my demos as straightforward as possible in this course,
4:40I'm going to set that up now. And so here's how that works. We're just going to go back
4:44up to the top right-hand corner here. We're going to go down and right underneath organizations,
4:49we're going to click on enterprises and we're going to click on this little start free for
4:5330 days button. Hopefully that still exists for you by the time you watch this video.
4:58And this actually brings us to one of the first things that I wanted to talk about in this skill,
5:02which is the difference between having an enterprise that uses personal accounts and an
5:08enterprise that uses what are known as managed users for now, just to finish our setup though,
5:14we're going to say, get started with personal accounts. All right. So we're just going to have
5:17to fill out all of this information here. So I'm going to call this enterprise, something like
5:22Sean's software enterprise. Notice that that will also automatically generate this enterprise URL
5:29slug down below Sean software enterprise for industry. Here's what we're going to do. We're
5:34going to select, um, let's see your software and internet. Perfect number of employees. We're going
5:39to say zero to 50, which is absolutely true. And then for organization, we're going to choose the
5:45one that we just created here. Sean's software Inc. And now for contact information, I'm going
5:51to skip over this part here. Once again, you're obviously going to fill that in with your own
5:55information, check these things down at the bottom, except for probably this targeted advertising one,
6:01you can leave that blank. And then you're going to click create enterprise. And there we go. Now
6:06it may ask you in the process of doing all of this to verify your email. So if you see that,
6:13just go in and verify your email. It's pretty simple. All right. So that should be all of the
6:17major setup that we'll need for now. So just to review what we have here so far, we have two
6:22accounts that I've created. One is Sean WCBT nuggets. And this is the account under which we
6:27created that organization and the enterprise that we just saw. But there's also this other account
6:33that we'll be using, which is just another personal account that we'll be using for
6:37demonstration purposes. And notice that when we switch to that account, looking at this enterprise,
6:42because this other account isn't part of the enterprise, it shows up as a 404 page here.
6:48We'll talk about that in a little bit more detail later, but anyway, that's the four things that we
6:53have here so far, two personal accounts, one of which owns an organization and an enterprise.
7:00So now that we have all of that set up, we can move on to more interesting things
7:03like user identities and authentication in GitHub.
Personal Accounts vs. Managed Users
0:00All right. Well, now that we've created two personal accounts,
0:02one organization and one enterprise that we're going to be using for the rest of this course,
0:07the next thing that I want to do is talk about our first topic, which is the difference between
0:13personal accounts and managed users. This is a very important distinction to make as a GitHub
0:20admin. And, um, so let's just talk about what this looks like. So first of all,
0:25you may remember that when we created this enterprise and you can see this flow again,
0:29if you go up to the top and click new enterprise, okay, there we go. Remember that we selected
0:34get started with personal accounts. Now, without a doubt, this is the most common approach to use
0:40when creating a GitHub enterprise, but notice that there's another option that we didn't select here
0:46as well, which is to use something called managed users. Now you'll hear these referred to sometimes
0:51as E M U's right. Enterprise managed users that is. And this can be a great way to quickly create
0:59lots of accounts that your company has lots of control over on GitHub. But again, it's not the
1:06most common approach. We'll talk about what it looks like in more detail shortly, but this is
1:11the first thing that I wanted to point out is that we explicitly selected the personal accounts
1:17approach for our enterprise. Now, the interesting thing about this is that there is no way to mix
1:23the account types in your enterprise. So you can't have an enterprise that sort of straddles between
1:28these two and uses some personal accounts and some managed users. Uh, that's just not how GitHub
1:34enterprise is designed. So anyway, if we go back to our enterprise here again, remembering that we
1:41chose the personal accounts option, what this means is that when we want to add users here,
1:47right, let's say that we just hired 10 new developers and we want to add them to our
1:53enterprise so that they can start developing and contributing to projects, things like that.
1:57What we would do is we would have each of those developers create their own account. Here's how
2:02I'm going to draw this. I'm going to draw each of the developers like this, and I'll just draw three
2:06here for the time being. And they're going to create their own account, which I'll draw as this
2:11little like sort of ID card. This is their account. All right. And then what we're going to do is our
2:18enterprise is going to invite their accounts to join, right? So this is our enterprise. We're
2:26going to say, all right, Hey, these people already have accounts. Let's invite them to our enterprise
2:32and give them access to contribute to our projects, things like that. All right. So just
2:36to demonstrate what this looks like from the point of view of both a GitHub admin and a person being
2:42invited, let's just walk through that process real quick. What we're going to do here is we're going
2:46to say, invite enterprise members. We're going to click on that. And then we're going to search for
2:52the other account that we created. So if you created two accounts here, remember that I'm
2:56using this Sean WCBT nuggets account here as the owner of the organization and enterprise,
3:02we're going to invite my other account, the just plain old Sean Wassell account to be a member of
3:09this enterprise. So here's what this is going to look like. We're going to say, invite member up
3:13here in the top right-hand corner. We're going to say, uh, down here, there's this little search
3:18bar. So we're going to search by username, which is just plain old Sean Wassell. There we go.
3:22And there's that account in case you're wondering what you're looking at there. That's me with a
3:28rather long hair and a very long beard. Um, just kind of a humorous photo there. Anyway,
3:33let's select that and we're going to click invite. So again, what just happened there is that
3:39account, right? That Sean Wassell account exists outside this enterprise. Someone else created it.
3:46In my case, I created it, I think about three years ago, and it's just been sitting there,
3:51not part of this enterprise for that whole time. And that as we'll see is the major difference
3:56between personal accounts and managed users. I'll get to that in more detail in just a minute here,
4:01but first let's take a look at this process from the point of view of the user who was invited
4:07to the enterprise. What we're going to do is we're going to switch accounts over to this regular
4:12Sean Wassell account. And once again, because we're on that, uh, Sean software enterprise page,
4:18which this account is not yet part of the account needs to actually, the person needs to actually
4:23accept that invite before they'll be able to see this. We see this four Oh four page. And so what
4:28we're going to do here is just go home where we should see our invite. You may have to search
4:34around for this a little bit. I believe it's actually under, if you go to enterprises here,
4:39you should see that there's this invitation sitting here and there's a button next to it that
4:44says accept. All right. So if we accept this from this personal account that was previously
4:51entirely separate from the enterprise, what that means is that this person is now going to have
4:56access to some degree. We'll talk about that in much more detail throughout this course as well.
5:01Um, but this person is going to have some access to that enterprise. So let's click accept.
5:06And here we are. We're at the enterprise homepage. Now an enterprise, by the way, I probably should
5:13discuss this before we go any further. GitHub has sort of like a hierarchy of constructs that
5:18are used to manage projects and ownership and access, things like that. At the very top of
5:24this hierarchy is something called an enterprise. This is what we created there before. You can
5:31kind of think of an enterprise as like a family of companies, right? That's typically how that
5:36an upside forgot the extra R in their enterprise. Kind of weird having that RPR next to each other
5:42there. It's just a hard thing to write for some reason while I'm talking. But anyway,
5:46this is kind of like a family of companies once again. So presumably, and I don't know if this
5:51is true or not, there's an alphabet enterprise out there under which is a Google organization.
5:58Again, I don't know if that's true, but that's the basic idea of how that works.
6:02So underneath an enterprise, as we already saw is an organization. This represents typically a
6:08single company. And then under that organization, we have typically a series of projects, repos,
6:16things like that, that the company is working on. All right. So if you're confused about the
6:20difference between an enterprise and an organization, really, you can think of an
6:24enterprise as just a container for multiple organizations. And in many ways, that's all it
6:30is. So anyway, now that we've accepted that invitation from the point of view of this
6:35Sean Wassell account, we can go to the organizations tab and sure enough, we can
6:40see Sean software Inc. And if we open that up, we see that it says this organization has no
6:46public repositories. Now we'll be fixing that at some point in the near future. But the point being
6:52that we can now view this enterprise and the organizations that it contains. And if there were
6:58repositories in here, we would be able to access those as well. All right. So anyway, going back
7:03to what I was saying at the beginning of this video, the approach that we just saw acted out
7:08there is the approach of having the developers themselves create their own personal accounts
7:15that will outlive their employment typically, and then inviting those accounts to the enterprise,
7:23right? So you create your enterprise, right? The developers, as I drew out earlier, create
7:30their accounts, which belong to them, right? They could be fired tomorrow. And they would
7:37still have those accounts, although those accounts would typically no longer have access to the
7:42enterprise. But then we just send invites to those specific accounts, giving them access to the
7:49enterprise, the organizations, the repos within reason, of course. So this differs quite a bit
7:56from the other approach that I mentioned, which is the approach of using something called
8:01managed users. Okay. Now, the interesting thing about managed users is you probably already have
8:07some experience with this, just perhaps not with GitHub. So for example, if you have a company
8:12email where it's like, you know, your name, Sean, at whatever company, XYZ Corp.com, for example,
8:22this is typically a managed account, right? The organization, the company that you work for
8:29creates it for you, and it belongs to the organization. They just allow you to log in
8:35and use it, right? And if, so to speak, you decide to move on to other opportunities,
8:41then you leave that account behind when your employment ends, right? In other words,
8:47it's linked to the enterprise itself. Now, in the case of GitHub, let me just kind of
8:52try and illustrate what this looks like. The enterprise itself is going to own those accounts,
9:00right? So here's the accounts that belonged to the users over here on the left-hand side.
9:06The accounts belong to the organization under the managed users way of doing things.
9:12And these three devs, when they get hired, they're merely given access to those accounts,
9:20which in turn give them access to the enterprise and all that it contains. All right. So as you
9:25can see already, there is a very subtle, but very important difference between these two things.
9:30And to put it as simply as possible, it's a matter of ownership, right? Does the enterprise
9:35own the accounts that people use in order to, you know, contribute to repos, things like that,
9:41or do the employees own those accounts? It's as simple as that. Now, one last thing that I wanted
9:46to say about the managed users scheme here is that typically these accounts won't be set up
9:53in GitHub. They'll be set up using something called an IDP, typically abbreviated like that
9:58with a lowercase D. I don't really know why that is, but this stands for identity provider.
10:04And basically an identity provider is just a centralized place for creating and managing
10:10employee accounts. So typically if your organization is going to be using this enterprise
10:15managed user approach, they'll already be using it for a lot of other things as well. So if you have,
10:21you know, if you're using a project management tool like Jira, typically your employer will own
10:26the account that you use for that as well. All right. So anyway, hopefully this video has helped
10:30you to understand the difference between personal accounts and managed user accounts in GitHub.
10:36And as I've already said, personal accounts are still the most common approach for companies to
10:41take with this. And so that's really the main approach that we're going to be taking in this
10:46course as well. Although I will do a few demonstrations with managed users later on
10:51in the course, just for the sake of completeness.
A Closer Look At Managed Users
0:00All right, well, now that we're familiar
0:01with the high-level difference between personal accounts
0:04and managed user accounts,
0:06the next thing that I wanna do is go a little bit deeper
0:08into the details of these two accounts
0:12and what can and can't be done with them.
0:15Because, you know, obviously in the previous video,
0:18I said that the main difference
0:20is that the enterprise owns managed user accounts,
0:25whereas the individual users own personal accounts.
0:29This fact has a lot of interesting implications
0:32for people using these accounts on GitHub.
0:35So let's just kind of start by listing out the things
0:39that we already know about these.
0:40So we're gonna say personal account,
0:42I'm just gonna abbreviate that as PA here,
0:44and then we'll have enterprise account, which will be EA.
0:47All right, so the first thing that we've already seen
0:50is the difference in who creates this.
0:54So I'll write created by.
0:56So as we've already seen,
0:58personal accounts are created by the individual, right?
1:02So the employee, the user, whatever you wanna call them.
1:06Whereas enterprise accounts are created by the enterprise
1:11or company or whatever you wanna call it,
1:15typically via an identity provider, right?
1:18So I'm gonna write that like this.
1:19We'll say enterprise.
1:20Let me try writing that again, enterprise.
1:24And then I'll write this as via IDP,
1:29just like we talked about in the previous video.
1:31All right, now we saw that in addition
1:32to the initial creator,
1:35the account continued to be controlled by that person
1:40or entity as well, right?
1:42So I'm gonna just add that to this created by thing.
1:47We'll say created by, controlled by.
1:49So in both of these cases,
1:51for personal accounts and enterprise accounts,
1:55the person who controls that account, right?
1:57The person who maintains ownership over that account,
2:01even after the employee no longer works
2:04for that company anymore is whoever created it, right?
2:09So with personal accounts,
2:10the account follows the employee
2:12even after they leave the company.
2:14With enterprise accounts, the account stays with the company
2:17and typically the company will just kind of deactivate
2:20that account when the employee leaves,
2:21but they'll still have access
2:23to all of the information that it contains, all right?
2:26So we already know that, but as I said,
2:29there's a lot of other implications of this
2:33that are important to know about as a GitHub admin.
2:36All right, so the next thing that we'll talk about here
2:38is how authentication is handled in both of these cases.
2:42That is a hard word to write while I'm talking.
2:45So there we go, authentication.
2:47In the case of a personal account,
2:50the authentication is handled
2:51just by GitHub's credentials, right?
2:54So as we already saw with a personal account,
2:57the user will have a username and password
3:00that they'll use to log in.
3:01Sometimes they can log in using their personal Gmail account.
3:05You get the idea.
3:06Now, in this case, the enterprise can require
3:10that they use things like two-factor auth,
3:14but the authentication itself
3:15is still handled through GitHub.
3:19Now, on the enterprise side of things,
3:21if you're using managed users,
3:23and actually, let me just write that up here,
3:25managed users, or EMUs is the acronym
3:28that you'll typically see with that
3:30as we talked about earlier.
3:32In this case, authentication will usually be handled
3:36through the enterprise's IDP.
3:39So let's imagine that you have a managed user account
3:43and you wanna log into GitHub.
3:45Well, instead of putting in your GitHub credentials
3:47like you would with a personal account,
3:49GitHub's gonna send you to your company's IDP.
3:53So for example, Microsoft Entra ID
3:56is a very common one to use with GitHub
3:58because they're owned by the same company.
4:00That is Microsoft.
4:01And you would log in there
4:02and it would send you back to GitHub once you do that.
4:05So it's a much more centralized solution.
4:08All right, so beyond authentication,
4:10let's talk about profile, right?
4:12In other words, who manages the information
4:15that's in that profile?
4:16In the case of personal accounts,
4:19it's managed by the user, right?
4:20So the user manages their email address,
4:23any other information about themselves on their profile.
4:26They can manage their profile picture, things like that.
4:30Whereas with managed user accounts,
4:33typically this is the enterprise
4:36and or the IDP that does this, all right?
4:39So enterprise slash IDP, and there you have it.
4:43All right, so moving on,
4:44the next thing that we come to here
4:46is an interesting set of abilities
4:47that only personal accounts have
4:50and that enterprise accounts purposely do not have.
4:54Now, as you'll see,
4:56the common factor between all of these abilities
4:58is that they allow the user through that account
5:02to do things outside the enterprise, right?
5:05So let's start off by taking a look
5:07at how public repositories are handled here.
5:11All right, so if you've been using GitHub
5:13primarily through a personal account,
5:15it might seem kind of obvious to you
5:17that a personal account is able to create
5:21and contribute to a public repository.
5:26And yet over here on the enterprise side of things,
5:29if you're using a managed user account, you can't, right?
5:34In other words, the access of a managed user account
5:38is typically restricted to the enterprise itself.
5:43All right, so I'm just gonna write no here,
5:45but what this means is that managed users
5:47cannot create public repositories.
5:49They can't contribute to public repositories.
5:52And once again, that's intentional.
5:54Typically, when you use managed user accounts,
5:57it's because the organization has
5:59some highly proprietary code or other content
6:03that they want strict control over.
6:06All right, now this also means,
6:07this may be synonymous in many cases,
6:10but if you want to contribute to open source projects,
6:13let's say, then personal accounts are able to do this,
6:19whereas managed user accounts are not able to.
6:23Now this can be inconvenient at times, right?
6:25After all, it is fairly common for employees
6:28to contribute to open source projects
6:30with what you might call ulterior motives.
6:33That is because the organization needs a particular change
6:36or fix to an open source project.
6:39But once again, on the managed user side of things,
6:42this is all done with the ultimate goal of tight control.
6:46In other words, whatever their employee does
6:47outside that organization,
6:49it cannot be through that account, okay?
6:53So anyway, hopefully this helps you to understand
6:56some of the broader consequences
6:58of choosing personal accounts versus managed user accounts.
7:03And so the last thing that I wanna do
7:04is just kind of summarize
7:06when you would use either one of these.
7:09So the typically used case for personal accounts here
7:13is just as a general individual GitHub identity
7:17for personal and professional work, right?
7:20So I'm gonna just simplify what I said there a little bit.
7:24We'll just say something like GitHub identity
7:28for personal and professional work, right?
7:33So in other words,
7:34if your company is using personal accounts,
7:36it's just kind of understood that your employees,
7:38through their personal accounts,
7:39are going to have a life outside of work, so to speak, right?
7:43They might be working on their own GitHub repos,
7:46they might be contributing to open source projects,
7:48and they're doing all of that
7:49through the same account that they're using
7:51to contribute to your company or enterprise.
7:55Now, many companies are fine with this, right?
7:57Especially in the software startup world,
7:59this is a fairly common thing to see.
8:02But in more controlled environments,
8:06that's when you end up
8:07with this whole managed user account thing.
8:10And this, just to sum up what this is
8:12and when you would use it,
8:14we'll write this as a company controlled identity
8:19for tightly managed environments, right?
8:23That's really the main difference here in the use cases
8:28between personal accounts and managed users.
8:33So anyway, hopefully this video has helped you understand
8:35in a lot more detail the differences
8:37between personal accounts and managed user accounts.
A First Look At Enterprise, Organization, and Repo Roles
0:00All right. Well, now that we've taken an in-depth look at the different types of users that are
0:04available in GitHub, right, that is a decision that you have to make very early on, which is
0:09why I spent so much time talking about it. Because again, you can't change an enterprise from one to
0:16the other once you've made that decision and started adding users. And so the next thing that
0:21I want to do here is I want to take a first look at the idea of working with roles across the
0:29different constructs that we've seen so far, right? The fact is that enterprises, as well as
0:34the organizations that they contain, as well as the repos that those contain, all have this idea
0:41of roles as a way of controlling who can do what in a particular construct, right? In a particular
0:49enterprise, in a particular organization, in a particular repo. And by the way, when I say roles,
0:55I'm talking about R-O-L-E-S, lest you haven't had lunch yet and you're hearing me say roles.
1:01That's not the roles I'm talking about. So anyway, the interesting thing about this,
1:06and probably the most important thing to grasp at this point, is that each of the levels that
1:12we've seen so far has its own roles that can be assigned to members of it. So let me just show
1:19you what I mean by that. If we open up our enterprise that we created, and here, let's
1:24just go to invite owners. It doesn't really matter what you click on there. The point is
1:27to get to this screen with the menu over here on the left-hand side. And what you'll see there is,
1:34there's this little dropdown called enterprise roles. And as you can see, there are two menus
1:40here, one for role management, one for role assignments. Now we're going to get into much
1:46more detail on exactly how these things work a little later in the course. But for now,
1:52what I wanted to point out is that the enterprise itself, the highest level of that hierarchy that
1:58we talked about in previous videos, has its own roles that control who's allowed to do what in
2:06the enterprise. In other words, you're not just going to be sharing your username and password
2:12in order to allow everyone at your organization to log into this same thing and perform different
2:18tasks on the enterprise. Please, please do not do that. And so anyway, by managing roles,
2:25you can control, as I said, who is allowed to do what in the enterprise, right? So who's allowed
2:30to add other users to the enterprise? Who's allowed to add new organizations? Who's allowed to
2:36modify the basic information of the enterprise, like the enterprise's name and other info?
2:42All of that is determined by these roles. Now, the other thing about this, right, going down
2:48another level is that the organizations that an enterprise contains each have their own roles
2:55that control who's allowed to do what in a particular organization. Now, for me, this thing
3:01already has a checkmark just because I have clicked on it before. Just ignore that. You probably won't
3:06see that yourself. You probably also won't see this little congratulations, you've completed a
3:10task pop up with the octocat with a jetpack on. Anyway, what you'll see here is over here again
3:19on the left hand side, there's a little drop down for organization roles. And the important thing to
3:25understand is that these are independent, at least in large part, from the roles of the organization
3:31that contains it, right? So as you can see, if you click on role management here, there's a pretty
3:37comprehensive list of all of the things that these roles that a given role can control. All right,
3:44so for example, there's this all repository read role that basically just gives a user who has it
3:49the ability to access, as you can see from this little description under here, all of the
3:54repositories in the organization in a read only way, right? So they'll be able to see what repos
4:01the organization contains, what code is in them, information about the repos, etc. But they won't
4:08be able to make any changes to it. And obviously, you know, if you just read through these, you'll
4:13see that there are plenty of other things that you can control. Once again, we're going to go
4:17into much more detail on this later in the course. So going down another level, right, we've seen
4:24that enterprises have their own roles, organizations in an enterprise have their own roles. And so
4:30the repos in an organization also have their own roles. So let's just open up a repo here. Now that
4:38we've opened up the organization we created there, we're going to go to repositories. And we actually
4:43don't have one of these yet. So let's just click a new repository. And we'll call this something
4:47like my first repo. And then what we'll do next is we'll just leave everything else as is. And
4:55we're going to say create repository, just for the sake of being able to look at the roles for
5:01this repo. So once again, let's just go into the settings for this repo. If you click on settings
5:07there. And sure enough, if you take a look at the left hand side here, it's a little bit different
5:13than what we've seen with enterprises and organizations. But we do still have this team
5:18and member roles thing, which allows us much more fine grained control over who's allowed to do what
5:24on a particular repo. All right. So anyway, the point of all of this, and really the main takeaway
5:30at this point is that GitHub gives us some amazingly flexible tools for making sure that
5:39exactly the right people are able to do exactly the right things across every level of our
5:46enterprise, right? Again, at the enterprise level, at the organization level, at the repo level.
5:51And while this is something that we'll be getting into in more detail later,
5:54this level of flexibility that GitHub gives us truly is necessary in many cases, right? And in
6:00order to understand why this is, let's just jump back to my whiteboard here. And let's imagine that
6:05we have an enterprise like we currently have. I'm just going to write that as E. And then maybe this
6:10organization or sorry, maybe this enterprise has multiple organizations here, right? We'll just
6:15call those O1 and O2. And then maybe each of these organizations has some repos, right? So we'll
6:21have R1 and R2 under, oops, why did I write R3? Let's try that again. All right, R1 and R2 under
6:27O1. And then we'll have R3 and R4 under O2, right? And what this separation of concerns you might say
6:39allows us to do is have different users take completely different roles at different levels
6:47of this hierarchy. And not only at different levels, but in different specific instances
6:54in this hierarchy, right? So in other words, this person here, we'll just call this these person
6:59A, B, and C. Person A could in theory be the owner of the enterprise, but this does not mean that
7:09they have to then be the admin of these organizations and admin of all of these repos,
7:15right? They can make person B here be, let's say, the admin of repos 1 and 3, right? We'll just
7:23write admin there. And they can make person C be the admin of these two organizations here.
7:30This is getting to be kind of a convoluted chart, but the point being, the fact that we have
7:36different levels of roles for enterprises, organizations, and repos allows us to achieve
7:42this kind of complexity if we need it. And in many organizations, this is necessary.
Challenge & Solution: Adding Organization and Repo Members
0:00All right, well, in this skill,
0:01we've set up enterprises, organizations, and repos,
0:04and we've also created some users.
0:07And so the last thing that we need to do,
0:09which I'm gonna give you as a challenge here,
0:11once I've kind of shown you exactly what this involves,
0:16is we need to actually associate the other user here, right?
0:20Remember that this account is the owner of this enterprise,
0:26but the other user that we set up here earlier
0:30in the skill isn't yet associated
0:33with the organization and repo that we set up.
0:37So for example, right, if we switch accounts
0:39and go back to this personal account here
0:43that we added to the enterprise,
0:44what we'll see is that while this person
0:46is able to see the enterprise,
0:48because they are a member of that,
0:50they're not actually able to see
0:51any of the organizations in the enterprise.
0:54Well, they're able to see it as a list,
0:56but if we go into the organization,
0:57we're not actually able to see
0:59any information about the organization, right?
1:02And that's because this user
1:04isn't yet a member of this organization.
1:08And the same thing is true of the repos, right?
1:11Because this person hasn't explicitly been added
1:14to any of these repos,
1:16they have basically no permissions whatsoever
1:19with regards to those repos, right?
1:21They're not even able to see that they exist.
1:25And so that is your challenge here,
1:26is going back to the other account, right?
1:29The enterprise owner that we created
1:32the organization and repo in this enterprise with,
1:37we're gonna need to add that user to the organization
1:41and also to the repo that we created.
1:45Now, I'll kind of point you in the right direction here
1:48just to make sure you don't get totally lost with this.
1:51But first, let's go back to our enterprise.
1:53And what you're gonna need to do here
1:55is inside this enterprise,
1:58you can click Invite Owners.
1:59This also allows you to add other people
2:02in other capacities.
2:03I don't know why they just say Invite Owners,
2:05because again, you can do other things too.
2:07What you'll see here is if we go to Members,
2:10that person is already a member of this enterprise.
2:14But if you go into the organization that we created,
2:16you'll find that that's not the case, right?
2:18If we go to Organizations
2:20and go to Sean Software Inc here,
2:22what you'll see is that there's this
2:23Invite Your First Member link,
2:25and that will take you to the place
2:27where you can actually add that other user as a member.
2:30And you'll find the same thing under Repositories here.
2:34If you go to Repositories,
2:36we'll open up my first repo that we created here.
2:39And then if we go to Manage Access right here up at the top,
2:44what we'll see is that you can add people here
2:46by clicking this Add People button.
2:49All right, so anyway, that is your challenge here,
2:50is to walk through what I just showed you
2:52and add that other user to the organization and the repo.
2:58So anyway, feel free to give this
3:00about five to 10 minutes to complete,
3:01and once you've given it a try,
3:02you can move on to the next video
3:04where I'll walk you through the solution.
3:06So best of luck, and I'll see you in the next video.
Challenge & Solution: Adding Organization and Repo Members
0:00All right, well hopefully you gave this challenge a try,
0:02so let's take a look at the solution.
0:04So the first thing that we're gonna do
0:05is we're gonna go back to the organization here,
0:09Sean Software Inc., I'm gonna click on that,
0:11and as I said, we're gonna go to invite your first member,
0:15and we're gonna add that other account to this organization.
0:19So here's what this'll look like.
0:20We're gonna say invite member,
0:22and what we have to do is basically
0:24just search by the username.
0:25So I'm gonna say Sean LaSalle here.
0:27Make sure to search by your own username.
0:29Verify with that icon there.
0:31And we're gonna click invite.
0:33Do make sure that you're inviting the right person there.
0:36If your name is something a little bit more common,
0:38like, I don't know, John Smith, definitely be careful.
0:42But anyway, we're gonna click invite there,
0:44and we're gonna say that we wanna invite
0:47this person as a member.
0:48If we were to invite this person as an owner,
0:51that gives them full administrative rights,
0:54as you can see in this little blurb here,
0:56to the organization, which is not what we wanna do here.
1:00We already have one owner, and that's us.
1:02That's this account, anyway.
1:03So we're gonna click send invitation,
1:06and now that we've done that,
1:08again, we get this little,
1:09you've completed a task pad on the back up here,
1:12virtual pad on the back, that is.
1:14And so the next thing that we need to do
1:16is we need to go and add this person to the repo.
1:20So if we click on repositories here
1:22and go into my first repo,
1:24what we'll see, if we go to manage access,
1:26is you may have noticed this message up here
1:29that says members of any organization
1:31belonging to Sean Software Enterprise
1:33can see this repository.
1:35Now that's kind of interesting,
1:37because that suggests that we don't actually need
1:39to add that other user directly to this repo
1:44in order for them to have access to it.
1:46And that's also a very easy thing to test,
1:48so let's go test this, shall we?
1:50What I'm gonna do is I'm gonna jump back
1:51to this other user.
1:53We're gonna switch accounts,
1:54and well, first of all, we get this 404 page,
1:57because that person's, this user,
2:00even if they're able to access that repo,
2:02is not able to access the settings,
2:04and especially the access part of the settings.
2:07That's something that only admins can typically do.
2:10So what we're gonna do is we're gonna go back
2:11to the homepage, and we're gonna go up here
2:13and go to organizations, okay?
2:16So we need to accept that invite to Sean's Software Inc.
2:21So we're gonna say accept there.
2:23We're gonna say join.
2:24And sure enough, with no additional access given,
2:29we can now access this MyFirstRepo.
2:32Now, you might be wondering why did this user
2:35not show up in that access list
2:38when we were looking at the repo
2:39from the other account, right?
2:41Well, the thing to understand is that
2:43if we go back to that account now,
2:44let's just open the admin account up,
2:48and we're gonna go back to our repo here,
2:51what we'll see now is it says
2:53all two Sean's Software Enterprise members,
2:55grammatically a little bit off there, but anyway,
2:58all two Sean's Software Enterprise members
3:01can access this repository, right?
3:03Now, we can change that as the default behavior,
3:07but basically that means that because that person
3:09is a member of that organization,
3:12they automatically have read access
3:14to all repos in that organization.
3:17Now, if we wanna allow them to contribute,
3:20that's a different thing, but well, you get the idea.
3:23All right, so whether you notice that
3:25or whether you just went straight in
3:26and added that person directly,
3:28doesn't really matter too much, right?
3:30This would be how we add more complex roles, right,
3:34or more, let me rephrase,
3:37this would be how we add more privileged roles
3:39to a particular user, so as we can see,
3:42read is marked as the base role here,
3:43meaning that that user already has that,
3:46but you can also give them more privileged roles
3:47like triage, write, maintain,
3:50or you can make them an admin if you really wanted to.
3:52I'm not going to do that, but well,
3:55if you went in there and added that person directly,
3:58that's totally fine as well.
3:59All right, so anyway, that was the solution walkthrough.
4:02All right, so hopefully this helped solidify
4:04what we've learned so far about enterprises,
4:07organizations, and repos, and the corresponding roles
4:10that allow users different types of access
4:13to those entities.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year