About roles in an enterprise
All users that are part of your enterprise have one of the following roles.
- Enterprise owner: Can manage all enterprise settings, members, and policies
- Billing manager: Can manage enterprise billing settings
- Enterprise member: Is a member or owner of any organization in the enterprise
- Guest collaborator: Can be granted access to repositories or organizations, but has limited access by default (Enterprise Managed Users only)
- Unaffiliated user: Has been added to the enterprise but isn't a member of any organizations
For information about which users consume a license, see Пользователи, использующие лицензию в организации.
People with collaborator access to repositories are listed in your enterprise's "People" tab, but are not enterprise members and do not have access to the enterprise. See Роли в организации.
Enterprise owners
Enterprise owners have complete control over the enterprise and can take every action, including:
- Managing administrators
- Adding and removing organizations
- Removing enterprise members from all organizations
- Managing enterprise settings
- Enforcing policy across organizations
- Managing billing settings
For security, we recommend making only a few people enterprise owners.
Enterprise owners do not have access to organization settings or content by default, but they can gain access by joining any organization. See Управление ролью в организации, принадлежащей предприятию.
Billing managers
Billing managers only have access to your enterprise's billing settings. They can view and manage:
- User licenses
- Usage-based billing
- Other billing settings
Billing managers do not have access to organization settings or content by default except for internal repositories within an enterprise in which they are a member.
Enterprise members
Members of organizations owned by your enterprise are automatically members of the enterprise.
Enterprise members:
- Cannot access or configure enterprise settings.
- Can access all repositories with "internal" visibility across any organization in the enterprise. See Сведения о репозиториях.
- May have different levels of access to various organizations and repositories. To view the resources someone has access to, see Просмотр пользователей в организации.
Guest collaborators
Примечание.
Роль гостевого участника совместной работы доступна только с Enterprise Managed Users.
Вы можете использовать роль гостевого участника совместной работы для предоставления ограниченного доступа поставщикам и подрядчикам. Гостевые сотрудники:
- Подготавливаются идентификатором поставщика удостоверений, как и все данные управляемые учетные записи пользователей.
- Можно добавлять как участников организации или в качестве участников совместной работы в репозиториях.
- Не удается получить доступ к внутренним репозиториям в организации, за исключением организаций, в которых они добавляются в качестве члена.
You may need to update your IdP application to use guest collaborators. See Включение гостевых участников совместной работы.
Unaffiliated users
Unaffiliated users are people who have been added to your enterprise but aren't members of any organizations. These users:
- Do not consume a standard GitHub Enterprise license.
- Cannot access private or internal repositories.
- Can be added as members of organizations or enterprise teams.
- Can receive a Copilot license directly from your enterprise.
You can add unaffiliated users from your identity provider (for Enterprise Managed Users) or by inviting users at the enterprise level (for personal accounts). For personal accounts, see Приглашение пользователей в ваше предприятие напрямую.
Next steps
When you have decided which roles your users require, assign the roles to them. See Assigning roles to users in an enterprise.