Skip to content
Notis

Audit GitHub team repository permissions via webhook

You need to verify that teams have the correct repository access levels. Send a webhook request and Notis audits permissions across your repos.

Trigger

Webhook received

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

Action

Check team permissions for a repository

Checks a team's permissions for a specific repository within an organization, including permissions inherited from parent teams.

Why this helps

Verifying team permissions requires manual GitHub checks across many repos. Permission creep happens silently and goes unnoticed.

  • Audit permissions on-demand without manual GitHub checks
  • Catch permission drift before it becomes a security issue
  • Integrate permission audits into your compliance workflow

Setup

Build it in a few focused steps.

  • 1Connect your GitHub organization to Notis.
  • 2Create an automation: 'When a webhook arrives, audit all teams and their repository permissions'.
  • 3Set the trigger to 'notis_webhook'.
  • 4Notis will give you a webhook URL to call from your compliance or security tools.
  • 5Test by sending a webhook request and receiving a detailed permission report.

Questions about this workflow

How detailed is the permissions report?

You'll get team names, repository names, permission levels (read/write/admin), and any inherited permissions from parent teams.

Can I audit permissions for specific teams only?

Yes—specify team names in your webhook request and Notis will audit only those teams.

Should I run this regularly?

Yes—set up a monthly or quarterly cron automation to catch permission drift early.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Whatsapp to GitHub. A trigger fires from one place; an action lands in another.

Whatsapp triggers

GitHub actions

Message Status Updated

Triggers when a WhatsApp message status changes. IMPORTANT LIMITATION: WhatsApp Cloud API does not provide a native polling endpoint for message status. Status updates are ONLY delivered via webhooks in real-time. This trigger cannot directly poll the WhatsApp API for status updates. This trigger will return empty results as WhatsApp does not support this operation. To track message status updates, you must: 1. Set up a webhook endpoint to receive status notifications from WhatsApp 2. Store the webhook data in your own database 3. Use a different mechanism to query your stored webhook data For more information, see: - https://developers.facebook.com/docs/whatsapp/cloud-api/webhooks

TriggerPolling

Accept a repository invitation

Accepts a pending repository invitation that has been issued to the authenticated user.

ActionInstant

New Message Received

Triggered in real time when your WhatsApp Business number receives an inbound message from a customer (text, media, location, or contact). Delivered via the Cloud API webhook.

TriggerInstant

List repositories starred by the authenticated user

Deprecated: lists repositories starred by the authenticated user, including star creation timestamps; use 'list repositories starred by the authenticated user' instead.

ActionInstant

Interactive Reply Received

Triggered when a customer taps a quick-reply button or selects an option from an interactive list message you sent.

TriggerInstant

List stargazers

Deprecated: lists users who have starred a repository; use `list stargazers` instead.

ActionInstant

Message Template Status Update

Triggered when the review status of a WhatsApp message template changes — for example approved, rejected, or flagged — on your WhatsApp Business Account.

TriggerInstant

Star a repository for the authenticated user

Deprecated: stars a repository for the authenticated user; use `star a repository for the authenticated user` instead.

ActionInstant

Add email for auth user

Adds one or more email addresses (which will be initially unverified) to the authenticated user's github account; use this to associate new emails, noting an email verified for another account will error, while an existing email for the current user is accepted.

ActionInstant

Add app access restrictions

Replaces github app access restrictions for an existing protected branch; requires a json array of app slugs in the request body, where apps must be installed and have 'contents' write permissions.

ActionInstant

Add a repository collaborator

Adds a github user as a repository collaborator, or updates their permission if already a collaborator; `permission` applies to organization-owned repositories (personal ones default to 'push' and ignore this field), and an invitation may be created or permissions updated directly.

ActionInstant

Add a repository to an app installation

Adds a repository to a github app installation, granting the app access; requires authenticated user to have admin rights for the repository and access to the installation.

ActionInstant

Connect any two apps with Notis in the middle.

Not just Whatsapp and GitHub. Any combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7 days free trial with 20$ free usage included.
No card. Works with personal or business GitHub.