Apify and Crawlee Official Forum

Updated 4 months ago

About organizations and private repositories

Hi. I am a member of an organization. I can switch from my personal account to the organization account and install actors there, when they are ready for production. The source code comes from my private Git repository.

I have two questions, regarding security:

  1. Can the organization owner/admin also switch into my account and see my actors, runs, storage and personal API token just like I can do with that account?
  1. Can they download the source code from the private repo?
This was available to link when the actor was built the first time, but I've removed the link so the repo is not visible from Apify.
And when I try to pull the code locally ('apify pull'), the operation fails.
However, it's still possible to do a 'clean build' and Apify is still able to clone the repo.
That looks fantastic, but I need to confirm if the source code is protected or maybe I'm forgetting something.

Thanks.
O
1 comment
  1. No, the admin can't access your personal account. Since you're a member of the organization, you have access to the organization's resources. Admins don't have permissions to manage or modify your personal account.
  1. Also no. Access needs to be granted directly on GitHub.
Add a reply
Sign up and join the conversation on Discord