Skip to main content

GitHub Organization Manager

Test suites REUSE status The latest version of GitHub Org Manager can be found on PyPI. Information on what versions of Python GitHub Org Manager supports can be found on PyPI.

A lightweight tool that helps with managing a GitHub organization, its members, teams, repository permissions and more.

The basic principle: all settings reside in YAML configuration files which will be made effective during a run of this tool.

Features

  • Manage GitHub organization owners
  • Manage GitHub teams, their members, maintainers and settings
  • Support of parent/child teams
  • Manage teams' permissions on organizations' repositories
  • Invite members to the organization if they aren't part of it yet
  • Warn about unmanaged teams
  • Warn about organization members who are not part of any team
  • Handle individual collaborator permissions to repositories

The tool's philosophy:

  • All relevant configuration shall happen in the YAML configuration files, no actions in GitHub UI shall be necessary.
  • All repository permissions shall be managed by team membership. Outside collaborators and individual permissions are discouraged.
  • All teams shall be managed by this tool. While it can deal with unmanaged teams, it's not a priority and may cause warnings.

Are you missing a feature? Please check whether it's already posted as an issue, and create one of this isn't the case.

Install

Dependencies: Python 3.10 or newer

To install: pip3 install github-org-manager

You may also want to consider using helpers such as pipx to avoid a dependency mess on your system.

Afterwards, the tool is executable with the command gh-org-mgr. The --help flag informs you about the required and available commands.

Configuration

Inside config/example, you can find an example configuration that shall help you to understand the structure:

  • app.yaml: Configuration necessary to run this tool and controlling some behaviour
  • org.yaml: Organization-wide configuration
  • teams/*.yaml: Configuration concerning the teams of your organization.

You may also be interested in the live configuration of the OpenRail Association's organization.

Authentication via token or app

As this tool issues many API requests (both on REST and GraphQL API), authentication is highly recommended. This is supported via personal access tokens of a user (PAT) or a GitHub App which you can setup yourself.

Access tokens and apps need the following permissions:

  • Repository permissions
    • Administration: read and write
    • Metadata: read
  • Organization permissions:
    • Administration: read and write
    • Members: read and write

You can set the required secrets in config/app.yaml or via environment variables (GITHUB_TOKEN or GITHUB_APP_ID and GITHUB_APP_PRIVATE_KEY).

Run the program

You can execute the program using the command gh-org-mgr. gh-org-mgr --help shows all available arguments and options.

Synchronisation examples:

  • gh-org-mgr sync -c myorgconf: synchronize the settings of the GitHub organization with your local configuration in the given configuration path (myorgconf). This may create new teams, remove/add members, and change permissions.
  • gh-org-mgr sync -c myorgconf --dry: as above, but do not make any modification. Perfect for testing your local configuration and see its potential effects.
  • gh-org-mgr sync -c myorgconf --debug: the first example, but show full debugging information.

Setup team examples:

  • gh-org-mgr setup-team -n "My Team Name" -c myorgconf: Bootstrap a team configuration for this team name. Will create a file myorgconf/teams/my-team-name.yaml, or provide options if this file already exists.
  • gh-org-mgr setup-team -n "My Team Name" -f path/to/myteam.yaml: Bootstrap a team configuration for this team name and will force to write it in the given file. If the file already exists, offer some options.

License

The content of this repository is licensed under the Apache 2.0 license.

There may be components under different, but compatible licenses or from different copyright holders. The project is REUSE compliant which makes these portions transparent. You will find all used licenses in the LICENSES directory.

The project is has been started by the OpenRail Association. You are welcome to contribute!

Metadata

Release files for github-org-manager 0.7.13

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for github-org-manager 0.7.13
File Size Uploaded
github_org_manager-0.7.13.tar.gz 39.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for github-org-manager 0.7.13
File Interpreter ABI Platform
github_org_manager-0.7.13-py3-none-any.whl Python 3 none any Details

Total release size: 87.7 kB

Release files / github_org_manager-0.7.13.tar.gz

Download URL github_org_manager-0.7.13.tar.gz
Size 39.8 kB
Tags Source
SHA-256 checksum
How to use checksums
a59560abf419cc6af6628666be85e18c90d87e492c08258e88959072b0441783
BLAKE2b-256 checksum
How to use checksums
5e079745aa44681ee86abcfd12a61aa2dd40cf85aef9c8453cf19c43946f1bbd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / github_org_manager-0.7.13-py3-none-any.whl

Download URL github_org_manager-0.7.13-py3-none-any.whl
Size 47.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
01be4067eda023215fc087dcd27a96bf3ba2eb29c564f7a90060d630564c894b
BLAKE2b-256 checksum
How to use checksums
8bc5a92d394c2198178fef982c1789ba61857d481f281213d5752397b344802a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.7.13 This release

2 release files

0.7.12

2 release files

0.7.11

2 release files

0.7.10

2 release files

0.7.9

2 release files

0.7.8

2 release files

0.7.7

2 release files

0.7.6

2 release files

0.7.5

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.6.0

2 release files

0.5.7

2 release files

0.5.6

2 release files

0.5.5

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.2

1 release file

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page