Permissions
The GitHub App asks for the smallest set of permissions that lets it do its job. Here is what each one is for.
What it reads
The app has read access to repository contents and pull request context so the agent can analyze a change against the codebase it lives in, not just the diff. Reviews use a checkout of the exact commits under review, created inside the analysis environment and discarded when the review task ends.
What it writes
Write access covers outputs, not code: pull request reviews and comments and the Foundry Verify check run. The app also reads pull request conversation comments so repository members can use commands, and it acknowledges a command with a reaction. The app does not create branches in your repository and cannot modify your code.
Verifying the app
The public listing shows the app's permissions, publisher and install base. Review it before installing if that is part of your process.
Install through app.irlabs.ai. An installation created directly from the GitHub listing is not connected to a workspace and no reviews run until onboarding completes. For what happens to your data, see the security page.
