Concept and mechanism
GITHUB_TOKEN permissions depend on context and effective configuration. When specific permissions are declared, omitted permissions become none. Grant only operations needed by the job performing them and check additional destination-resource controls. A reusable workflow cannot elevate permissions received from its caller. Secret passing also has a contract: if A passes a secret to B, that does not automatically make it available to C. Each link should declare what it needs and be authorized to receive it. Separating building, publishing, and promotion can clarify these needs, provided the boundaries also appear in actual execution. Names alone do not establish access isolation.
Guided application
In a fictional post-rotation incident, consider when each value was read. Organization and repository secrets are read when the run is queued; environment secrets are read when the referencing job starts. Rotation does not imply continuous rereading on every shell line. For production, where the plan supports required reviewers, the job waits for approval before accessing environment secrets. Confirm that the job actually references that environment and that branch policies are appropriate. During APS handover, document who approves, how a blocked run is recovered, and which evidence distinguishes authorization failure from an expired credential.
A grants only contents: read; C requests packages: write: fix the authorized caller contract rather than expecting callee escalation.
Common pitfalls
Transitive secrets; output as vault; production name as gate; rotation as immediate rereading; write-all as diagnosis.
Related topics: Events, filters, and dependencies · Data, outputs, and service networking · Reuse, artifacts, and troubleshooting
Record scope, read time, recipient, and approval for each access.
Reference: Secret scope and read time · GH-200 skills measured January2026;study guide updated2026-02-05