Design and audit roles, seats, API access, and administrative separation for an enterprise organization. Use when this operator task needs a current, evidence-backed CodeRabbit workflow. Trigger with "audit CodeRabbit RBAC".
Use CodeRabbit native administrative roles instead of inferring all access from the Git provider. Map developer seats and administrative authority separately.
references/official-docs.md and re-check any time-sensitive contract before execution.Treat Git-provider sessions, CodeRabbit web sessions, CLI credentials, and CodeRabbit API keys as separate credentials. Use only an already-approved session or secret-manager reference, never print a secret, and do not place credentials in .coderabbit.yaml, source files, logs, or deliverables.
Inventory users, provider roles, CodeRabbit roles, seats, keys, and repo access.
Map job functions to least privilege across settings, billing, reports, API, and logs.
Find toxic combinations, stale admins, unused seats, and unmanaged keys.
Draft changes with partial-success handling, rollback, and recertification.
Require an authorized CodeRabbit Admin and security owner before role, seat, default-role, or key changes. Keep analysis and drafts local until approval is explicit, and record who approved the action and its scope.
An access matrix, least-privilege target, exceptions, approved change set, and recertification schedule. Include source dates, unknowns, and the exact boundary between observed fact and recommendation.
| Condition | Response |
|---|---|
| Current contract is unclear or docs disagree | Stop mutation, cite both sources, and request owner resolution. |
| Required access or approval is missing | Produce a draft and evidence plan only. |
| Validation or pilot behavior differs from expectation | Restore the prior state and retain the failed evidence. |
| Output contains secrets or private code | Stop, quarantine the artifact, redact it, and notify the data owner. |
Separate billing duties using Billing Admin.
Create an Enterprise read-only audit custom role.
references/official-docs.md.88dcf65
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.