Doctorine App permissions
One Doctorine App supports docs synchronization and SDK publishing. Install it on the repositories you intend to connect; an installation is not permission for a different Doctorine workspace to claim your repository.
The shared permission set covers repository metadata, content and pull requests; workflow files, Actions and repository variables; checks, statuses, deployments and environments; issues; organization membership lookup; and read-only administration and merge-queue inspection. These permissions support the shared App's capabilities. They do not mean every connected repository enables every automation tier.
Why administration read access?
Section titled “Why administration read access?”Doctorine inspects repository protections when deciding whether automation may merge. Administration access is read-only: it does not authorize Doctorine to turn off your branch protections. If the protection or bypass result is unknown, use manual review.
Approve an installation update
Section titled “Approve an installation update”An existing installation can retain its old grants until an administrator approves an App update. Studio shows approval pending when the SDK-required grants are absent. Open the installation's configuration link, review the change on GitHub, and return to Studio. Existing docs synchronization can continue while SDK linking waits for the new grants.
If a repository is missing, use I don't see my repo to refresh authorization. Use the separate account/organization option when you need another installation.
What publishing consent controls
Section titled “What publishing consent controls”Consent enables Doctorine's publishing automation for a target. The repository
variable DOCTORINE_PUBLISHING records that preference. Repository administrators
can change variables and workflows themselves, so this is not an enforcement
boundary against the repository owner. Studio reports detected drift as
repository-managed publishing.
Disabling or unlinking in Doctorine does not revoke a registry trusted publisher or a credential you created yourself. Follow the full offboarding inventory.