🤖GitOps-drivenDeclare desired GitHub state as Kubernetes Custom Resources. The operator continuously reconciles reality to match.
🔌Pluggable Identity SourcesSync team membership from LDAP/AD, HTTP APIs, static lists, or Greenhouse — namespaced or cluster-wide.
🛡️Safety Rails Built-inDry-run mode, label-gated mutations, rate-limit handling, and protected-member lists prevent accidental changes.
📊Full ObservabilityPrometheus metrics, PromQL examples, Perses dashboards, and bundled alerting rules ship out of the box.
🏢Multi-org ReadyManage multiple GitHub organizations (cloud and enterprise) from a single operator deployment.
✉️Email VerificationEnforce verified domain-email requirements per org via GithubAccountLink — no more unverified members.