GitOps keeps ordinary contributors out of settings drift. Branch protections and merge behavior live in the navigator
CLI, so an authorized operator reviews the planned change before applying it to one named repository:
Copy
navigator ops github setup neon-law/navigator --dry-run
The repository name is optional — it falls back to GITHUB_REPOSITORY and then this checkout's origin — but the
command still reconciles one repository at a time and cannot apply to every repository at once. The boundary is a
(host, organization) pair: the host from NAVIGATOR_GIT_HOST, defaulting to github.com, and two admissible
organizations — neon-law that holds Navigator itself, plus the deployment's own NAVIGATOR_GITHUB_ORG when one is
configured. A repository outside that pair is refused before a token is read. It reconciles pull-request-only and
squash-only policy, gated on one check named ci. Authorized contributors should read docs/gitops.md in their
checkout before changing the real setting; contributors normally work through a PR and let the gate do its job.