{"meta":{"title":"Delegated bypass for push protection","intro":"Maintain your secret security while unblocking trusted actors with delegated bypass for push protection.","product":"Security and code quality","breadcrumbs":[{"href":"/en/code-security","title":"Security and code quality"},{"href":"/en/code-security/concepts","title":"Concepts"},{"href":"/en/code-security/concepts/secret-security","title":"Secret security"},{"href":"/en/code-security/concepts/secret-security/delegated-bypass","title":"Delegated bypass"}],"documentType":"article"},"body":"# Delegated bypass for push protection\n\nMaintain your secret security while unblocking trusted actors with delegated bypass for push protection.\n\n## About delegated bypass for push protection\n\nWith delegated bypass for push protection, you can:\n\n* **Grant bypass permissions** to select individuals, roles, and teams, allowing them to push commits that are initially blocked by push protection.\n* **Grant exemptions** to select actors, skipping push protection entirely for all of their commits. Exemptions should be granted to trusted automation like migration bots or service accounts that need to push frequent commits with minimal friction.\n* **Introduce a review cycle** for bypass requests from all other contributors. Requests expire after 7 days.\n\nDelegated bypass applies to files created, edited, and uploaded on GitHub.\n\n## Users with bypass privileges\n\nThe following types of users can always bypass push protection:\n\n* Organization owners\n* Security managers\n* Users in teams, default roles, or custom roles that have been added to the bypass list\n* Users who are assigned (either directly or via a team) a custom role with the \"review and manage secret scanning bypass requests\" fine-grained permission\n\n## Next steps\n\nTo start managing bypass privileges, see [Enabling delegated bypass for push protection](/en/code-security/how-tos/secure-your-secrets/manage-bypass-requests/enable-delegated-bypass)."}