A finance stakeholder needs monthly invoice access and spending visibility for GitHub Enterprise Cloud without the ability to change enterprise security policies. Which assignment best matches least privilege?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Assign the enterprise billing manager role so finance can view invoices and payment settings without full enterprise-owner powers. Never share owner passwords or disable SAML as a finance workaround.
Full explanation below image
Full Explanation
GitHub Enterprise Cloud supports billing managers who can access billing and payment administration without becoming full enterprise owners who control security policies, membership, and organization ownership. This separation satisfies least privilege for finance and procurement stakeholders. Granting enterprise owner broadly, sharing owner credentials, or weakening SSO for convenience introduces severe compliance and security risk. Administrators should inventory billing managers regularly, prefer SSO-authenticated accounts, and ensure ownership of payment methods is documented for audit. Spending alerts and usage reports further help finance control Actions minutes, Packages storage, and license growth without elevating privileges.