Early access · GitHub governance by Gimbal HQ

Audit everything. Enforce policy as it happens.

GitSpice is an enterprise Git management system. It controls and audits your GitHub estate, from enterprise down to branch and environment, and applies policy when changes happen, not after the fact.

Features

Built on Gimbal HQ's GitHub audit layer, with enforcement and workflows on top.

Coverage

Full scope

Covers enterprise, org, repo, team, user, branch and environment.

Events

Event capture

Receives every event through GitHub webhooks.

Audit

Audit

Reports on who can do what, and what happened, based on effective permissions.

Enforce

Policy enforcement

Apply policies when repos are created, on pull requests, and on other events.

Automate

Workflows

A visual workflow builder, triggered by GitHub events.

Workflow canvas: a repository.created trigger checks for a CODEOWNERS file, then applies branch protection or opens an issue and notifies a channel.
Workflow builder. Trigger on a GitHub event, check, then act.

Policy, enforced as it happens

Define a policy once, choose where it applies, and GitSpice evaluates it on every matching event, including pull requests.

Pull request checks showing a GitSpice policy check with two passed rules and one failed rule, and merging blocked.
Pull request policy status. Results appear right on the pull request.
Policy builder with a repository.created trigger, conditions, an enforce action and an organization scope picker.
Policy builder. Trigger, conditions, action and scope.
Enforcement log listing allowed and blocked decisions with the policy responsible, one row expanded.
Enforcement log. Every decision and the policy behind it.

Product previews with sample data.

How it works

Events, effective permissions and policy decisions are the core of GitSpice.

GitHub event→ Captured & stored→ Effective permissions→ Policy decision→ Enforced on GitHub

Install

GitSpice installs as a GitHub App on each organization.

  1. Install the GitHub App

    Add GitSpice to each GitHub organization you want governed.

  2. Events start flowing

    Webhook events are captured and effective permissions are built.

  3. Review the audit

    See who can do what, across every org and repo.

  4. Turn on policies

    Enforce your rules on new repos, pull requests and more.

Onboarding screen for choosing which organizations GitSpice manages, with a list of the access it requests.
Choosing organizations during install.

Built for the teams who answer for GitHub

One source of truth for who can do what, and proof that your rules were followed.

Security

Find excess admin access and risky settings, and stop them from coming back.

Compliance & GRC

Answer auditors with a record of access and policy decisions instead of screenshots.

Platform engineering

Set standards once and apply them to every new repo, across every org.

Early access

Join the waitlist

GitSpice is opening to a small group of early teams. Tell us about your setup and we'll reach out when your spot is ready.

What has you looking for a solution like this?
How would you prefer to pay?
What monthly budget feels right for a tool like this?

We'll only use your details to contact you about GitSpice. No spam. See our privacy policy.