- github recommends Fine-grained tokens over Personal access tokens. - create read only token for all users - create read/write token to be manually installed for approved users https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens