Project management
Multi-tenant projects
Every project is (repo_owner, repo_name). The projects table holds the metadata; project_users is the membership table. Projects are isolated: a user's role in project A does not affect project B.
Tokens
projects.github_token is a per-project admin PAT. Used by the API for the file proxy. Admin-only — other members cannot read it. If unset, the API falls back to the admin's session token.
Project owners
Anyone who owns the underlying GitHub repo can create a project record. Project deletion cascades to project_users and invitations. The underlying GitHub repo is unaffected.