To deploy an app, we want to be able to restrict access to annotation, limiting it to just some Gitub users.
Same for reviewers - even smaller set of users would need a reviewer bit set on.
Developing a full-blown ACL solution is outside of the scope though.