Project leads are organization members assigned to a project. They receive that project's dependency-change digests and security alerts. Being a lead also grants editor capabilities on that project only (review, publish, import, security acknowledge, and public branding). It is not an organization role and does not grant activate, repository connect/disconnect, or org admin powers. See Help center → Roles and permissions for the org matrix.
How routing works
- If a project has one or more leads, digests and security alerts for that project go only to those members.
- If no leads are set (or every named lead has left the org), mail goes to the organization notification list. If that list is empty, SourceTrust falls back to owners and admins.
- Being a lead on project A does not stop you from getting mail for project B when B has no leads. No-lead projects still use the full organization list.
- Integration and custom-domain alerts stay on the organization notification list. They are not lead-routed.
What leads can do on the project
- Review packages, import lockfiles, re-publish, sign a publish, and acknowledge security findings on that project.
- Edit public branding (logo, brand color, product URL).
- They cannot activate a draft (first billed publish), connect or disconnect the repository, change signature policy, or manage org members and billing.
- A viewer or finance member who is a lead gets those project powers only on led projects.
How to set leads
- Open the project → Settings → Automation → Project leads (admins and owners).
- Search and select current members who should lead this project (up to 10).
- To add someone not yet in the org, invite them as a pending lead. That sends an organization invite as a viewer. After they accept, they become a lead on this project (editor capabilities here only, not org-wide).
- You can also choose leads on the last step when creating a project.
When members leave
Removing a member from the organization, or deleting their account, also removes them from every project's lead list in that org. Alerts for those projects fall back to remaining leads, or to the organization list if none remain.