I do this so that AI can only have limited GitHub permissions. It can't merge, doesn't have admin rights, etc.
This after I started catching it commit directly to upstream main without PRs among other things.