I'm seeing unknown users checking in code to PRIVATE repositories. I found out who they are by reviewing it with my teams, but the system should automatically disallow this from happening. If a repository is PRIVATE, it should ONLY allow access to the people that have permissions to access it. That includes doing any management on it.