## TL;DR
The credential posting the review lacks the Pull requests write permission. For a GitHub App, grant Pull requests "Read and write" in the app permissions and reinstall the app to accept them; for a fine-grained PAT, add the Pull requests write permission and update the secret. Then re-run the review step.

## The error
```text
"403 Resource not accessible by integration" error when posting a PR review
```

## Steps to fix
1. Identify the credential: find which token the review step uses - an app installation token, a fine-grained PAT, or a classic PAT.
   - Expected: you know exactly which credential is making the failing call.
2. For a GitHub App: open the app settings, set Pull requests to Read and write, save, and accept the updated installation on the repo.
   - Expected: the installation lists Pull requests read and write.
3. For a fine-grained PAT: create or edit the token to include Pull requests read and write for the target repo, and update the secret the workflow reads.
   - Expected: the workflow picks up the new token value.
4. Re-run the review step.
   - Expected: the review posts successfully.

## Use this when
- A bot gets 403 "resource not accessible by integration" submitting a pull request review.
- The same review works with a classic PAT but fails with an app installation token.
- A review bot was just switched from PAT auth to GitHub App auth.

## Not for this skill when
- The error is about annotations rather than reviews (that's the Checks permission).
- The PR is closed or merged (reviews can only be submitted on open PRs).
- The token is expired rather than under-permissioned (mint a fresh one).

## Variant phrasings
- github app 403 posting pull request review
- resource not accessible by integration pull request review
- bot cannot submit PR review permissions
- 403 when review bot posts review github actions

## Why it happens
Posting a review calls the pull-request reviews endpoint, which requires write access to pull requests. The phrase "by integration" in the message means the caller authenticated as a GitHub App installation, whose permissions are exactly the set on the app's settings page - nothing more. Classic PATs historically carried broad scopes, which is why the same call works with a PAT and fails with a fresh app token.

## Edge cases
- Permission changes only take effect after the new installation is accepted; the old token keeps the old scopes until then.
- Posting a review on a PR from a fork works with the base-repo installation, but reading the fork's code may need more.
- Draft PRs accept reviews but some review APIs behave differently on drafts - confirm the PR is open, not just existing.
- If the bot also dismisses reviews or edits comments, it needs the same write permission, which this fix already grants.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_DUSL_ol5eWjgppHgPMee4w
