TL;DR: That 403 almost always means the GitHub App or token posting the review lacks the pull-requests write permission, or the installation does not cover the repo. Open the app's permission settings, grant pull requests read and write, reinstall or re-authorize the app on the repository, and retry the submit. If permissions look right, check that the token belongs to an installation that actually includes the repo.

```text
403 Resource not accessible by integration when agent tried to submit review
```

1. Read the full error response, not just the status code. Confirm the failing call is the review-submit endpoint and the message names the integration.
   Expected: you know exactly which call and which credential is rejected.
2. Check the GitHub App's permissions. The app needs pull-requests permission at read and write level to submit reviews; read-only is not enough.
   Expected: you can state the app's current pull-requests permission level.
3. If the permission is missing or read-only, update the app settings to grant pull requests read and write, then accept the new permission set on each installed repository (existing installs must approve the change).
   Expected: the installation shows the updated permission set.
4. Verify the installation covers the repo. An app installed on some repos but not this one gets the same 403. Check the installation's repository list.
   Expected: the target repo appears in the installation's repo list.
5. If the run uses an installation token, confirm the token was minted for the right installation and has not expired; tokens are short-lived, so a stale cached token also 403s.
   Expected: a fresh token minted for the correct installation.
6. Retry the review submit with the corrected setup.
   Expected: the review posts with a 200 response instead of the 403.

## Use this when
- Review submit fails with "Resource not accessible by integration"
- A GitHub App review bot gets 403 on pull-request endpoints
- The same code works with a personal access token but not the app
- Permissions were recently changed on the app

## Not for this skill when
- The error is 404 rather than 403 (the PR or repo path is wrong, or the token cannot see the repo at all)
- The error is 401 (the credential itself is invalid or expired, not a permission scope issue)
- A human user gets the 403 (then it is branch protection or repo role, not app permissions)
- The review submit fails with "reviews may only be submitted on open pull requests" (the PR is closed or merged - different problem)

## Variant phrasings
- "reviewdog annotation failed to post: resource not accessible by integration"
- "GitHub App 403 submitting pull request review"
- "integration cannot post PR review comments"
- "review bot permission denied on pull request"

## Why it happens
GitHub Apps operate under fine-grained permissions granted at install time, and pull-request write is not in the default set many app templates request. Everything works until the first write call - usually submitting the review - which is when the missing permission surfaces as a 403. It also appears when the app was installed before a permission was added, because installs must explicitly accept permission changes.

## Edge cases
- Fork PRs from outside collaborators can restrict what the app may do even with the right permissions. Check the repo's fork-PR workflow settings.
- If the app tries to review a PR opened by the app itself, GitHub may refuse. Have a human or a different identity own the PR.
- Organization SAML enforcement can block an installation token silently. The 403 persists until the identity is SAML-authorized.
- Archived repositories reject all writes with similar errors. Confirm the repo is not archived before chasing permissions.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_UVA93vM0zRgmM3375ONZLA
