Two thoughts related to this:
- As long as the TM server resides on my research server hosted by my employer, I am strictly limiting who has write access to any part of it.
- We can get much of this functionality with automated merges and pulls from GitHub in what I believe would be a much more secure process. It wouldn't give results in a minute, since a site update process takes several minutes, mostly to reload the databases. I am thinking more along the lines of hourly updates. I am still very hesitant on the automated merges of GH pull requests, so this might be accomplished by having several people with ability to merge PRs, and those changes would go into the next automated update.