I believe it's `repo, workflow` and that the bot user must be invited with `write` access to all repos involved.