You can connect a GitHub repository to a workspace and start a review of it.
The App asks for two read-only permissions — repository contents and metadata — and nothing else. It cannot push code, open pull requests or change settings, and it can only see the repositories you select in GitHub's own interface.
Revoking works the way it should. If you remove or suspend the App in GitHub, Monterva is told and your settings page says so, rather than continuing to show a connection that no longer works. Your existing reviews and findings are untouched.