Why it matters
Source code access is effectively access to how every other control in your product actually works.
How a self-led small team implements it
Restrict repository access by team/role in your existing Git provider — this alone usually satisfies the control.
What auditors expect to see
Repository access permissions.
Track A.8.4 in your own Statement of Applicability — mark it applicable, log your justification, and link it to the risk that drove it.
Start your ISMS