Skip to content
worth noting Tools and apps

GitHub introduces centrally managed permissions for agent operations in GitHub Copilot

clearly official source

GitHub has made enterprise managed permissions available - central management of agent operations in GitHub Copilot (shell commands, file operations, network access) that cannot be bypassed through user settings.

GitHub has made enterprise managed permissions available - a feature for centrally managing agent operations in GitHub Copilot on the Copilot Business and Copilot Enterprise plans. Administrators can specify whether individual types of operations should be blocked, require human approval, or proceed without prompting. The rules cover running shell commands, reading and editing files, and accessing network domains.

According to GitHub, restrictions configured this way cannot be weakened through user or workspace settings, automatic approvals, or previously saved approvals. Enterprise administrators can also define different policies for individual teams within the organization.

The feature is generally available in the GitHub Copilot app, in GitHub Copilot CLI, and in Visual Studio Code sessions that use Agent Host.

What changed

Why it matters

For companies running GitHub Copilot agents, this is a tool for reducing the risk of an agent performing an unintended or dangerous action - such as running a destructive shell command, editing a sensitive file, or accessing an unapproved network - without having to disable agents entirely. Enforcement at the administrator level, which cannot be bypassed through user settings, gives security and compliance teams assurance that the policy applies across the entire organization or a specific team.

Two audiences, two different impacts

What this means

01

For individuals

Developers in organizations that adopt these rules will no longer be able to bypass agent restrictions through their own settings, automatic approvals, or previously saved approvals.

More practical updates →
02

For a business

Administrators of GitHub Copilot Business and Enterprise gain central control over which operations agents are allowed to perform (shell commands, file edits, network access), including the ability to set different policies for individual teams - these restrictions also cannot be bypassed at the user or workspace level.

Risks and compliance
What to decide Review the available enterprise managed permissions templates for GitHub Copilot and set policies for teams working with sensitive repositories or production environments.
More business impacts →
AI agents security enterprise GitHub Copilot Governance

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
GitHub Copilot Changelog primary source · first detected Enterprise managed permissions for GitHub Copilot agent operations