github GitHub Changelog ·

GitHub Copilot now offers enterprise-managed permissions for agent operations

aigaengineer
feature

GitHub Copilot Business and Enterprise administrators can now centrally control agent operations, including shell commands, file access, and network domains. These managed permissions provide fine-grained guardrails for sensitive actions without needing to disable agent workflows entirely. The restrictions cannot be bypassed by individual user or workspace settings, and specialized policies can be applied to different enterprise teams. This functionality is generally available in the GitHub Copilot app, CLI, and Visual Studio Code sessions using Agent Host.

Features (1)
  • Centrally manage permissions for Copilot agent operations

    Administrators of GitHub Copilot Business and Enterprise can now implement centralized controls over Copilot agent operations, such as shell command execution, file reads and edits, and network access. These managed permissions provide fine-grained guardrails for sensitive actions and cannot be weakened by user settings, auto-approval, or previously saved approvals. Organizations can also define specialized policies for different enterprise teams.

Read the original announcement →

https://github.blog/changelog/2026-09-09-enterprise-managed-permissions-for-github-copilot-agent-operations

Related releases