GitHub Copilot now offers enterprise-managed permissions for agent operations
GitHub Copilot Business and Enterprise administrators can now centrally control agent operations, including shell commands, file access, and network domains. These managed permissions provide fine-grained guardrails for sensitive actions without needing to disable agent workflows entirely. The restrictions cannot be bypassed by individual user or workspace settings, and specialized policies can be applied to different enterprise teams. This functionality is generally available in the GitHub Copilot app, CLI, and Visual Studio Code sessions using Agent Host.
Features (1) ›
- Centrally manage permissions for Copilot agent operations
Administrators of GitHub Copilot Business and Enterprise can now implement centralized controls over Copilot agent operations, such as shell command execution, file reads and edits, and network access. These managed permissions provide fine-grained guardrails for sensitive actions and cannot be weakened by user settings, auto-approval, or previously saved approvals. Organizations can also define specialized policies for different enterprise teams.
https://github.blog/changelog/2026-09-09-enterprise-managed-permissions-for-github-copilot-agent-operations
Related releases
- CodeQL 2.27.0 Adds Linux ARM64 Support, New Rust Security Query, and Expanded Framework Coverage GitHub Changelog ·
- GitHub introduces rulesets to block PRs with exposed secrets from merging GitHub Changelog ·
- GitHub Advanced Security trial expands to more Enterprise Cloud customers GitHub Changelog ·
- GitHub Copilot Introduces Agentic Autofix for Code Quality Findings GitHub Changelog ·
- GitHub Copilot for JetBrains Adds Enterprise Sandbox Controls and CLI Integration GitHub Changelog ·
- GitHub Enterprise Server 3.22 Now Generally Available GitHub Changelog ·