GitHub adds enterprise-managed permissions for Copilot agent ops: shell, files, network
PaulShellDev · x · 2026-09-10
GitHub has made enterprise-managed permissions for Copilot agent operations generally available across the Copilot app, CLI, and VS Code Agent Host sessions.
- Admins of Copilot Business/Enterprise can centrally govern four operation types: shell commands, file reads, file edits, and network domains
- Each operation can be blocked, require fresh human approval, or run without a prompt
- Crucially, users cannot weaken managed restrictions via auto-approval, saved approvals, workspace settings, or YOLO mode
- Specialized policies can be configured per enterprise team
Practical recipes highlighted include blocking credential folders, requiring approval for git push, and allowing approved test commands — moving agent governance into the execution layer.
More from coding & agent
- Devs shipping agents in prod: what would you rip out of your framework? — BhAAI777 · 2026-09-10
- Not every multi-step AI task needs an agent — workflows still win for predictable paths — Old-Farmer-1029 · 2026-09-10
- YC to host 'Make Something Agents Want' hackathon Oct 17-18 in SF as agents become new users — ycombinator · 2026-09-10
- PowerChat: an iOS client that connects cloud/local models to any MCP server — powerchat-dev · 2026-09-10
- His wife writes tickets, an agent opens PRs: 52 of 56 merged on their marketplace — rathcom · 2026-09-10
- Next AI adoption wave will be computer use: Astra already automates real office workflows, argues thread — zephyr_z9 · 2026-09-10