Tools
Copilot: enterprise managed agent permissions
GitHub announced on September 9, 2026 that administrators of GitHub Copilot Business and Enterprise can centrally set which agent operations are blocked, require human approval, or may proceed without a prompt. Managed permissions cover shell commands, file reads and edits, and network domains, with team-specific policies; restrictions cannot be weakened by user or workspace settings, auto-approval, or previously saved approvals. The controls are generally available in the GitHub Copilot app, Copilot CLI, and Visual Studio Code sessions that use Agent Host. This is GitHub Copilot enterprise agent governance, not Microsoft 365 Copilot and not the JetBrains sandbox policy from September 8.