Back to news
launchgithub2026-09-09

GitHub Copilot launches enterprise-managed permissions for agent operations

On September 9, GitHub announced that Copilot Business and Enterprise administrators can centrally control agent operations, including block, require human approval, or proceed without prompt; managed restrictions cannot be weakened by local settings.

On September 9, GitHub announced enterprise-managed permissions for agent operations in GitHub Copilot. Copilot Business and Copilot Enterprise administrators can now centrally control which agent operations are blocked, require human approval, or can proceed without a prompt.

Managed permissions cover shell commands, file reads and edits, and network domains, giving fine-grained guardrails for sensitive operations without disabling agent workflows. Managed restrictions cannot be weakened by user settings, workspace settings, auto-approval, or previously saved approvals. Administrators can also provide specialized policies for different enterprise teams.

These controls are generally available in the GitHub Copilot app, GitHub Copilot CLI, and Visual Studio Code sessions that use Agent Host. GitHub also shipped a policy diagnostics tool that lets administrators verify that managed settings are detected and enforced on developer endpoints, rather than merely configured.

GitHub Copilot企业托管权限智能体安全