Agents

GitHub lets enterprises set Copilot agent permissions that users cannot loosen

GitHub made enterprise-managed permissions for Copilot agent operations generally available on Sept. 9. Administrators can block, require approval for, or allow shell commands, file access and network domains, and the company says individual users cannot weaken those limits.

The controls cover three kinds of agent activity: shell commands, file reads and edits, and the network domains an agent may contact. For each, an enterprise can decide that the action is blocked outright, needs a person to approve it, or can go ahead without a prompt. Administrators can also give different teams different policies.

The notable part is precedence. According to the changelog, managed restrictions cannot be relaxed through a developer's own settings, through workspace settings, through auto-approval, or through approvals saved earlier. The aim is to stop a local preference or a remembered yes from overriding a rule set centrally.

The feature applies to the GitHub Copilot app, the Copilot command-line tool and Visual Studio Code sessions that use Agent Host. It is available to organizations on Copilot Business or Copilot Enterprise plans. The changelog entry points to documentation for setup and does not walk through the configuration itself.

Source details
Source
GitHub

Source reporting

Read the original reporting and research behind this briefing.