GitHub made enterprise-managed permissions for Copilot agent operations generally available
GitHub Changelog·high signal
As of 2026-09-09, Copilot Business and Enterprise admins can centrally set which agent operations are blocked, require human approval, or run without a prompt, across shell commands, file reads and edits, and network domains. The restrictions cannot be weakened by user or workspace settings, auto-approval, or previously saved approvals, and organizations can set different policies per enterprise team. It covers the Copilot app, Copilot CLI, and VS Code sessions using Agent Host.