Fetching from the wire…
Public story · 2026-09-10 · high
Enterprise admins can now set org-wide rules for Copilot agents that developers can't loosen, even with a saved approval from before the policy existed.
Why now: GitHub's changelog post marks the enterprise-managed permissions feature as generally available.
GitHub made enterprise-managed permissions for Copilot agent operations generally available on September 9. Business and Enterprise admins can now set which agent operations are blocked, require human approval, or run without a prompt. That covers shell commands, file reads and edits, and network domains, per GitHub's changelog post.
For any team that's tried to get an AI coding agent approved for a codebase with real credentials attached, this is the missing piece. Most agent permission systems put the developer in charge of what the agent can touch. This one puts the enforcement point above the developer entirely.
The restrictions can't be loosened by user settings, workspace settings, auto-approval, or an approval a developer already saved before the policy existed. An admin sets the rule once, and it holds whether the agent is running in the Copilot app, the Copilot CLI, or a VS Code session using Agent Host. Policies can also differ per enterprise team, so different teams don't have to run under identical rules.
That closes a specific hole. I've watched agents auto-approve their way past a permission prompt because some earlier saved setting let them. An org-level policy that can't be overridden locally kills that path for good, not just for one session.
What the changelog doesn't say is how granular the network domain rules get, or whether a blocked operation gets logged anywhere an admin can review later. That audit trail question matters more than whether the blocking itself works. It's the next thing to ask GitHub.
Each link below shares sources, entities, or timing with this story.
Announced September 2, the Copilot app and CLI now respect exclusion policies configured by enterprise, org and repository administrators. Until this shipped, exclusion policies were enforced in some surfaces but not the agentic app and CLI paths, meaning a policy that looked...
Enterprise-managed MCP allowlists shipped August 6 across the Copilot app, Copilot CLI and VS Code, configured with allowedMcpServers and deniedMcpServers in copilot/managed-settings.json inside the org's .github-private repo. Match by serverUrl with wildcards for remote HTTP/...
43.3% on Frontier-Bench v0.1. Opus 4.8 scored 18.7%. That's not an incremental bump, that's the same benchmark with a different shape of answer. Anthropic released Claude Opus 5 on July 24 at $5/$25 per million input/output tokens, exactly half of Fable 5's $10/$50, while matc...
GitHub shipped it July 28 across Pro through Enterprise, reachable from VS Code, Visual Studio, Copilot CLI, the cloud agent, JetBrains, Xcode, and Eclipse, with text and image inputs and low/medium/high reasoning effort, billed at provider list pricing rather than a fixed mul...
July 9, across VS Code, Visual Studio, Copilot CLI, the cloud agent, github.com, GitHub Mobile, JetBrains, Xcode, and Eclipse. Sol is the high-reasoning tier at $5/1M in, $30/1M out, gated to Pro+/Max/Business/Enterprise. Terra is the balanced default at $2.50/$15. Luna is fas...
In one 48-hour window Anthropic announced a September 14 limit change netting out to 17% less than today, GitHub moved Copilot Business and Enterprise to upfront per-seat charging and changed the code-review default effort, Claude Code 2.1.251 added a Spend limit bar to /usage...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.