megachangelog
Feature

Manage GitHub Copilot app access with a dedicated policy

GitHub Copilot app now has its own dedicated policy for controlling access at the enterprise and organization levels, providing more granular access management.

The GitHub Copilot app now has its own policy, so you can control who has access to it at the enterprise and organization levels.

Until now, access to the Copilot app depended on your GitHub Copilot CLI policy being enabled. From several conversations with customers, we understand that many of you want to manage each client independently. Now the Copilot app and the Copilot CLI each have their own policy, giving you the flexibility and control to enable the right clients for your teams.

This new policy keeps your developers’ work within the guardrails you already rely on. When using this app, developers drive agent sessions in isolated workspaces and land changes through pull requests. This means the same reviews, checks, and audit history apply as they would to any other contribution. The Copilot app also joins Copilot CLI and VS Code as a supported client for enterprise-managed settings, so the guardrails you define once (e.g., which plugins developers can use) are consistently enforced in the Copilot app as well.

You’ll find this policy alongside your other Copilot policies. It’s set to Enabled everywhere by default, so your developers can start using the app right away with no action needed from you. You have three options:

  • Enabled everywhere gives your developers access to the app.
  • Disabled everywhere turns the app off across your enterprise.
  • Let organizations decide passes the choice to each organization’s admin.

If the Copilot app isn’t the right fit for your teams, set it to Disabled everywhere. Developers who open the Copilot app will see a notice that their admin hasn’t enabled it.

To review or change the policy:

  1. From your enterprise or organization settings, open the AI Controls tab.
  2. Go to the “Copilot Clients” section.
  3. Select the Copilot app policy.
  4. Choose Enabled everywhere, Disabled everywhere, or Let organizations decide.

To learn more about the Copilot app, including how to get started and manage policies, explore our Copilot app documentation.

To download the Copilot app, visit our landing page

The post Manage GitHub Copilot app access with a dedicated policy appeared first on The GitHub Blog.

copilotaccess-controlpolicyenterprisesecurity

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →