What changed
GitHub added generally available enterprise-managed permissions for Copilot agent operations on September 9, 2026. Copilot Business and Enterprise administrators can centrally classify shell commands, file reads and edits, and network domains as blocked, requiring human approval or allowed without a prompt. Managed restrictions cannot be weakened by user or workspace settings, auto-approval or previously saved approvals, and enterprises can define different policies for different teams. The controls apply to the GitHub Copilot app, Copilot CLI and Visual Studio Code sessions using Agent Host. This extends the same governance direction already visible in JetBrains, where GitHub added public-preview managed sandbox policies on September 8 for sandbox enablement, filesystem/network access, proxy behavior, developer tools and macOS Keychain access. On October 7, 2026, GitHub made local sandboxing generally available in Copilot CLI, the Copilot app and VS Code sessions using Agent Host. The local execution boundary is powered by Microsoft eXecution Container (MXC), which translates shared policies into native OS controls on Windows, macOS and Linux. Policies can restrict files, directories, network destinations and credentials, including local MCP tools and language servers where supported. Enterprise settings can require sandboxing and prevent developers from weakening restrictions. This is distinct from the JetBrains-specific sandbox controls, which GitHub previously described as public preview.
Why it matters
AI coding governance now has an enforceable operation layer rather than only client-wide settings. An organization can let agents work autonomously on low-risk actions while requiring approval or blocking higher-risk shell, filesystem or network operations, and those restrictions survive local attempts to relax them. The JetBrains sandbox remains a complementary boundary: operation permissions govern what actions may proceed, while the sandbox limits what the local execution environment can reach. Together they show GitHub converging on centralized policy for both agent intent and execution across multiple clients. The October GA milestone means teams can rely on a supported local execution-isolation layer across three mainstream Copilot surfaces rather than only approval prompts or a preview switch. The model still does not become intrinsically trustworthy: containment applies to tool execution, and server-side authorization remains essential.
Enterprise policy can now govern individual agent operations
Administrators can centrally define policy for shell commands, file reads and edits, and network domains. Operations can be blocked, require a human approval prompt or be allowed without prompting. GitHub says managed restrictions cannot be weakened by user settings, workspace settings, auto-approval or approvals a user saved previously.
The permission layer spans multiple Copilot clients
The September 9 controls are generally available in the GitHub Copilot app, Copilot CLI and Visual Studio Code sessions using Agent Host. Enterprises can also apply specialized policies to different teams, making the control model more granular than a single organization-wide autonomous-versus-manual switch.
JetBrains adds a complementary local sandbox boundary
GitHub's September 8 JetBrains update remains relevant because it governs the local execution environment itself: sandbox enablement, filesystem and network access, proxy settings, developer-tool access and macOS Keychain access. Those managed restrictions override developer-local choices and are still public preview.
MCP, plugins and telemetry remain part of the broader policy stack
Existing managed settings continue to govern plugin marketplaces, MCP server allow/deny lists, OpenTelemetry and permissive agent modes. The newer operation permissions add finer-grained action control without replacing those external-integration and observability policies.
Central policy does not remove server-side authorization needs
A client-side permission system and sandbox reduce accidental or unauthorized local actions, but production systems should still enforce their own identity, authorization and review boundaries. High-impact infrastructure, billing and deployment APIs should not rely solely on a coding client's approval prompt.
Local sandboxing is now GA across three Copilot surfaces
On October 7 GitHub made MXC-backed local sandboxing generally available in Copilot CLI, the Copilot app and VS Code Agent Host sessions. A common policy maps to native Windows, macOS and Linux restrictions for agent-run commands and tools. This is separate from the earlier JetBrains preview.
Sandbox policy limits capabilities, not just prompts
The execution boundary can restrict filesystem read/write scope, network access and access to Git/GitHub CLI credentials, with some local MCP and language-server integrations also covered. Enterprises can require sandboxing and disallow local weakening of managed settings. Model selection does not change the sandbox policy.