<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst" -->

---
title: Enterprise managed permissions for GitHub Copilot agent...
description: GitHub Copilot Business and Enterprise administrators can now centrally control agent operations through managed permissions covering shell commands, file...
canonical: https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Enterprise managed permissions for GitHub Copilot agent operations | daily.dev
og:description: GitHub Copilot Business and Enterprise administrators can now centrally control agent operations through managed permissions covering shell commands, file...
og:url: https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst
og:image: https://api.daily.dev/og/posts/4pjRv8Sst.png
og:image:alt: Enterprise managed permissions for GitHub Copilot agent operations
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise managed permissions for GitHub Copilot agent operations

**[GitHub Changelog](https://daily.dev/sources/github_updates)** · 1 min read · 1 upvotes · 0 comments

## Summary

GitHub Copilot Business and Enterprise administrators can now centrally control agent operations through managed permissions covering shell commands, file reads/edits, and network domains. Admins can set operations to be blocked, require human approval, or proceed automatically, with rules enforced across teams and unable to be overridden by user or workspace settings, auto-approval, or saved approvals. These controls are generally available in the GitHub Copilot app, GitHub Copilot CLI, and VS Code sessions using Agent Host.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://github.blog/changelog/2026-09-09-enterprise-managed-permissions-for-github-copilot-agent-operations>

## Questions this post answers

### How can I control what GitHub Copilot agents are allowed to do in my enterprise?

GitHub now provides enterprise managed permissions that let administrators of Copilot Business or Copilot Enterprise centrally control agent operations, deciding which shell commands, file reads/edits, and network domain access are blocked, require human approval, or can proceed automatically. These restrictions cannot be weakened by individual user settings, workspace settings, auto-approval, or previously saved approvals, and different policies can be set per team.

_Admins locking down AI agent behavior can follow daily.dev for updates on Copilot governance controls._

### Where are GitHub Copilot's new enterprise managed permissions available?

The managed permissions controls are generally available in the GitHub Copilot app, the GitHub Copilot CLI, and Visual Studio Code sessions that use Agent Host. They apply to shell commands, file reads and edits, and network domain access, giving enterprise admins consistent guardrails across these surfaces without disabling agent workflows entirely.

_Teams standardizing Copilot agent policy across tools can track rollout details like this on daily.dev._

## Similar posts on daily.dev

- [Manage GitHub Copilot app access with a dedicated policy](https://daily.dev/posts/manage-github-copilot-app-access-with-a-dedicated-policy-xpwddadpz) · GitHub Changelog · 0 upvotes · 0 comments
- [GitHub Copilot CLI Reaches General Availability](https://daily.dev/posts/github-copilot-cli-reaches-general-availability-kwflfu4u5) · InfoQ · 0 upvotes · 0 comments
- [Delegate AI controls management to members of your enterprise](https://daily.dev/posts/delegate-ai-controls-management-to-members-of-your-enterprise-7gwl6vd9a) · GitHub Changelog · 0 upvotes · 0 comments
- [GitHub Copilot app: The agent-native desktop experience](https://daily.dev/posts/github-copilot-app-the-agent-native-desktop-experience-wcmfud14a) · GitHub Blog · 2 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security), [#github](https://daily.dev/tags/github), [#vscode](https://daily.dev/tags/vscode), [#agentic-ai](https://daily.dev/tags/agentic-ai)

[View this post on daily.dev](https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Enterprise managed permissions for GitHub Copilot agent operations","url":"https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst"},"datePublished":"2026-09-09T21:24:29.814Z","dateModified":"2026-09-14T07:45:17.093Z","description":"GitHub Copilot Business and Enterprise administrators can now centrally control agent operations through managed permissions covering shell commands, file...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3357499096d1ac937ef893ebb45547cb?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3357499096d1ac937ef893ebb45547cb?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"GitHub Changelog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"GitHub Changelog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/15004b7835da4d89b02b115871f0f6dc","url":"https://daily.dev/sources/github_updates"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,github,vscode,agentic-ai","timeRequired":"PT1M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"GitHub Changelog","item":"https://daily.dev/sources/github_updates"},{"@type":"ListItem","position":3,"name":"Enterprise managed permissions for GitHub Copilot agent operations"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/enterprise-managed-permissions-for-github-copilot-agent-operations-4pjrv8sst#faq","mainEntity":[{"@type":"Question","name":"How can I control what GitHub Copilot agents are allowed to do in my enterprise?","acceptedAnswer":{"@type":"Answer","text":"GitHub now provides enterprise managed permissions that let administrators of Copilot Business or Copilot Enterprise centrally control agent operations, deciding which shell commands, file reads/edits, and network domain access are blocked, require human approval, or can proceed automatically. These restrictions cannot be weakened by individual user settings, workspace settings, auto-approval, or previously saved approvals, and different policies can be set per team. Admins locking down AI agent behavior can follow daily.dev for updates on Copilot governance controls."}},{"@type":"Question","name":"Where are GitHub Copilot's new enterprise managed permissions available?","acceptedAnswer":{"@type":"Answer","text":"The managed permissions controls are generally available in the GitHub Copilot app, the GitHub Copilot CLI, and Visual Studio Code sessions that use Agent Host. They apply to shell commands, file reads and edits, and network domain access, giving enterprise admins consistent guardrails across these surfaces without disabling agent workflows entirely. Teams standardizing Copilot agent policy across tools can track rollout details like this on daily.dev."}}]}
```

