GitHub made enterprise-managed permissions for Copilot agent operations generally available (Copilot Business + Enterprise; Copilot app, CLI, and VS Code sessions using the Agent Host): admins set block/ask/allow policies for shell commands, file read/edit, and network domains, overriding user/workspace settings, auto-approvals and saved approvals, with per-team policies. A companion JetBrains enterprise-managed sandbox (public preview, 9/8) locks sandbox enablement, filesystem/network access, proxy settings, dev-tool access and macOS Keychain access to org-managed policy. The same-week Copilot release wave added: Jira integration in the Copilot app (issues on a shared canvas feeding investigation/implementation/PR prep), experimental 'Project HydraFusion' adaptive model routing in Copilot CLI, VS Code 1.137 scheduled agent automation (hourly/daily/weekly or on-demand, public preview) plus experimental voice mode, and MAI-Code-1-Flash deprecated in favor of MAI-Code-1.1-Flash.
Agent governance has moved from vendor talk to org-policy surfaces: the same block/ask/allow model Claude Code ships as managed settings is now GA across Copilot's app/CLI/IDE fleet, and the JetBrains sandbox preview extends it to the IDE. Combined with scheduled automation, Copilot agents can now run unattended inside org-defined guardrails — the governance half of the always-on agent stack.
| Managed Permissions Ga | 2026-09-09, GA; Copilot Business + Enterprise; applies to Copilot app, CLI, VS Code sessions on Agent Host; block/ask/allow for shell commands, file read/edit, network domains; overrides user/workspace settings, auto-approvals, saved approvals; per-team policies |
|---|---|
| Jetbrains Sandbox Preview | 2026-09-08, public preview; org-managed: sandbox enablement, filesystem/network access, proxy settings, dev-tool access, macOS Keychain access; controls locked in-IDE |
| Weekly Wave 2026 09 10 | Jira integration in Copilot app (shared canvas -> investigation/implementation/PR); 'Project HydraFusion' experimental adaptive routing in Copilot CLI (/experimental); VS Code 1.137 scheduled agent automation (public preview) + experimental voice mode + Agents-window issue/PR review without opening the repo (experimental) |
| Models | MAI-Code-1-Flash deprecated across all Copilot surfaces -> MAI-Code-1.1-Flash (admin-enabled via model policy) |
| Usage Metrics 2026 09 11 | GA 1-day and 28-day enterprise/organization reports add daily_active_vscode_agent_users, totals_by_vscode_agent session_count and total_user_messages, plus per-user used_vscode_agent; measures the dedicated VS Code Agents window |