cd /news/ai-tools/manage-github-copilot-app-access-wit… · home topics ai-tools article
[ARTICLE · art-75972] src=github.blog ↗ pub= topic=ai-tools verified=true sentiment=· neutral

Manage GitHub Copilot app access with a dedicated policy

GitHub has introduced a dedicated policy for the GitHub Copilot app, allowing enterprise and organization admins to control access independently from the Copilot CLI. The policy, set to Enabled everywhere by default, offers three options: Enabled everywhere, Disabled everywhere, or Let organizations decide. This change gives admins flexibility to manage each client separately while enforcing consistent guardrails.

read2 min views1 publishedJul 27, 2026
Manage GitHub Copilot app access with a dedicated policy
Image: GitHub Changelog

The GitHub Copilot app now has its own policy, so you can control who has access to it at the enterprise and organization levels.

Until now, access to the Copilot app depended on your GitHub Copilot CLI policy being enabled. From several conversations with customers, we understand that many of you want to manage each client independently. Now the Copilot app and the Copilot CLI each have their own policy, giving you the flexibility and control to enable the right clients for your teams.

This new policy keeps your developers’ work within the guardrails you already rely on. When using this app, developers drive agent sessions in isolated workspaces and land changes through pull requests. This means the same reviews, checks, and audit history apply as they would to any other contribution. The Copilot app also joins Copilot CLI and VS Code as a supported client for enterprise-managed settings, so the guardrails you define once (e.g., which plugins developers can use) are consistently enforced in the Copilot app as well.

You’ll find this policy alongside your other Copilot policies. It’s set to Enabled everywhere by default, so your developers can start using the app right away with no action needed from you. You have three options:

Enabled everywhere gives your developers access to the app.Disabled everywhere turns the app off across your enterprise.Let organizations decide passes the choice to each organization’s admin.

If the Copilot app isn’t the right fit for your teams, set it to Disabled everywhere. Developers who open the Copilot app will see a notice that their admin hasn’t enabled it. To review or change the policy:

  • From your enterprise or organization settings, open the AI Controls tab. - Go to the “Copilot Clients” section.
  • Select the Copilot app policy. - Choose Enabled everywhere,** Disabled everywhere**, or** Let organizations decide**.

To learn more about the Copilot app, including how to get started and manage policies, explore our Copilot app documentation.

To download the Copilot app, visit our landing page

── more in #ai-tools 4 stories · sorted by recency
── more on @github 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/manage-github-copilo…] indexed:0 read:2min 2026-07-27 ·