Changes confirmed medium confidence

GitHub Adds Enterprise Controls and Usage Metrics for the Copilot App

Administrators can now govern app access separately, extend managed settings into app and cloud-agent sessions, and attribute usage to individual users.

GitHub expanded enterprise controls for its Copilot app and cloud agent across July 27 and 28. Administrators can now manage app access separately from Copilot CLI, apply centrally defined settings across additional agent surfaces, and see app activity in user-level usage reports. The changes matter to organizations that want broader agent adoption without losing client-level policy or measurement.

What changed

The Copilot app now has a dedicated access policy at both enterprise and organization level. GitHub says it is enabled everywhere by default, while administrators can disable it across an enterprise or let individual organizations decide. App sessions continue to run in isolated workspaces and deliver changes through pull requests, preserving the review, check and audit path used for other contributions.

GitHub also added the Copilot app and Copilot cloud agent to its enterprise-managed settings system. A shared `managed-settings.json` file can control available plugins and plugin marketplaces, set auto model selection as the default, and decide whether users of interactive clients can bypass approval prompts before commands run or files and URLs are accessed. GitHub notes that prompt-bypass controls apply to interactive clients, not the cloud agent. Organizations already using the settings file for Copilot CLI and VS Code do not need a separate configuration path for the app.

The measurement layer changed a day later. Copilot app activity can now be attributed to individual users and included in reports broken down by feature, model and programming language. Per-user fields cover sessions, requests, prompts and token use, while code-generation, acceptance, lines-added and lines-deleted totals now include app activity. Access to these reports remains limited to authorized roles and requires the Copilot usage metrics policy to be enabled.

Why it matters

Agent governance is difficult when each client has a different policy surface. These releases bring app access, tool restrictions and usage evidence closer to one administrative model. They do not prove that Copilot improves productivity or code quality; the metrics describe activity and output, not business outcomes. Their immediate value is operational: teams can decide who may use the app, constrain which extensions reach agent sessions, and compare usage with other Copilot surfaces.

Status

Confirmed. GitHub published the access, managed-settings and metrics changes in its official changelog. Internal confidence is medium because all three pages come from the same primary vendor and lack independent corroboration.

Sources

Update note: Last reviewed 2026-07-29. We will revise this post if GitHub changes default access, supported settings or metrics availability.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.