GitHub has made local sandboxing generally available for GitHub Copilot, letting developers restrict what its agent tools can access on their computers. The feature comes with GitHub Copilot without an extra charge and covers GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions that use Agent Host. Developers or their organizations set the policies governing those restrictions.
The controls apply to commands and tools that Copilot starts, with restrictions covering files, network connections, credentials and other capabilities of the host system. Developers can specify which directories and files those commands may read, as well as which ones they may change. GitHub says the boundary is intended to let developers use more autonomous agent workflows while retaining control over the resources Copilot can reach.
Network policies let developers govern connections both to the internet and to local networks from tools running under Copilot. Credential controls also cover Git credentials and credentials used by GitHub CLI, bringing those forms of access within the developer’s or organization’s sandbox policy. These restrictions govern tool execution on the developer’s own machine.
Organizations can use enterprise-managed settings to make sandboxing mandatory for developers, rather than leaving adoption to each individual. They can also enforce policies that developers are unable to loosen, giving organizations a way to keep required access limits in place during local agent work.
The same approach extends to local services and tools, with support for local MCP and language servers where that capability is supported. Microsoft eXecution Container (MXC) provides the underlying mechanism, converting a shared sandbox policy into operating-system-specific controls for Linux, Windows and macOS.
The access restrictions apply regardless of the model selected in Copilot, so choosing a different model does not change which sandbox policy governs tool execution. GitHub distinguishes the execution of the model from isolation of the tools it uses.
Separately, GitHub made Claude Haiku 5.5 generally available in Copilot on October 7, describing it as designed for quick edits, terminal work and subagents. On October 2, GitHub also made API requests for Copilot code review generally available across its Pro, Pro+, Max, Business and Enterprise plans, with Balanced becoming the default effort level for reviews.













