GitHub Copilot logoGitHub Copilotby GitHub
Govern · GitHub Copilot

Copilot's agents, governed in the IDE and in Actions.

GitHub Copilot is no longer a completion engine. Agent mode runs commands and calls MCP servers from the IDE, and the coding agent takes issues, works in GitHub Actions and opens pull requests. Agen judges each action at runtime, against the developer behind it, and records the verdict.

Enforced on the endpointAgenShieldStopped on the device, before execution. The gateway's verdict, enforced where the gateway cannot see.
<30ms
per-action verdict at runtime
2
surfaces governed: endpoint and cloud
1:1
a named developer behind every run
1 day
from install to governing

How Agen governs GitHub Copilot

  • AgenShield governs agent mode on the device: every file write, terminal command and MCP call is judged before it executes.
  • The Copilot coding agent, running in GitHub Actions, is governed where it touches your repositories and systems, tied to the developer who assigned the work.
  • Each action resolves to the developer's identity from your IdP. Copilot acts as a governed principal, not as a seat.
  • Policy returns a verdict in under 30ms: allow, mask, step up, hand to a human, or deny. Only the crossing action stops.
  • Enterprise Copilot policies, content exclusions and MCP registry settings stay in place. Agen adds the central verdict and the per-action record.
What GitHub Copilot reaches

Two agents, one credential set.

Copilot acts inside the editor and inside GitHub itself. Both reach your code with permissions someone already granted.

Agent mode in the IDE
Edits files, runs terminal commands and iterates on errors inside VS Code, JetBrains and other editors, with the developer's local privileges.
The coding agent in Actions
Takes an assigned issue, works in a GitHub Actions environment, and opens a pull request with the changes.
MCP servers
Connects to tools registered for the organisation or configured per developer, including GitHub's own MCP server.
Repository access
Reads and writes across every repository the developer or the installation can reach.
Copilot Workspace and Spaces
Plans and executes multi-file changes with organisation context attached.
Copilot on GitHub.com
Acts on pull requests, issues and code review from the web, with the same account.
Where the native controls stop

Enterprise policy turns features on and off. It does not judge the action.

Copilot's enterprise settings, content exclusions and branch protections are the right controls to keep. They decide what is available, not what a given action should be allowed to do.

01

Feature toggles, not verdicts

Policies enable agent mode, MCP and the coding agent for the organisation. Once enabled, the individual action is decided in the editor by the developer, or not at all.

decision granularityfeature, not action
02

A seat is not an accountable owner

Copilot is licensed per seat and commits under the developer's identity. Nothing distinguishes what the person chose from what the agent chose.

author fielda person's name
03

The coding agent runs where no endpoint control runs

It works inside an Actions runner with the repository access it was granted. Device tools cannot see it, and IDE settings do not apply.

visible to endpoint toolsno
04

Audit logs record usage, not decisions

GitHub's audit log shows that Copilot was used. It does not show each action, the policy it was judged against, or who was accountable when it crossed the line.

per-action verdict lognone
How Agen governs it

One policy for the IDE and the Actions runner.

The gateway decides. Shield enforces where the gateway cannot see. Agent-mode actions are stopped on the device by AgenShield. Coding-agent actions are decided at the gateway where they reach your repositories. Same rules, same identity, one record.

01 · Discover
Find every Copilot agent
Endpoint and repository telemetry surface agent-mode usage, coding-agent runs, and every MCP server in use across the organisation.
02 · Identify
Tie every run to a developer
IDE sessions and coding-agent runs resolve to the developer's identity from your IdP. Copilot becomes a governed principal with a named owner.
03 · Govern
Judge each action in-line
File writes, terminal commands, MCP calls and repository changes are evaluated per action against policy and identity. Verdict in under 30ms.
04 · Evidence
Record the chain
Every action and verdict logged with developer, repository, command and decision, across both surfaces, exported to your SIEM.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

Copilot's agent mode runs on the developer's machine, so AgenShield does the work: the gateway's verdict, enforced where the gateway cannot see. BrowserShield covers what the same developer pastes into AI tools in the browser. The coding agent in Actions is decided at the gateway where it reaches your repositories.

AS
On the device
AgenShield
Primary for GitHub Copilot

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · Copilot agent mode · dev-mbp-092blocked
Actionread · .env.production
Stoppedon device, before execution
Verdict27ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · github.com/copilotpaste blocked
Detectedpersonal access token in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What Copilot asks to do, and what policy says.

Illustrative verdicts for common GitHub Copilot actions under a typical policy.

Typical per-action verdicts for GitHub Copilot
GitHub Copilot actionVerdictWhy
Agent mode edits files inside the workspaceallowIn scope for the developer and the task. Logged, not interrupted.
Agent mode runs the test suiteallowNormal engineering work on the developer's own machine.
Agent mode reads a credentials filedenyA credential has no place in an agent's context. Blocked before the read completes.
Coding agent opens a pull request to a protected branchhuman-in-the-loopThe assigning developer reviews before the change reaches the branch.
Coding agent modifies a workflow filestep-upA change to CI is a change to what runs with secrets. The owner confirms.
Query a customer database through an MCP servermaskThe query runs. Personal data is masked before it enters the model context.
Call an MCP server outside the organisation registrydenyNot an approved door. Blocked and logged with the developer who tried.
Push generated secrets to a remotedenyRecognised at the point of exfiltration and blocked in-line.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See GitHub Copilot governed, live.

Thirty minutes on the way your teams already use GitHub Copilot. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your GitHub Copilot setup
you seeevery action decided at runtime
Watch it happen

Agent mode reaches for a secret. On a laptop.

It never crosses your network controls, and no log outside that machine would record the attempt. AgenShield stops it on the device.

on-device block · live product scene
From install to governing

Rolled out like software. Copilot policies stay as they are.

Copilot stays exactly as your engineers use it today, in the editor and on GitHub.

Day 1
Ship AgenShield through your MDM
The endpoint agent deploys to developer machines with the tooling you already use.
Day 1
Connect your IdP and GitHub organisation
Sessions resolve to developers through your IdP. The organisation connection brings coding-agent runs under the same policy.
Week 1
Run observe-only
See every agent-mode and coding-agent action across the organisation before enforcing anything.
Week 2
Turn on the policies that matter
Start with credentials, protected branches and workflow files. Developers only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern GitHub Copilot and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace Copilot's enterprise policies and content exclusions?
No. Keep them. They decide what Copilot features are available. Agen decides what each individual action is allowed to do, anchored to the developer's identity, and records the decision.
How is the coding agent governed if it runs in GitHub Actions?
It acts on your repositories and connected systems, and that is where it is judged, tied to the developer who assigned the issue. The same policy applies as on the device.
Does it slow agent mode down?
No. The verdict returns in under 30ms on the device, in-line with the action.
Does this work with Copilot in JetBrains and other editors?
Yes. AgenShield governs the action on the device regardless of which editor hosts the agent.
Is this sold to individual developers?
No. Agen is deployed by the security or platform team across the fleet. Developers keep using Copilot as they do today.

Govern GitHub Copilot without taking it away.

One policy plane for the IDE and the Actions runner, a named developer behind every run.