Skip to the content.

← Daily Brief for September 9, 2026

GitHub gives enterprises central control over Copilot’s JetBrains sandbox

Focus: Technical AI Engineering
Date: September 8, 2026
Topics: GitHub Copilot, sandboxing, enterprise policy, agent security
Evidence: Unspecified
Availability: Unspecified

Layered textbook diagram showing administrator policy governing filesystem, network, proxy, tools, keychain, and terminal access inside a sandboxed IDE agent workspace.

Summary: GitHub added enterprise-managed sandbox policies for Copilot in JetBrains IDEs. Administrators can centrally control sandbox enablement, filesystem and network access, proxy settings, developer tools, and macOS Keychain access; managed restrictions override local user settings and policy diagnostics show whether controls are enforced.

Why it matters: Agentic coding tools increasingly operate across files, terminals, and external services. Central policy converts safety from a developer preference into an enforceable organizational boundary. The sandbox controls are in public preview, and the broader release also includes preview features, so teams should validate behavior on their own platforms before relying on it.

Original commentary: Use this as a concrete governance example in agent training: define allowed resources centrally, lock high-risk controls, and verify enforcement with diagnostics rather than trusting written instructions alone.

Source: Enterprise-managed sandbox in Copilot for JetBrains


← Daily Brief for September 9, 2026