Pimp My IDE / garage dispatch
Back to garage
October 1, 2026 | desktop agents / app approval / stop custody

Always allow is not always safe.

GitHub Copilot can now read and drive desktop apps. The launch puts app approval in the interface. The sharper control is the seam between future permission and the session already moving.

A saved approval answers which app may be controlled later. It does not stop the active operation, limit the visible data, or prove the last action landed where intended.

The desktop is now part of the agent route.

GitHub released computer use in public preview for Copilot CLI and the Copilot app on macOS and Windows. It can read accessible app content and screenshots, click controls, edit text, press keys, scroll, drag, and move through workflows across applications.[1]

This reaches the work that APIs and command lines leave behind. A presentation, an expense form, or a legacy admin screen can become part of one agent session. GitHub's own documentation still prefers an API, MCP server, terminal command, filesystem tool, or dedicated browser tool when one can do the job. Those routes return more structured information and tend to behave more predictably.[2]

Use pixels for the gap. Do not turn every structured door into a screenshot.

Approval has a time axis.

Computer use starts disabled. When an app requests control, a person can allow it for the current session, save approval for later sessions, or deny it. A saved approval is local and shared by Copilot CLI and the Copilot app on that computer. Deny rules still take priority.[2]

Here is the detail worth putting on the dashboard: removing a saved app approval blocks future sessions, but it does not revoke access already granted to a running session. Stopping the current operation is a separate action. In the CLI, GitHub documents pressing Esc twice. In the app, use Stop or Esc.[2]

That means one generic lock icon lies by omission. A useful control surface needs two indicators. One shows whether the application will ask again next time. The other shows whether this session can act now.

The screen is both input and cargo.

On macOS, the feature asks for Accessibility permission to operate controls and Screen Recording permission when visual context is needed. The screen may include personal, financial, enterprise, or third-party information. GitHub tells users to limit computer use to apps and tasks whose visible content they are willing to provide as context.[2]

Older computer-use research from Anthropic explains the same exposure in mechanical terms. A model looks at screenshots, estimates cursor movement, and acts on the next view. Anthropic also identifies on-screen prompt injection as a risk and describes the screenshot sequence as a flipbook that can miss short-lived changes. Its early system could click the wrong control or interrupt the wrong process.[3]

The specific GitHub product should be judged by GitHub's current documentation. The older Anthropic report is not evidence about Copilot's implementation or reliability. It is useful because it shows why visible content, action authority, and verification remain separate concerns across computer-use systems.

Write a desktop route before granting one.

Name the target application and the intended result. List the app regions the task may inspect. Keep credentials, unrelated windows, notifications, and other people's data outside that view. Choose session approval unless repetition has earned a saved rule.

Then write both brakes. One stops the active operation. The other removes future approval. Finish with a result check that does not depend on the same visual guess that drove the click. Read the saved file, query the destination, reopen the record, or ask a person to inspect the high-impact result.

VS Code 1.140 is also moving agent behavior into a dedicated host process that can connect the same session across windows.[4] The wider product direction is clear: sessions now travel across surfaces and applications. Permission status has to travel with equal clarity.

Interactive makeover / twin-circuit permission cabinet

Decouple the saved key from the moving car.

Traditional purpose replaced: one allowed-app list. Better version: a native approval selector drives the future-access rail, while separate stop and revoke controls expose the running-session boundary. The receipt stays a drill plan until real app and result evidence is attached.

Issue one app pass

This teaching rig changes only the diagram and receipt. It does not control an application or change Copilot settings.

Approval duration

Saved access is the widest setting. Use it only after a bounded task has a tested stop path and a result check.

Permission cutaway

Future / live circuits

Ask required
Future accessAsk
Live sessionStopped
Removing a saved rule changes the top rail. Stop changes the bottom rail.

Future access asks. No session is active.

The narrow default keeps both rails closed until a person grants the app pass.

Four fields before desktop control

Approval is only one line in the contract.

01 / TARGET

Which app, account, and window?

Name the destination. Hide unrelated windows and notifications before capture begins.

02 / SIGHT

What may cross the screen?

List visible records and excluded data. Screen access is a data route.

03 / ACTION

What may the session change?

Use the shortest approval duration. Keep high-impact submission behind a person-owned gate.

04 / RECEIPT

What proves the result?

Stop the session, inspect the destination through an independent read, and record unresolved effects.

Sources read

Source log and evidence boundary
  1. GitHub Changelog, "GitHub Copilot can now interact with desktop apps with computer use", published and read October 1, 2026. This is the product announcement for public-preview availability, supported platforms, application control, approval, and setup commands.
  2. GitHub Docs, "About computer use in GitHub Copilot", read October 1, 2026. It documents preferred structured tools, app approval duration, shared local saved approvals, deny precedence, live interruption, macOS permissions, visible-data risk, and the limit that removing saved approval does not revoke a running session.
  3. Anthropic, "Developing a computer use model", read October 1, 2026. This older first-party research describes screenshot-driven control, prompt-injection exposure, missed transient events, and early failure examples. It does not describe GitHub Copilot's implementation.
  4. Visual Studio Code 1.140 release notes, read October 1, 2026. The notes describe the Copilot harness, its dedicated agent-host process, and cross-window session connection. This supports the cross-surface context only.

Evidence boundary. GitHub's announcement and documentation describe a public-preview product. Pimp My IDE did not enable computer use, grant operating-system permissions, or run a desktop task. The twin-circuit model is editorial synthesis. The interactive cabinet is a teaching aid and generates a drill card. It does not inspect or change a real permission.