Pimp My IDE / Garage dispatch
Back to garage
September 28, 2026 | GitHub Copilot / enterprise policy

A valid policy file is not proof that the policy reached the editor.

GitHub added validation for enterprise-managed Copilot settings. Good. Now keep syntax, scope, delivery, and observed client behavior on separate circuits.

The new validator closes a real hole.

GitHub's enterprise validator checks managed Copilot settings for malformed JSON, unsupported configuration, invalid team mappings, and related errors. It points administrators to the affected file and JSON path. The checked repository files include copilot/managed-settings.json, copilot/team-mappings.json, and the team files referenced by that map.[1]

This catches failures that used to look deceptively complete. A file could exist on the default branch while a bad key or team slug kept the intended rule from taking effect. The validator turns that hidden parse failure into a named repair.

Validation proves that the control plane can read the policy. It does not prove what one editor did with it.

Coverage changes by client and property.

GitHub lists Copilot CLI, VS Code, the GitHub Copilot app, the cloud agent, and JetBrains IDEs as supported clients. The same documentation warns that not every client supports every property. GitHub also documents team-specific overrides through team-mappings.json and separate files under copilot/teams/.[2]

That makes scope a separate test. Record the client, version, billing enterprise, team membership, and expected winning rule. "Valid JSON" is too small a receipt for a policy with inheritance and overrides.

Delivery has its own clock.

For server-managed settings, GitHub says supported clients receive updates within about an hour. Restarting the client or signing in again triggers a refresh. Mobile-device-management clients check hourly, while file-based deployments load an updated file after restart.[2]

A clean validator followed by an immediate spot check can produce a false alarm. A clean validator followed by no client check can produce false confidence. Put the delivery method and observation time in the packet.

Defaults can change the blast radius.

GitHub also announced a global default policy for eligible Copilot features. The options cover enabled, disabled, and delegated administration. GitHub says the policy applies to eligible settings on the Features and clients page, Copilot Code Review, and MCP servers in Copilot policy. The announced change takes effect on October 22 after a 28-day configuration period.[3]

A default is part of the policy, even when nobody touched a team file. Review it beside explicit overrides. Then test one expected allow and one expected deny on a real client.

Interactive makeover / policy release

Managed policy proof rack

Traditional purpose replaced: merge a policy file and trust the green validator. Better version: close four distinct circuits and copy a packet that still asks for the host, client version, revision, and observed result.

Close each circuit with evidence

The bus lights only through the first open circuit. A later check can be selected, but it cannot hide an earlier gap.

Evidence bus
0 of 4 circuits selected. Route blocked at Parse.The packet structure is available. Evidence still needs review.
Copyable release packet

Keep blank evidence visible

Selections add the fields you intend to collect. They do not fill those fields or prove the policy.

What this rack proves. It keeps four release questions and required evidence fields in one handoff. It does not contact GitHub, inspect a repository, identify a user, refresh a client, or run an allow or deny test.

Sources and limits

Open the source log
  1. GitHub Changelog, "Enterprise managed settings in-product validator", read September 28, 2026. GitHub describes the validator, covered files, reported issue types, and default-branch repair loop.
  2. GitHub Docs, "Getting started with enterprise-managed settings", read September 28, 2026. The guide documents supported clients, property coverage limits, repository layout, team overrides, validation, refresh timing, and client checks.
  3. GitHub Changelog, "Default Enablement of Copilot features for Copilot Business and Enterprise", read September 28, 2026. GitHub describes the new global default, its options, affected policy areas, exceptions link, and October 22 activation date.
  4. Visual Studio Code 1.139 release notes, read September 28, 2026. The release notes were inspected during the editorial scan. They document current agent-host and remote Dev Container behavior but do not verify GitHub enterprise policy delivery.

Source boundary. GitHub documents its own validator, settings system, delivery timing, and policy rollout. This dispatch does not independently test an enterprise account or measure enforcement latency. The proof rack is a planning tool. Its selected state means that packet sections were chosen, not that evidence was attached or accepted.