The window is a controller, not the engine.
Visual Studio Code 1.140 adds a Copilot harness that runs in a dedicated Agent Host process. The host owns agent sessions. Clients can display and control those sessions from more than one window.[1]
The Agent Host documentation draws the process boundary plainly. The host can run locally, in a Dev Container, or on a remote machine. File edits and commands run in the environment that contains the host. A browser or desktop window can disconnect while a turn continues.[2]
Moving the steering wheel does not move the garage.
Placement chooses a machine, not a workspace.
The experimental remote delegation tools can list connected hosts, inspect their operating systems and capacity, and create a remote session. Automatic placement matches the requested operating system, memory, CPU count, and optional model. It favors the matching host with the lightest session load.[1]
That machinery does not copy the originating workspace. A delegated session has no workspace unless the request names one. Repository work must use an existing trusted folder on the target host or a new worktree there.
A connected host still needs an authority record.
The remote session keeps normal approvals. This matters because host selection can feel like permission even when it is only placement. Write access, shell commands, network reach, credentials, and merge authority remain separate decisions.
The remote-session guide warns that an unauthenticated dev tunnel can let anyone who finds its URL reach the machine and start sessions. It calls out the added danger of auto-approval modes. Authentication and approval policy belong on the dispatch card, not in an assumed default.[3]
The return path is part of the job.
The experimental delegation flow uses one tool to inspect a remote session and another to send a follow-up or report back. The coordinating Agents window must stay open and connected for those messages to flow. Final answers are not forwarded by implication.[1]
Record who receives a question, what happens when the client is gone, and where the final patch or report lands. A remote process can keep running after the person who launched it has lost the conversation.
Tool changes need their own receipt.
The GitHub Copilot SDK exposes the Copilot CLI engine through JSON-RPC. Its README says first-party tools are exposed by default and applications can approve, deny, or customize tool calls through permission handlers.[4]
The October 2 preview release adds an experimental way to replace client-supplied tools and handlers during a live session. Built-in, MCP, and plugin tools are unaffected by that call. A tool update is therefore narrower than a complete authority reset. Record which tool set changed and which tools did not.
Dispatch four contracts.
Use one line each for host, workspace, authority, and return. Add the exact task, model, revision, stop route, and expected artifact. Leave unknown fields marked as unknown.
The relay below prepares that record. It does not connect a host, validate a folder, change permissions, or prove that a result returned. Those checks happen in the real session.