GitHub has made local sandboxing for Copilot generally available in the Copilot CLI, the GitHub Copilot app, and VS Code sessions that use Agent Host. The feature provides a secure execution boundary for agentic workflows on developers’ own machines.
WHAT LOCAL SANDBOXING DOES
Sandbox policies govern how tools and commands initiated by Copilot can access system resources. Sandboxes restrict access to the filesystem, network, credentials, and other capabilities, based on policies defined by the developer or their organization. TechStaged has also covered GitHub Copilot PR Context Makes AI Code Review Easier to Manage.
CAPABILITIES AND CONTROLS
Local sandboxing translates a common sandbox policy into native OS controls so it works across Windows, macOS, and Linux. Developers can implement protections such as:
- Limit which files and directories Copilot agents can read or modify
- Control access to the internet and to local networks
- Restrict access to Git credentials and GitHub CLI credentials
- Apply sandboxing to local tools and services (including local MCP and language servers where supported)
- Enforce enterprise-managed settings to require sandboxing and prevent policy weakening
WHERE IT’S AVAILABLE AND AT WHAT COST
The feature is available in GitHub Copilot across Copilot CLI, the Copilot app, and VS Code sessions using Agent Host. Local sandboxing is included with GitHub Copilot at no additional cost.
ENTERPRISE CONTROLS AND POLICY FIDELITY
Organizations can define and enforce sandbox policies to ensure developers cannot bypass protections. Sandboxing policies apply to tool execution regardless of which Copilot model is used.
GETTING STARTED
GitHub’s documentation points developers to the About cloud and local sandboxes for GitHub Copilot for setup and guidance on policy configuration and enforcement.
RELATED COVERAGE
SOURCES
- Archive: 2026 - GitHub Changelog: Local sandboxing for GitHub Copilot now generally available Published · Primary source







