{"meta":{"title":"Governing Copilot to support developer productivity","intro":"Set a governance posture that balances compliance requirements with developer productivity, so your rollout succeeds from day one.","product":"GitHub Copilot","breadcrumbs":[{"href":"/en/copilot","title":"GitHub Copilot"},{"href":"/en/copilot/tutorials","title":"Tutorials"},{"href":"/en/copilot/tutorials/roll-out-at-scale","title":"Roll out at scale"},{"href":"/en/copilot/tutorials/roll-out-at-scale/govern-at-scale","title":"Govern at scale"},{"href":"/en/copilot/tutorials/roll-out-at-scale/govern-at-scale/govern-for-adoption","title":"Govern for adoption"}],"documentType":"article"},"body":"# Governing Copilot to support developer productivity\n\nSet a governance posture that balances compliance requirements with developer productivity, so your rollout succeeds from day one.\n\nGetting the most from GitHub Copilot means finding the right balance between governance and developer access. Too restrictive, and developers can't use the features that make them productive. Too permissive, and you may not meet your compliance requirements.\n\nThis guide covers the governance decisions that help your developers get value from Copilot quickly, while keeping your enterprise within its compliance boundaries. You should make these decisions during initial setup, and revisit them as your usage matures.\n\n## Delegate Copilot administration to people with AI context\n\nPolicy decisions work best when they're informed by practical experience with AI tools. Custom enterprise roles let you delegate AI administration to subject matter experts.\n\nThis approach reduces bottlenecks and helps ensure that the people setting policies understand how developers actually work with Copilot.\n\nFor step-by-step instructions on creating an AI manager role, see [Establishing AI managers in your enterprise](/en/copilot/tutorials/roll-out-at-scale/govern-at-scale/establish-ai-managers).\n\n## Review and enable features promptly\n\nDevelopers get the most value from Copilot when they can access new features and models as they become available. When there are significant feature gaps, due to features remaining disabled, developers may turn to third-party tools that sit outside your compliance controls.\n\nConsider enabling vetted capabilities promptly, rather than disabling features by default and enabling them only after review:\n\n* **Enable new features as they become available**, unless you have a specific compliance reason not to. GitHub vets all features and models before release.\n* **Enable new models automatically**. By default, most new generally available models are enabled automatically. We recommend keeping the **Default availability for released models** policy enabled and only explicitly disabling individual models that you do not want to be available.\n* **Only set enterprise-level defaults to disabled for non-negotiables**, such as compliance-critical controls or features that conflict with regulatory requirements.\n* **Scope restrictions to sensitive organizations**. Rather than blocking features enterprise-wide, disable them only in organizations with stricter compliance requirements. This lets other organizations move faster.\n\n### Spend management and policy posture\n\nSpend controls interact with your policies. If you enable advanced models and agentic features but set tight budget limits, developers may not be able to use those features consistently.\n\nWhen configuring policies and budgets, consider whether your limits align with how you want developers to use Copilot.\n\n## Use pre-vetted LLM models\n\nIf your organization already has a vetted LLM provider for compliance, cost management, or existing contracts, you can use those API keys with Copilot instead of going through a separate approval process for GitHub-hosted models.\n\nIf you don't have an existing LLM provider relationship, this approach is optional. GitHub-hosted models are ready to use immediately.\n\nThis approach offers several advantages:\n\n* **Governance and compliance**: Use LLM providers that already meet your organization's policies and regulatory requirements.\n* **Cost management**: Align with existing payment methods, contracts, credits, or negotiated rates.\n* **Visibility and control**: Monitor usage through your provider's existing dashboards and billing.\n\nFor setup instructions, see [Enabling custom models for GitHub Copilot in your enterprise](/en/copilot/how-tos/administer-copilot/manage-for-enterprise/enable-custom-models)."}