ToolScout
Product update ยท 28 September 2026

GitHub Copilot adds local sandboxing and agent observability

GitHub is adding stronger execution boundaries and monitoring for Copilot agents, alongside a broader choice of AI models.

What changed

GitHub Copilot now offers local sandboxing in public preview in the Copilot app. Teams can restrict agent access to files, networks and credentials on a project basis. If the operating system cannot enforce the requested policy, the sandboxed shell fails instead of silently running without the restriction.

GitHub has also added OpenTelemetry configuration through enterprise-managed settings. Administrators can export agent activity to compatible monitoring tools, trace model and tool interactions and investigate unexpected behavior. The same weekly release expands Copilot model choice with GPT-6 Sol, GPT-6 Luna, Claude Opus 5.5 and Grok 4.7 on eligible plans.

Why it matters

As coding assistants become agents that execute commands and use tools, model quality is only part of the buying decision. Execution isolation and observability determine how confidently teams can allow agents to work with repositories, credentials and development environments.

Buyer takeaway

For teams evaluating AI coding platforms, GitHub is increasingly packaging model choice, agent execution, security policy and monitoring inside one environment. Local sandboxing is still a preview and is off by default, so buyers should validate operating system support and enterprise policy behavior before treating it as a production security boundary.

Primary sources: GitHub local sandboxing announcement, GitHub OpenTelemetry announcement and GitHub Copilot weekly release. ToolScout writes independent summaries and analysis. Affiliate relationships do not determine coverage.
More software news