September 13, 2026: GitHub announced enterprise-managed sandbox policies for Copilot in JetBrains IDEs on September 8. The feature is in public preview, giving administrators centralized control over the environment available to coding agents.

What changed

According to GitHub’s release announcement, managed policies cover sandbox enablement, filesystem and network access, proxy configuration, developer-tool access, and macOS Keychain access. Organization restrictions override user settings, and affected IDE controls are locked and marked as managed.

The GitHub Copilot > Sandbox settings appear when the organization enables the Editor Preview feature flag or manages a setting that enables or disables the sandbox. Without either condition, the settings are hidden. The release also adds enterprise policy diagnostics to check whether device policies are detected and enforced.

Why this matters for QA engineers

For teams asking an agent to repair Selenium tests or investigate a failing build, environment access can affect the result. A blocked dependency download or unavailable fixture directory may look like an application failure. Our QA takeaway: record the effective policy alongside the test outcome so reviewers can distinguish environment restrictions from defects.

What to verify in a pilot

These are suggested rollout checks, not results of a QATechTools product test:

  • Policy visibility: confirm managed settings appear and cannot be loosened through the IDE controls.
  • Boundary behavior: use disposable fixtures to check an allowed project path and a deliberately denied path, then test permitted and restricted network destinations.
  • Test workflow compatibility: run a small existing suite and capture dependency, cache, and local-service failures before expanding adoption.

Preview limits to keep in view

GitHub’s linked local sandbox configuration documentation says local sandboxes remain subject to change and Windows local sandboxing requires a Windows Insiders build. That page describes the CLI configuration interface; it should not be treated as a JetBrains UI walkthrough. Verify platform support and policy behavior on your own pilot devices.

Start with one representative test repository and retain its policy diagnostics with the run evidence. The immediate opportunity is to evaluate controlled agent execution while checking that everyday QA workflows still work.