According to DevOps.com; the source materials contain no primary source.

GitHub opened a public preview of centrally managed policies for the Copilot sandbox, a restricted environment for running commands, in JetBrains IDEs. The policies give administrators control over Copilot access to the file system and network.

An administrator can set a proxy, access to developer tools, and Keychain access on macOS. A locked setting appears as managed in the JetBrains plugin, and a developer cannot change it locally.

Claim check:

  • GitHub opened a public preview of centrally managed Copilot sandbox policies in JetBrains IDEs. (confirmed only by the carrying publication: evidence; «Enterprise-managed sandbox policies for Copilot in JetBrains are now in public preview»)
  • The policies give administrators control over Copilot access to the file system and network. (confirmed only by the carrying publication: evidence; «they let IT teams centrally set what a sandboxed Copilot session can and can’t do: whether sandboxing runs at all, what filesystem and network paths it can reach»)
  • An administrator can set a proxy, access to developer tools, and Keychain access on macOS. (confirmed only by the carrying publication: evidence; «which proxy it routes through, whether it can touch developer tools, and — on Mac — whether it gets access to the Keychain»)
  • A locked setting appears as managed in the JetBrains plugin, and a developer cannot change it locally. (confirmed only by the carrying publication: evidence; «Once an admin locks a setting, it shows up in the JetBrains plugin marked “(managed),” and developers can’t override it locally.»)

Publications:

score 74.2 · kind release · revision 2 · stories st-15h2ql8