Skip to content
← Back to blog
CopilotArticle

GitHub Copilot MCP and Code Review: Set Team Permissions

Configure GitHub Copilot MCP and Code Review with clear feature policies, server permissions, write boundaries and costs before a team rollout.

Author

Syntalith

Published Updated 2 min read

Copilot can retrieve an incident or specification through MCP and use it when reviewing code. That context can help connect a change to the actual requirement. It also makes the tool account and its permissions part of the review design.

GitHub's documentation, checked on 1 October 2026, warns that configured MCP tools for Copilot cloud agent and code review can be used autonomously, without approval before each call. Configure limits in the tool and its account. Repository MCP configuration.

Separate feature policy from server access

Organisation policy controls feature availability. Repository configuration selects servers and tools. The server account determines which data and operations those tools can actually access.

Reading a documentation collection needs a suitably restricted account. A tool that writes an issue needs a separate decision. An instruction saying “do not change data” does not remove a token's write permission.

The MCP servers in Copilot policy applies to relevant Copilot features. It does not control use of the GitHub MCP server in other applications such as Claude or Cursor. GitHub policy documentation.

Check who shares the configuration

Repository MCP configuration is shared by cloud agent and code review. Adding a server for one use can affect the other. GitHub documents a separate Allow Copilot to use MCP tools when reviewing pull requests setting under Code review.

List the required tool names before adding a server. GitHub recommends explicitly allowing selected read-only tools. A wildcard can enable operations the team does not need. Also check whether the server operator can change a tool's behaviour independently of the client configuration.

Compatibility has limits. The documented integration supports MCP tools, rather than resources and prompts, and does not currently support remote MCP servers that require OAuth. A server working in a desktop client is not proof that it works in GitHub's integration.

Trial a discount-calculation fix

In this proposed exercise, the team provides an approved discount specification and a bug report. The reviewer should compare the code with the rule, identify a missing case and cite the requirement. It does not need permission to edit prices.

Include an inaccessible issue, an unknown identifier and a document containing unrelated instructions. Expect a clear indication of missing context and no expansion of authority. Sensitive source details should not be copied into a comment visible to a wider audience.

Verify important findings in the code or with a test. A person still reviews the change before merging. A model's review does not establish that the whole application is correct.

Measure review quality and cost

Use known changes and defects to record useful findings, false alarms, omissions and human review time. If extra comments make the process slower, narrow the assignment or improve its context.

Budget for the Copilot plan, additional usage, the MCP service and repository preparation. Confirm billing terms in the organisation account. Syntalith's technical AI-Native course is quoted after reviewing the repository; a process audit starts at €600 excluding VAT and has a different scope. See pricing.

Describe the repository and context sources so we can scope the trial. Also review the Copilot default policy taking effect on 22 October.

Free process scan

Start with a free process scan.

  • A 30-minute call with the engineer who would lead the work.
  • A review of the processes that cost you the most time and money.
  • A written summary: a possible direction, missing information and the next step.

The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.

€0

30 minutes · written takeaway within 2 business days

Book a free process scan (30 min)

Times are shown in your own time zone. We work with clients across time zones.

Describe the process in the form