# GitHub Copilot Agent in Microsoft Agent Framework: Permissions, Streaming, Approvals

> Wrap the GitHub Copilot harness with Microsoft Agent Framework in .NET and Python: permission gates, MCP servers, custom tools, streaming and approvals.

- **Published**: 2026-08-19
- **Category**: AI Infrastructure
- **URL**: https://agentpedia.codes/blog/microsoft-agent-framework-github-copilot-agent-guide

---

> **Important callout**

**Bottom line:** The GitHub Copilot Agent in Microsoft Agent Framework is now released and stable for both .NET and Python. Copilot's CLI and SDK own the agent loop, while Agent Framework supplies instructions, tools, streaming, middleware, observability, and human-in-the-loop approval. Every shell, file, and URL capability is gated by a permission handler you write.

Microsoft [announced the GitHub Copilot Agent integration](https://devblogs.microsoft.com/agent-framework/build-production-ready-agents-with-the-github-copilot-harness-and-agent-framework/) as released and stable for .NET and Python. The design splits responsibilities: GitHub Copilot provides a powerful coding harness with shell execution, file read/write, URL fetching, and MCP tools, while Agent Framework adds the abstractions developers need around it -- a consistent run interface, permission gates, middleware, observability, streaming, and approval workflows.

This guide covers the quickstart in both languages, permission handling for system capabilities, MCP servers, custom tools with approval gates, session management, and production patterns.

## What the GitHub Copilot Agent integration is

The GitHub Copilot agent is an Agent Framework agent backed by the GitHub Copilot CLI and SDK. Copilot owns the agent loop: model calls, tool invocation, planning, and session state. Agent Framework gives you a consistent surface for instructions, tools, streaming, middleware, observability, and human-in-the-loop approval.

The result is an agent with Copilot's built-in coding-agent capabilities -- shell execution, file read/write, URL fetching, and MCP tools -- wired into the same run interface as every other Agent Framework provider.

This matters for teams that want production coding agents without rebuilding the agent loop. You get Copilot's proven harness and Agent Framework's governance and observability, instead of choosing between them.

## Prerequisites

- **.NET:** the `GitHub.Copilot` and `Microsoft.Agents.AI` packages, and a Copilot CLI/SDK available on the machine.
- **Python:** the `agent_framework[github]` packages, plus the `copilot` package for the session and permission modules.
- A working GitHub Copilot CLI login for the machine that runs the agent.

Package names and access requirements can change; verify against the current Agent Framework documentation before installing.

## .NET quickstart

Start a Copilot client, turn it into an `AIAgent`, and run it:

```csharp
using GitHub.Copilot;
using GitHub.Copilot.Rpc;
using Microsoft.Agents.AI;

// Start a Copilot client and turn it into an AIAgent.
await using CopilotClient copilotClient = new();
await copilotClient.StartAsync();

SessionConfig sessionConfig = new()
{
    OnPermissionRequest = (request, invocation) =>
        Task.FromResult(PermissionDecision.ApproveOnce()),
};

AIAgent agent = copilotClient.AsAIAgent(sessionConfig, ownsClient: true);

AgentResponse response = await agent.RunAsync("Summarize what this project does.");
Console.WriteLine(response);
```

Streaming works through `RunStreamingAsync(...)`.

## Python quickstart

The same flow in Python:

```python
import asyncio
from agent_framework.github import GitHubCopilotAgent, GitHubCopilotOptions
from copilot.session import PermissionHandler


async def main() -> None:
    async with GitHubCopilotAgent(
        instructions="You are a helpful assistant.",
        default_options=GitHubCopilotOptions(
            on_permission_request=PermissionHandler.approve_all,
        ),
    ) as agent:
        result = await agent.run("Summarize what this project does.")
        print(result)


if __name__ == "__main__":
    asyncio.run(main())
```

Python streaming uses `run(..., stream=True)`.

## Permission gates for system capabilities

Copilot's harness comes with the abilities a coding agent needs, and you opt in to each one through the permission handler:

- **Shell execution** -- run commands, scripts, and system tools.
- **File operations** -- read existing files and write new ones.
- **URL fetching** -- pull in and process web content.

Every capability is gated by a permission request. The handler receives each request and returns an approve or deny decision, so the agent can only do what you explicitly allow.

.NET:

```csharp
static Task<PermissionDecision> PromptPermission(PermissionRequest request, PermissionInvocation invocation)
{
    Console.WriteLine($"[Permission Request: {request.Kind}]");
    Console.Write("Approve? (y/n): ");
    string? input = Console.ReadLine()?.Trim().ToUpperInvariant();
    return Task.FromResult(input is "Y" or "YES"
        ? PermissionDecision.ApproveOnce()
        : PermissionDecision.Reject());
}
```

Python:

```python
def approve_and_log(request, context):
    if request.kind == "shell":
        print(f"[Permission: {request.kind}] {getattr(request, 'full_command_text', '')}")
        return PermissionHandler.approve_all(request, context)
    return PermissionDecisionUserNotAvailable()
```

The pattern supports richer policies: approve specific command families, reject anything touching certain paths, or route requests to a human approval queue in another system.

## Extend with MCP servers

Configure Model Context Protocol servers -- local (`stdio`) or remote (`http`) -- to give the agent tools and data beyond the built-ins, from a filesystem server to remote services like the Microsoft Learn documentation API.

.NET:

```csharp
SessionConfig sessionConfig = new()
{
    OnPermissionRequest = PromptPermission,
    McpServers = new Dictionary<string, McpServerConfig>
    {
        ["filesystem"] = new McpStdioServerConfig
        {
            Command = "npx",
            Args = ["-y", "@modelcontextprotocol/server-filesystem", "."],
            Tools = ["*"],
        },
        ["microsoft-learn"] = new McpHttpServerConfig
        {
            Url = "https://learn.microsoft.com/api/mcp",
            Tools = ["*"],
        },
    },
};

AIAgent agent = copilotClient.AsAIAgent(sessionConfig, ownsClient: true);
```

Python:

```python
mcp_servers = {
    "filesystem": {
        "type": "stdio",
        "command": "npx",
        "args": ["-y", "@modelcontextprotocol/server-filesystem", "."],
        "tools": ["*"],
    },
    "microsoft-learn": {
        "type": "http",
        "url": "https://learn.microsoft.com/api/mcp",
        "tools": ["*"],
    },
}

agent = GitHubCopilotAgent(
    instructions="You are a helpful assistant with filesystem and Microsoft Learn access.",
    default_options=GitHubCopilotOptions(
        on_permission_request=PermissionHandler.approve_all,
        mcp_servers=mcp_servers,
    ),
)
```

## Custom tools with approval gates

Register functions as tools alongside Copilot's built-ins. Tools that require approval are gated through Copilot's native pre-tool-use hook and routed to your approval handler. Wrap an `AIFunction` in `ApprovalRequiredAIFunction` in .NET, or declare `approval_mode="always_require"` in Python.

.NET:

```csharp
// Wrap a tool in ApprovalRequiredAIFunction to gate it behind OnPermissionRequest.
AIFunction getWeather = AIFunctionFactory.Create(GetWeather);

AIAgent agent = copilotClient.AsAIAgent(new SessionConfig
{
    OnPermissionRequest = PromptPermission,
    Tools = [new ApprovalRequiredAIFunction(getWeather)],
    SystemMessage = new SystemMessageConfig
    {
        Mode = SystemMessageMode.Append,
        Content = "You are a helpful weather assistant.",
    },
}, ownsClient: true);
```

Python:

```python
from typing import Annotated
from agent_framework import tool


@tool(approval_mode="always_require")
def get_weather_detail(
    location: Annotated[str, "The city and state, e.g. San Francisco, CA"],
) -> str:
    """Get a detailed weather report for a location."""
    ...


agent = GitHubCopilotAgent(
    instructions="You are a helpful weather assistant.",
    tools=[get_weather_detail],
    # The tool's "always_require" decision is routed here to approve or deny.
    default_options=GitHubCopilotOptions(on_permission_request=approve_all_requests),
)
```

## Sessions, resume, and streaming

Copilot sessions are created automatically. Reuse a session to keep context across turns, and resume an earlier conversation by its session ID, even from a new agent instance.

Streaming is first-class in both languages: `RunStreamingAsync(...)` in .NET, `run(..., stream=True)` in Python. Combined with Agent Framework middleware, you can attach telemetry, logging, or custom behavior to the stream before it reaches the caller.

## Production patterns

- **Never auto-approve everything.** `PermissionHandler.approve_all` and `PermissionDecision.ApproveOnce()` on every request are fine for a local demo, but a production agent should classify requests: approve read-only operations, queue mutations, and reject anything outside an allowlist.
- **Route approvals to humans.** The permission handler can forward a decision to an approval queue, a chat channel, or a ticket system instead of blocking on stdin.
- **Persist sessions.** Resuming by session ID lets long-running coding tasks survive restarts of your process.
- **Pin tool sets.** Use MCP server `Tools` filters and per-tool `approval_mode` so the agent cannot silently grow its capabilities.
- **Observability.** Agent Framework middleware gives you a single place to log prompts, tool calls, permission decisions, and streamed tokens.

## When to use it

**Use it when:**

- You are already on .NET or Python and want Copilot's coding harness inside Agent Framework's governance model.
- You need permission gates, MCP integration, streaming, and approval workflows around a coding agent.
- You want a consistent run interface across multiple agent providers, with Copilot as one of them.

**Skip it when:**

- You only need the raw Copilot CLI with no framework layer.
- Your stack is not .NET or Python.
- You want the agent loop itself to be replaceable and do not need Agent Framework's middleware, observability, or approval surface.

**Caveats:** validate package names and access requirements against current docs; the announcement states the integration is stable, but production hardening (permission policy, session persistence, tool pinning) remains your responsibility.

## FAQ

**What is the GitHub Copilot Agent in Microsoft Agent Framework?**

It is an Agent Framework agent backed by the GitHub Copilot CLI and SDK. Copilot owns the agent loop (model calls, tool invocation, planning, session state), while Agent Framework provides instructions, tools, streaming, middleware, observability, and human-in-the-loop approval.

**Is the integration stable for production?**

Microsoft announced the GitHub Copilot Agent as released and stable for both .NET and Python, with runnable examples in the announcement post.

**How are shell and file capabilities gated?**

Every capability is gated by a permission request handled by your permission handler. The handler receives each request and returns an approve or deny decision, so the agent can only do what you explicitly allow.

**Can I add MCP servers and custom tools?**

Yes. Configure local (stdio) or remote (http) MCP servers, and register your own functions as tools. Tools that require approval are gated through Copilot's native pre-tool-use hook and routed to your approval handler.

## All Sources and Links

- [Build Production-Ready Agents with the GitHub Copilot Harness and Agent Framework](https://devblogs.microsoft.com/agent-framework/build-production-ready-agents-with-the-github-copilot-harness-and-agent-framework/) -- official Microsoft dev blog, accessed August 19, 2026
- [Microsoft Agent Framework documentation](https://learn.microsoft.com/agent-framework/) -- official docs
- [Agent Framework GitHub repository](https://github.com/microsoft/agent-framework) -- official source
- [GitHub Copilot CLI documentation](https://docs.github.com/en/copilot/github-copilot-chat/github-copilot-cli) -- official docs

Related AgentPedia guides: [Microsoft Agent Framework Caching and Tool Replay](https://agentpedia.codes/blog/microsoft-agent-framework-1-12-1-caching-tool-replay-guide), [GitHub Copilot SDK Agent Integration](https://agentpedia.codes/blog/github-copilot-sdk-agent-integration-guide), [GitHub Copilot Code Review Agents](https://agentpedia.codes/blog/github-copilot-code-review-agent-skills-mcp-guide).


---

- [All articles](https://agentpedia.codes/blog)