github / github/copilot-cli

Permission Profiles: named, switchable permission presets (global + per-repo)

Open
#3,176 0 comments 2 reactions 0 assignees View on GitHub
area:configuration area:permissions
Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Description

### Describe the feature or problem you'd like to solve

I typically run with `/allow-all` for maximum productivity, but sometimes I want to restrict the agent (e.g., no shell execution, read-only mode, or limited directory access) for sensitive tasks or specific repos. Currently there's no way to:

1. Save a named permission configuration and switch to it quickly
2. Define per-repo permission defaults so certain repos always start restricted
3. Toggle between "full trust" and "restricted" without manually re-configuring each session

Related issues #3028 and #3050 cover parts of this (MCP tool trust and persistent directories), but neither addresses switchable named profiles.

### Proposed solution

Introduce **permission profiles** — named sets of permission rules that can be defined at two levels:

**Global profiles** (`~/.copilot/permission-profiles.json`):
```json
{
"profiles": {
"full-access": { "allowAll": true },
"read-only": {
"allowedTools": ["view", "grep", "glob", "github-mcp-server-*"],
"denyTools": ["powershell", "edit", "create"]
},
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
},
"default": "full-access"
}
```

**Per-repo profiles** (`.github/copilot-permissions.json`):
```json
{
"default": "no-shell",
"trustedDirectories": ["."],
"profiles": {
"no-shell": {
"allowAll": true,
"denyTools": ["powershell"]
}
}
}
```

**Switching profiles in-session:**
- `/profile list` — show available profiles
- `/profile use ` — switch to a profile
- `/profile show` — show current active profile and its rules

Per-repo profiles would take precedence over global ones (team-enforced guardrails).

### Example prompts or workflows

1. Start session in infra repo → automatically applies "no-shell" profile (team policy)
2. Working on a PR review → `/profile use read-only` to ensure no accidental edits
3. Ready to implement → `/profile use full-access` to switch back
4. New session in any repo → applies user's global default without needing `/allow-all` each time

### Additional context

GitHub Copilot CLI 1.0.43

This would complement #3028 (granular MCP tool trust) and #3050 (persistent directory allow lists) by providing the overarching framework for managing permission sets.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.