Section 40 of 45 7 min read

GitHub Copilot

GitHub Copilot: configuration surface, the multi-surface problem, the consumption model, and controls worth setting.

Objective

Cover Copilot’s configuration model across its surfaces.

40.1 Configuration Surface #

MechanismLocationLoads
Repository instructions.github/copilot-instructions.mdEvery turn
Agent instructionsAGENTS.mdEvery turn
Path-scoped instructions.github/instructions/*.instructions.md with applyToOn matching files
Personal instructionsGitHub.com and JetBrains account settings; ~/.copilot/ files in the CLIEvery turn, where the surface supports them
Organization instructionsEnterprise settings; GitHub.com surfaces onlyEvery turn there; not loaded in IDEs or the CLI
Skills.github/skills/ and installed skillsMetadata always; body on demand
Custom agentsAgent definition filesOn delegation
MCPRepository settings, CLI config, IDE configSchemas every turn, unless tool search defers them (CLI and VS Code)

Support in that table is per surface rather than uniform, and the vendor’s support matrix is the thing to read before promising anyone a rule will apply: personal instructions are absent from VS Code, Eclipse and Xcode, and organization instructions are listed for GitHub.com’s chat, coding-agent and code-review surfaces alone.72

The MCP row carries the same per-surface caveat, and it has moved. Copilot CLI defers full external tool definitions behind tool search: deferTools defaults to "auto", a server set to "never" stays eagerly loaded, and a custom agent opts in with deferred-tool-loading.72 Deferral activates only on supported models and only past an activation threshold—the documentation puts it at roughly thirty tools, below which the saving is not worth the round trip—so eager schemas on every turn remain the outcome where search is disabled with toolSearch: false, unsupported, under the threshold, or overridden per server. Assume the eager case when budgeting, and verify which one you are in rather than assuming either.

Path-scoped instruction files live in .github/instructions/, end in .instructions.md, and carry an applyTo glob in frontmatter.72 Path scoping is the most underused mechanism here:

---
applyTo: "src/**/*.tsx"
---
- Server components by default. Add `"use client"` only when a hook requires it.
- Never import from `@/lib/server/*` in a client component.
- Co-locate tests as `*.test.tsx` beside the component.

On a codebase where seven turns in ten never touch a .tsx file, that rule is off the request for those turns rather than diluting all of them. Both halves of that sentence are assumptions rather than measurements: the seventy percent is a workload guess about your repository, and the zero cost holds only if a matched rule does not then persist across later non-matching turns. The documentation establishes how Copilot decides to include a path-scoped file, not that it drops one again afterward (§15.6 has the Claude Code case, where a loaded rule does stay in history). Treat the saving as real and front-loaded, and measure it on your surface before putting a number in a budget.

Two caveats that the enthusiasm usually omits. Support is surface-dependent—path-specific instructions are not honored uniformly across every Copilot surface, and on GitHub.com they have been limited to the cloud agent and code review rather than applying everywhere.72 Verify on the surface you actually use before assuming a rule is in force; an instruction file that silently does not apply is worse than no file because you will believe the rule is covered.

And the excludeAgent frontmatter keyword removes a file from code review or the coding agent specifically.72 Without it, both unattended surfaces consume the file, which is the subject of the next subsection.

40.2 The Multi-Surface Problem #

Copilot’s distinguishing characteristic is that a single configuration reaches surfaces carrying materially different oversight:

SurfaceHuman in the loopNotes
IDE chat / completionsYesStandard interactive
CLIYesInteractive
Code reviewNoRuns on PRs automatically
Cloud agentNoRuns unattended

A skill committed to the repository is available to the last two, unprompted. That is a change to the execution environment of unattended automation, and it should go through review that reflects it.

MCP gets there by a different route, and conflating the two will mislead a threat model in the safer direction only by accident. Committing a .vscode/mcp.json does not grant the cloud agent or code review anything: that file configures your editor. Shared access is configured by a repository administrator under Settings → Copilot → MCP servers, with the JSON entered into GitHub rather than committed, and an existing editor configuration is a template to adapt rather than the mechanism.72 Code review carries its own tool-eligibility and enablement conditions on top. What is true, and is the reason the row matters, is that once configured there, repository-level MCP configuration serves both the cloud agent and code review from one JSON blob—so review the settings change, not only the tree.

40.3 Consumption Model #

Copilot’s billing model changed materially on June 1, 2026, and any guidance written before that date describes a system most users are no longer on. One carve-out survives: subscribers inside an existing annual Pro or Pro+ term stay on premium-request pricing until that term expires, so model multipliers remain a live concept for them and a legacy one for everyone else.73

The former model counted premium request units. Each model interaction cost one PRU, and a per-model multiplier scaled that cost, so a single prompt and a fifty-turn agentic session could draw the same unit. GitHub retired PRUs and replaced them with GitHub AI Credits, where one credit equals one cent and consumption is calculated from actual token usage—input, output, and cached tokens—at the published API rate for each model, before any plan-level modifier. The documented modifier is a 10 percent discount on model costs for paid plans while auto model selection is in use, so credits consumed track the direct API bill closely rather than exactly.73

Four consequences matter more than the price tags.

Everything in Part IV now applies directly

Under PRUs, token optimization was invisible at the invoice, since the meter counted interactions. Under credits, the meter counts tokens, including cached ones, at published API rates. Cache hit rate, prefix stability, context pressure, and model routing therefore move the Copilot bill exactly as they move an API bill. The arithmetic in §21 through §27 is no longer an analogy for Copilot users but the billing formula itself.

Completions remain free

Code completions and Next Edit Suggestions stay included on paid plans and draw no credits.73 The credit pool is consumed by the agentic surfaces: chat, agent mode, CLI, code review, and cloud agents.

The fallback is gone

Exhausting PRUs previously dropped a user to a cheaper model so that work could continue. Under credits, availability is governed instead by the remaining balance and by administrator budget controls.73 A team planning for the old soft landing will encounter a hard stop.

Agentic work is now priced as agentic work

A fifty-turn session that reads twenty files no longer costs one unit. It costs what its tokens cost, which is the point of the change, and it is why §4.2’s observation about the marginal turn now carries a line on the invoice.

The practical consequence is that the levers in this document apply to Copilot without translation. Instruction file discipline (§15), path scoping (§15.6), MCP surface reduction (§17.1), cache hygiene (§22), and context recycling (§24) each reduce credits consumed, and they do so in direct proportion to the tokens they remove.

40.4 Organization-Level Controls #

  • Organization-level instructions—reach every repository on GitHub.com’s own surfaces, which makes them the highest-leverage single lever there and no lever at all inside a developer’s IDE or CLI.72
  • MCP allowlist—which servers may be connected at all.
  • Policy controls for the unattended surfaces specifically.
  • Model availability by team. §27.5 is the companion here: automatic selection is GitHub’s recommended path, so for any team following that recommendation this control governs the set the platform selects from rather than the model an individual picks. An allowlist that removes the frontier tier constrains the router rather than the developer.

GitHub’s own code-review guidance corroborates the length discipline argued in §15: when Copilot does not follow instructions as expected, the named causes include a file over a thousand lines, vague or ambiguous instructions, conflicting instructions, and rules sitting in the repository-wide file that belong in a path-specific one.74 That is the §15.7 audit, written by the vendor.

40.5 What Is Distinctive #

The path-scoping frontmatter is a clean implementation of scoped instructions, and excludeAgent is a control no competitor currently offers. The multi-surface reach is the distinctive property, and it cuts both ways: the same file that helps a developer in an IDE also steers an agent nobody is watching.

The corresponding weakness is inconsistency. Instruction discovery, path-scoping support, and the consumption model differ across the IDE, the CLI, code review, and the cloud agent, and the documentation is split across surface-specific pages rather than one specification.72 A team standardizing on Copilot should confirm behavior on each surface it uses rather than generalizing from the one it knows. Where a rule must hold everywhere, put it in the repository-wide file and verify, rather than relying on a path-scoped file being honored.

References cited in this section

3 of 81 · numbering matches the PDF

  1. 72GitHub, "Adding repository custom instructions for GitHub Copilot," GitHub Docs together with the surface-specific pages for the IDE and for Copilot CLI, verified September 8, 2026. Vendor documentation; cited as product fact for the three instruction types, the .github/instructions/NAME.instructions.md location, the applyTo glob frontmatter, the excludeAgent keyword, and instruction-file discovery order. Cited also for the limitation: path-specific instruction support is surface-dependent rather than universal, and the documentation is split across surface-specific pages rather than published as one specification, so behavior must be confirmed per surface.docs.github.com/copilot/customizing-copilot/adding-custom-instructions-for-github-copilot ↗
  2. 73GitHub, "GitHub Copilot is moving to usage-based billing," The GitHub Blog, April 27, 2026 and "What changed with Copilot billing (legacy)," GitHub Docs, https://docs.github.com/en/copilot/reference/copilot-billing/request-based-billing-legacy/what-changed-with-billing, both verified September 11, 2026. First-party announcement plus vendor documentation. Source of the June 1, 2026 transition from premium request units to GitHub AI Credits, the one-credit-equals-one-cent conversion, the calculation of consumption from input, output, and cached tokens at published per-model API rates, the unchanged seat pricing ($19 Business including $19 of credits, $39 Enterprise including $39), the pooling of credits at the organization level, the exclusion of code completions and Next Edit Suggestions from credit consumption, the replacement of the lower-cost-model fallback with balance and administrator budget controls, and the survival of model multipliers only as a legacy concept for annual Pro and Pro+ subscribers within an existing term. This is the most perishable product fact in the document: it replaced its predecessor roughly three months before publication, and that predecessor had itself been in place barely a year.github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing ↗
  3. 74GitHub, "Using custom instructions to unlock the power of Copilot code review," GitHub Docs verified September 8, 2026. Vendor documentation. Cited for the troubleshooting guidance naming instruction files over a thousand lines, vague or ambiguous instructions, conflicting instructions, and repository-wide rules that belong in path-specific files as causes of instructions not being followed—a vendor-side corroboration of the length and allocation discipline argued in §15.docs.github.com/en/copilot/tutorials/use-custom-instructions ↗
PDF↓