Skip to main content

policy-and-managed-settings

Use whenever adding, modifying, or reviewing any Copilot, agent, LLM, AI, tool, permission, sandbox, MCP, model, telemetry, feature-gate, setting, configuration, or enterprise control—especially anything an organization or administrator may need to manage. Start here to decide whether it belongs in runtime managed settings, a typed SDK contract, VS Code configuration policy, extension policy, or a split implementation. Run on every new Copilot/agent/LLM control and ANY change that adds a `policy:` field.

ソース情報

リポジトリ
microsoft/vscode
ソースの最終更新活動
2026年10月3日 01:48
検出された SKILL.md の言語
英語
スター
193,536
フォーク
44,449

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

ファイルエクスプローラー
9 ファイル

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
policy-and-managed-settings
description
Use whenever adding, modifying, or reviewing any Copilot, agent, LLM, AI, tool, permission, sandbox, MCP, model, telemetry, feature-gate, setting, configuration, or enterprise control—especially anything an organization or administrator may need to manage. Start here to decide whether it belongs in runtime managed settings, a typed SDK contract, VS Code configuration policy, extension policy, or a split implementation. Run on every new Copilot/agent/LLM control and ANY change that adds a `policy:` field.
# Adding an Enterprise Policy Choose the policy destination by **where the governed behavior is implemented**, not by which team requested it. Most controls for Copilot agent behavior belong in the SDK/runtime rather than VS Code. ```mermaid flowchart TD A[Enterprise control] --> P{Existing permission policy<br/>introduced before VS Code 1.133.0?} P -->|Yes| L[Pre-1.133 compatibility migration] P -->|No| B{Where is the governed behavior implemented?} B -->|Copilot runtime, tools, MCP,<br/>sandbox, or agent loop| R[SDK/runtime managed setting] B -->|VS Code editor or workbench| V[VS Code configuration policy] B -->|Extension-provided setting| E[Extension policy] B -->|Independent runtime and editor behavior| M[Split runtime/editor control] ``` Follow the matching guide: - [SDK/runtime managed setting](./sdk-runtime-policy.md) - [VS Code configuration policy](./vscode-policy.md) - [Extension-provided setting](./extension-policy.md) - [Split runtime/editor control](./mixed-policy.md) - [Pre-1.133 permission-policy migration](./legacy-permission-policy.md) - [Agent Host policy support and migration readiness](./policy-support-maintenance.md) Use the support-maintenance guide when changing policy classifications, applied-requirement predicates, or admin migration-readiness diagnostics. It applies when reviewing an existing control as well as when adding a new one. General rules: - Runtime enforcement is authoritative for behavior executed inside the runtime. - Do not duplicate a runtime parser, matcher, or security decision in VS Code. - A VS Code policy is appropriate only for editor/workbench-owned behavior. - New Copilot enterprise controls should target the shared managed-settings/SDK model. - The VS Code settings-to-managed-settings bridge is a compatibility path for legacy settings only. Do not add a new VS Code setting in order to bridge it; define new runtime-owned controls directly in the managed-settings/SDK contract. The bridge itself is unconditional; do not reintroduce a compatibility gate for it. - Run `npm run export-policy-data` for every VS Code or extension policy change. Never edit `build/lib/policies/policyData.jsonc` manually. ## Deprecated and Historical Channels Some policy channels remain supported for existing controls but are closed to new properties: - **GitHub token/account policy data** (`IPolicyData` fields consumed by `AccountPolicyService`) is deprecated for new controls. Do not add new entitlement or policy properties from the GitHub token. Existing fields remain for compatibility. - New Copilot enterprise controls use managed settings and runtime/SDK enforcement. - Pre-1.133 permission-policy translation is a bounded migration, not a reusable channel. When another channel is deprecated, record the boundary here and keep implementation details in the relevant destination guide. Supporting references: - [GitHub Copilot managed settings](./github-managed-settings.md) - [Local policy testing](./local-testing.md) Keep these guides contract-focused. Document contributor decisions and behavioral invariants; point to source rather than copying implementation that will drift. Trust executable source and tests over planning documents.
GitHubで見る