By usage

GitHub Copilot and Microsoft 365 Copilot, one governance layer.

GitHub Copilot writes and executes code across your repos. Microsoft 365 Copilot reads and summarizes nearly every document, email, and chat an employee can see. Neither creates new access - both make existing over-permissioning trivially easy to exploit at scale.

Why it matters

Two assistants, two very different blast radii

Two assistants, two very different blast radii

GitHub Copilot can write and execute code across your repos; Microsoft 365 Copilot can read and summarize nearly every document, email, and chat an employee has access to.

Both inherit the user's existing permissions

Copilot doesn't create new access, but it makes existing over-permissioning trivially easy to exploit at scale.

Enterprise rollout outpaces policy

Licenses get issued org-wide long before anyone defines what Copilot should and shouldn't be able to do.

What Lineation does

One policy model for code and content

Coverage

One policy layer for both Copilots

GitHub Copilot and Microsoft 365 Copilot are governed under the same inventory and policy model.

Scoping

Tool-call and data-access policy

Code write/deploy actions and document/email access are scoped independently, by user, team, or repo.

DLP

Content inspection

Prompts, generated code, and Copilot-summarized content are checked for secrets, PII, and policy violations.

Audit

Full audit trail

Every Copilot interaction is logged and replayable, tied to the user and session.

How it works

Five steps to governed Copilot usage

Connect Microsoft & GitHub admin APIs

Link the Microsoft 365 admin center and GitHub org settings - no endpoint agents required.

Discover Copilot usage

Every licensed user and their Copilot activity surfaces in the inventory automatically.

Scope policy by product

Code actions - write, deploy, shell - and content actions - read, summarize, share - get independent policy.

Inspect content

Generated code and document summaries are scanned for secrets, PII, and policy violations.

Log and report

Every interaction is logged for audit, with violations routed to your SIEM/SOAR.

FAQ

Common questions

Does this cover GitHub Copilot, Microsoft 365 Copilot, or both?

Both, under one governed inventory and policy model - you don't need separate tooling for each.

Does Copilot get new permissions, or just use what the user already has?

Copilot inherits the signed-in user's existing permissions; governance here is about scoping what it's allowed to do with that access.

Can we allow code suggestions but block autonomous commits or deploys?

Yes - policy is scoped by action type, so suggestion and read actions can stay open while write, commit, and deploy require explicit allow.

Does this slow down developers or knowledge workers using Copilot?

No. Policy evaluates against a cached rule set at the gateway/endpoint layer, adding negligible latency to the happy path.

What access is needed to set this up?

Admin access to the Microsoft 365 admin center for Microsoft 365 Copilot, and org-level GitHub access for GitHub Copilot.

Can alerts route to our existing SIEM?

Yes - policy violations and flagged content route to your SIEM and SOAR the moment they're detected.

Govern both Copilots without slowing anyone down.

Connect your Microsoft and GitHub admin APIs and see Copilot activity today.