Copilot managed permissions: which Sume domains to allow

Enterprise managed permissions can block, require approval for, or allow network domains. For Sume, decide api.sume.com and mcp.sume.com up front.

4 min readSume
All posts

Under Copilot enterprise managed permissions, an admin sets each network domain to block, require approval, or allow, and users cannot override it. For Sume that means the two hosts your agents use, mcp.sume.com for the hosted MCP and api.sume.com for the REST API, need an explicit decision before rollout.

GitHub announced the controls on September 9. They cover shell commands, file reads and edits, and network domains, and are generally available in the Copilot app, the Copilot CLI and VS Code sessions that use the Agent Host. The announcement does not mention MCP, so treat this as a network-level control and verify with a test session how your MCP connection behaves.

What the policy can and cannot be overridden by

The changelog states that managed restrictions cannot be weakened by user or workspace settings, auto-approval, or previously saved approvals. That matters because a developer who clicked Always allow last week cannot widen what the admin set.

Managed permission surface and the Sume hosts involved (read 2026-10-03)
Operation typeAdmin choicesSume relevance
Network domainsBlock, require approval, allowmcp.sume.com (MCP), api.sume.com (REST, Agent Completions)
Shell commandsBlock, require approval, allowScripts that call the REST API with curl or an SDK
File reads and editsBlock, require approval, allowFiles holding SUME_API_KEY; keep keys out of the repo

A sensible starting policy

Decide by what each host lets an agent do, which follows the credential rather than the host. Session and OAuth details are on the MCP page and in Authentication.

  • mcp.sume.com: allow for teams that use Sume from the agent. An OAuth session defaults to read-only (mcp:read); the person approving at the consent page decides whether to also grant mcp:write.
  • api.sume.com: require approval at first, because a script holding an API key reaches the full tool set, and paid calls follow the key.
  • Everything else the agent fetches (reference images, signed result URLs): leave to your general policy.

Approval is not a spend control

A require-approval rule asks a human once per request. It does not cap what a call costs. The cap lives on the Sume side: max_spend_usd per paid MCP call when you pass it, generation_spend_cap_usd on every Agent Completion, and wallet admission underneath. Keep both layers: the managed permission decides whether the agent can talk to Sume at all, and the caps bound what it can spend once it can.

For the sandbox view of the same hosts, see the Copilot app network allowlist post.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume