Copilot managed permissions: which Sume domains to allow
Enterprise managed permissions can block, require approval for, or allow network domains. For Sume, decide api.sume.com and mcp.sume.com up front.

Under Copilot enterprise managed permissions, an admin sets each network domain to block, require approval, or allow, and users cannot override it. For Sume that means the two hosts your agents use, mcp.sume.com for the hosted MCP and api.sume.com for the REST API, need an explicit decision before rollout.
GitHub announced the controls on September 9. They cover shell commands, file reads and edits, and network domains, and are generally available in the Copilot app, the Copilot CLI and VS Code sessions that use the Agent Host. The announcement does not mention MCP, so treat this as a network-level control and verify with a test session how your MCP connection behaves.
What the policy can and cannot be overridden by
The changelog states that managed restrictions cannot be weakened by user or workspace settings, auto-approval, or previously saved approvals. That matters because a developer who clicked Always allow last week cannot widen what the admin set.
| Operation type | Admin choices | Sume relevance |
|---|---|---|
| Network domains | Block, require approval, allow | mcp.sume.com (MCP), api.sume.com (REST, Agent Completions) |
| Shell commands | Block, require approval, allow | Scripts that call the REST API with curl or an SDK |
| File reads and edits | Block, require approval, allow | Files holding SUME_API_KEY; keep keys out of the repo |
A sensible starting policy
Decide by what each host lets an agent do, which follows the credential rather than the host. Session and OAuth details are on the MCP page and in Authentication.
mcp.sume.com: allow for teams that use Sume from the agent. An OAuth session defaults to read-only (mcp:read); the person approving at the consent page decides whether to also grantmcp:write.api.sume.com: require approval at first, because a script holding an API key reaches the full tool set, and paid calls follow the key.- Everything else the agent fetches (reference images, signed result URLs): leave to your general policy.
Approval is not a spend control
A require-approval rule asks a human once per request. It does not cap what a call costs. The cap lives on the Sume side: max_spend_usd per paid MCP call when you pass it, generation_spend_cap_usd on every Agent Completion, and wallet admission underneath. Keep both layers: the managed permission decides whether the agent can talk to Sume at all, and the caps bound what it can spend once it can.
For the sandbox view of the same hosts, see the Copilot app network allowlist post.
Sources
Related posts
More in Integrations
- Dev Container devcontainer.json MCP: add Sume's hosted server
Declare Sume's hosted MCP server in devcontainer.json under customizations.vscode.mcp. Where the entry lands, what to keep out, and how to verify it.
- Devin Local server-level MCP permission: what it means for Sume
Devin Desktop 3.5.17 added two server-level options to the MCP tool permission prompt. Before approving a whole server for Sume, know which tools it exposes.
- Devin Desktop "Needs auth" and the Authenticate button for Sume
Devin Desktop shows an Authenticate button on MCP servers marked Needs auth, and it clears stored OAuth credentials. What to expect when you do it for Sume.
- Discord interaction token lasts 15 minutes: deliver a long Sume run
A Discord follow-up works for 15 minutes; a long-form Format run takes 15 to 30. Edit the original reply when young, post as the bot to the channel when not.
Written by Sume