Copilot 'MCP servers in Copilot' policy: admin checklist for Sume

For Copilot Business and Enterprise, an MCP servers in Copilot policy controls remote servers. What an admin checks before allowing Sume's hosted endpoint.

5 min readSume
All posts

If your developers use Copilot Business or Enterprise, an admin controls the "MCP servers in Copilot" policy that governs remote servers such as Sume. After that, allow the one URL https://mcp.sume.com/mcp, require OAuth with Write off by default, and keep API keys out of shared config.

GitHub's page (read 2026-10-07) says the policy applies to Business and Enterprise plans. This checklist covers Sume's side of the decision.

What the policy is

GitHub's documentation states that the "MCP servers in Copilot" policy applies to Copilot Business and Copilot Enterprise subscribers. Individual plans are not covered by that statement. The policy is the admin control over whether members can use MCP servers in Copilot, so settle it before you roll Sume out.

What Sume exposes

Sume's server is remote, public and HTTPS. The OAuth consent page is hosted on the MCP origin. Read access is required and Write is opt-in. Without Write, only read-only tools are listed. With an API key, the whole tool set is visible, so key-based setups need tighter handling.

Admin questions and Sume answers (read 2026-10-07)
QuestionAnswer
Endpoint to allowhttps://mcp.sume.com/mcp
AuthOAuth by default, or an API key header
Default permissionmcp:read; Write toggle is off at consent
Can it spend?Only with mcp:write or an API key
Spend gatesWallet, idempotency_key, optional dry_run and max_spend_usd

Recommended settings

Tell members to sign in with OAuth and leave Write off unless they are making media. Ask people who need generation to use a separate workspace or a funded wallet with a limited balance. Keep API keys in a secret store and never in a repo-level config file that other people can read.

Sume's safe-automation guidance is that API keys must not appear in logs or chat. If one does, rotate it.

What to document for your team

Write a one-page rule: which URL is approved, which sign-in to use, who may grant Write, and where the wallet balance is reviewed. Add the first three calls to run after connecting, mcp_health, tools_list and balance_get, so a new member can verify the session in a minute.

Also name an owner for key rotation. If a key shows up in a chat, ticket or log, that person revokes it the same day and issues a new one.

Revisit the policy on a schedule

Tools and scopes change. Re-read the tool list each quarter with tools_list, compare it with your approved uses, and confirm that read-only members still see only read tools. A policy that was right at launch can drift when new paid tools appear.

A pilot before you open it

Start with two people for a week. Ask them to call mcp_health, tools_list and catalog_list, and to report the cost of one dry_run. Review the workspace usage afterward. If the numbers match their expectations, widen the policy. If someone granted Write and spent more than planned, add a rule that paid work needs a named budget.

Keep the approved URL list short. One entry, https://mcp.sume.com/mcp, is enough for Sume, and anything that looks similar but sits on another host should be rejected until someone has checked it.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume