GitHub Copilot Code Review: Bill Reviews to the Organization and Restrict Who Can Request Them

GitHub CopilotView original changelog

GitHub added new billing and access controls for Copilot code review. Organization owners can now choose to bill reviews requested by licensed members to the organization instead of each member's own entitlement. Owners and repository admins can also restrict who can request a review to people using a license provided by the organization or enterprise.

Key Takeaways

  • Reviews can now be billed to the organization, through a new "Choose how members with a Copilot license are billed" setting under Copilot policies.
  • The default stays Member billing, where an exhausted personal quota causes the code review to fail.
  • The Organization option charges the organization's cost center, requires AI Credits paid usage, and supports an optional budget.
  • A new authorized users only option blocks personal and external Copilot licenses from requesting reviews.
  • Setting the restriction at the organization level stops repository admins from turning it off.
  • The behavior of the external-license rule for personal repositories, automatic reviews and API requests is detailed in GitHub Docs.

Overview

GitHub added two new controls for Copilot code review that help organizations manage who pays for reviews and who is allowed to trigger them. Both changes target administrators who want predictable costs and tighter governance over how Copilot is used on their repositories.

Choose Who Pays for Code Reviews

By default, a review requested by a member who holds a Copilot license is billed against that member's own Copilot entitlement. That default keeps usage tied to the individual, but it can cause trouble when a member runs out of quota, because the code review then fails.

GitHub now lets organization owners change this behavior with a new setting named Choose how members with a Copilot license are billed. It is found in organization settings under Copilot, then Policies, and it has two options.

Member (default)

Reviews are billed to the member's entitlement. If that member's quota is exhausted, the code review fails.

Organization

Reviews are billed to the organization that owns the repository, and they are charged to the organization's cost center rather than consuming member quotas. This option requires AI Credits paid usage to be enabled for the organization, and owners can optionally set a budget to cap spending.

Control Who Can Request a Review

By default, anyone with a paid Copilot license can request a Copilot code review in repositories they can access. GitHub added a new option that organization owners and repository admins can turn on, called Only allow Copilot code review to be triggered by authorized users.

When it is enabled, review requests must come from a Copilot license provided by the organization or enterprise. Personal licenses and other external licenses can no longer be used to request reviews. If an organization owner enables the option at the organization level, repository admins cannot disable it for their repositories.

GitHub points to its documentation section on reviews requested with an external Copilot license for how the setting applies to personal repositories, automatic reviews and API requests.

Why It Matters

Together, the two settings give administrators a clear way to keep review spending inside organization budgets and to make sure that only organization-sanctioned licenses trigger reviews. Teams that were worried about members exhausting personal quotas, or about reviews being billed through licenses the company does not manage, now have direct controls.

Copilot Code Review: Org Billing and Access Controls | Yet Another Changelog