GitHub is adding a consequential step to Copilot Code Review: the assistant can now approve a pull request, and that approval may count toward branch protection requirements. The capability is in public preview for Copilot Pro, Pro+, Max, Business and Enterprise plans.

The short answer

BehaviorEffect
Automatic assessmentEvery review says whether Copilot considers the PR ready for approval.
Approval enabledCopilot submits an approval recognized by the merge rule.
New commitThe earlier approval is dismissed, as a human review would be.

The assessment alone does not satisfy an approval requirement. An administrator must explicitly enable signed approvals, which are off by default.

Controls at three levels

An enterprise can disable the feature everywhere or delegate the choice to organizations. An organization can enable it broadly, limit it to selected repositories or let repository administrators decide. At repository level, teams can specify the file paths Copilot is allowed to approve.

That final boundary is especially valuable. A team might allow the assistant to approve documentation, tests or low-risk dependency changes while excluding authentication, billing, infrastructure and data migrations.

Approval is not accountability

Copilot can spot inconsistencies and summarize a change, but it may not know the business intent, incident history or an undocumented constraint. A syntactically sound PR can still change an access right, break an operational procedure or damage a metric that is not represented in the repository.

Automated approval should therefore complement a review strategy rather than become its only gate. Code owners, required tests and security controls remain necessary for sensitive areas.

How to test it safely

Start with a non-critical repository and narrow path permissions. Over several weeks, measure useful approvals, incorrect comments and defects found after merging. Keep at least one human approval for production-impacting changes.

Also verify who can alter the configuration. A useful control loses its value if a pull request author can widen the approved paths or bypass protections.

The signal matters even without the signature

Even when counted approvals remain disabled, the assessment in Copilot's overview comment gives maintainers a quick triage signal. It can help prioritize a review queue, provided teams do not confuse statistical confidence with proof.

GitHub is moving the agent closer to the maintainer role while retaining administrative controls. A sound rollout starts with reversible changes, compares Copilot decisions with human reviews and expands only when the results support it.