Learning path

Engineering manager learning path

Covers plan economics, governance and adoption, and is candid about measurement: attribution is genuinely hard, and this path says so rather than offering a productivity figure it cannot support.

For
Technical leaders deciding what to buy, what to permit, and how to tell whether it helped.
Lessons
14 existing Academy lessons
Reading time
about 3½ hours
Prerequisites
None.

of 14 complete (%)

  1. Stage 1What you are buying

    The capability lines between plans are not intuitive — Pro+ has audit logs but no policy management, and Business is cheaper than Max.

  2. Stage 2What your engineers will actually do with it

    Governing a tool you have not seen used produces policy that does not survive contact with the work.

    • GitHub Copilot Agent Mode Explained— completed

      The in-IDE autonomous loop: planning, multi-file edits, tool calls, terminal approval, iteration — and the tasks it handles badly.

    • GitHub Copilot Cloud Agent vs Agent Mode— completed

      Resolves the terminology confusion between agent mode, the cloud agent (formerly the coding agent) and third-party agents, with a decision table.

    • GitHub Copilot Agents: Complete Guide— completed

      Five agent surfaces with genuinely different capabilities, the autonomy scale that makes them comparable, and why an agent that can act needs a different trust model.

  3. Stage 3Governance

    The organisation controls, their documented limits, and the policy that gates MCP.

    • GitHub Copilot Governance and Policy Guide— completed

      Governance as a set of deliberate decisions rather than a locked door — eleven domains, a precedence model that surprises people, and a quarterly review that takes an hour.

    • Managing GitHub Copilot Across an Organization— completed

      The organization owner's job: assigning seats people use, the policy surface you own, what the enterprise decided for you, and telling developers what changed.

    • GitHub Copilot Security Best Practices— completed

      A working developer's security practice for AI-assisted code: what to check, which categories deserve a second pair of eyes, and where generated code fails quietly.

    • GitHub Copilot MCP Security: Governing External Tools— completed

      The MCP threat model at enterprise scale: allowlists in managed settings, why the private registry is not the stronger control, and the surface it does not reach.

  4. Stage 4Review and standards at team scale

    A committed instructions file is the one mechanism that makes conventions travel without depending on each person's settings.

  5. Stage 5Adoption and measurement

    Access is the easy half. This is the half that determines whether the licences were worth buying.

Put it into practice

Projects

Reading time is computed from the prose of the lessons listed above at 200 words per minute, excluding code blocks. It is an estimate of reading, not of the practice that makes any of it stick.