Who this is for
You have been asked to roll GitHub Copilot out. Somewhere between that request and the first seat, someone has to produce an acceptable use policy, a security review, a content exclusion decision, an MCP approval process, a rollout plan and a way of measuring whether any of it worked. Usually that someone is a platform engineer or an engineering manager who has a day job.
This is those 23 documents, written. Engineering managers, platform engineers, DevOps and security teams, and GitHub organisation administrators.
The problem it solves
The templates that exist for this are either vendor marketing dressed as a checklist, or a generic "AI policy" that could be about anything. What is missing is the specific stuff: that content exclusion is not retroactive and therefore has to be decided before the pilot rather than after; that an MCP server is a supply-chain dependency running inside an agent loop; that review comments per pull request is the metric that tells you whether the tool is producing code that needs more correcting, and almost no dashboard shows it.
Every document here is opinionated in that direction. Where a template depends on a product fact GitHub may change, it links to the Academy lesson that tracks it rather than restating it, so a template does not quietly go stale between releases.
What is in it
Version 1.0.0 — 23 files. Markdown and CSV, so they open in anything and diff in Git.
Planning
| File | What it is |
|---|---|
business-vs-enterprise-decision-matrix.md | Forces a written requirement before comparing tiers, and a recorded decision after |
licensing-worksheet.csv | Seats, premium-request overage, rollout effort and administration, first year and steady state |
pilot-plan.md | Scope, weekly observations, decision criteria agreed in advance, and named failure conditions |
readiness-assessment.md | A scored questionnaire with four blocking questions, so it can return "not yet" |
Governance
| File | What it is |
|---|---|
acceptable-use-policy.md | The one-page version for the wiki people actually open |
agent-permissions.md | Four permission tiers, with the restricted tier defined as operations an agent never performs |
ai-assisted-development-policy.md | The full policy, built on one rule: you are the author of everything you commit |
content-exclusion-policy.md | What qualifies, who decides, and the three things exclusion does not do |
mcp-server-approval-process.md | A request form and an eight-point review, turned around in days rather than weeks |
Security
| File | What it is |
|---|---|
copilot-security-review-checklist.md | Eight sections mapping to what a reviewer will be asked to sign off |
prompt-injection-checklist.md | Maps untrusted inputs, bounds the blast radius, and includes tests to actually run |
secret-handling-guidelines.md | One rule, a debugging table, and what to do in the first sixty seconds after a mistake |
Configuration
| File | What it is |
|---|---|
copilot-instructions.example.md | A worked instruction file, with the reasoning for each choice |
custom-agent-examples.md | Three scoped agents — migration review, test authoring, dependency triage |
mcp-configuration-examples.md | Read-only, write-capable and one configuration deliberately shown as wrong |
frontend.md | Repository instructions for a component frontend, accessibility included |
terraform.md | Repository instructions for a Terraform codebase |
Rollout
| File | What it is |
|---|---|
30-60-90-rollout-plan.md | Phased plan with exit criteria per phase and the failure mode of each |
developer-onboarding-checklist.md | One page, issued with the seat |
training-agenda.md | Sixty minutes, hands-on, including ten minutes deliberately spent on where it fails |
Measurement
| File | What it is |
|---|---|
adoption-kpis.csv | Twenty-three metrics with baseline and 30/60/90 columns, including the ones dashboards omit |
developer-feedback-survey.md | Eight questions, anonymous, under four minutes |
productivity-measurement-framework.md | Why the percentage you will be asked for is not obtainable, and what to report instead |
Price
Checking availability…
Sign in with an email link first, so the purchase attaches to an account you can actually get back into. No password to choose.
Payment is handled by Stripe. This site never sees your card details.
You already have this.
Go to your downloadsNot on sale yet.
Payment is not switched on, so there is nothing to click. Rather than show a button that fails, this says so. The account page has a mailing-list box that covers product updates — tick it and you will hear when this opens.
The service that handles purchases is not responding right now. Everything free on this site is unaffected.
$149 for one person adapting the templates for their organisation. $299 for an organisation licence, which lets anyone there use and adapt them, including inside internal documentation. One payment; there is no subscription and no renewal.
Licence, in a sentence
Adapt them and use them inside the organisation that bought the licence, including in internal policy systems and wikis. Do not redistribute them, resell them, or hand them to a third party as a consulting deliverable. Adapted documents are yours and need no attribution. The full terms are in the download.
Questions
Is this legal advice?
No. These are templates that give your legal and security review a starting document instead of a blank page. They are not a substitute for the people accountable for those things where you work, and they say so.
How is this different from the free Academy?
Every Academy lesson, lab, assessment, tool, dataset and research page on this site is free and stays free. Pro and the Toolkit add implementation material; they never remove anything. The Academy explains how Copilot behaves — that is the knowledge, and it is free. This is the paperwork an organisation has to produce before it can act on that knowledge, which is a different job and a much less enjoyable one.
What happens when GitHub changes something?
Templates are revised and the changelog says what moved and why, so you can diff your adapted copy against ours. Updates to the version you bought are included. See what has changed recently.
Can I see one first?
The reasoning behind them is public: the security and enterprise cluster and the risks and mitigations lesson are the free material these templates are built on. If those are not useful to you, this will not be either.
Refunds?
Write within 14 days and you get one, without a conversation about why.