Product

GitHub Copilot Enterprise Deployment Toolkit

Everything you have to write down before you turn Copilot on for a few hundred engineers — already written, and editable.

Who this is for

You have been asked to roll GitHub Copilot out. Somewhere between that request and the first seat, someone has to produce an acceptable use policy, a security review, a content exclusion decision, an MCP approval process, a rollout plan and a way of measuring whether any of it worked. Usually that someone is a platform engineer or an engineering manager who has a day job.

This is those 23 documents, written. Engineering managers, platform engineers, DevOps and security teams, and GitHub organisation administrators.

The problem it solves

The templates that exist for this are either vendor marketing dressed as a checklist, or a generic "AI policy" that could be about anything. What is missing is the specific stuff: that content exclusion is not retroactive and therefore has to be decided before the pilot rather than after; that an MCP server is a supply-chain dependency running inside an agent loop; that review comments per pull request is the metric that tells you whether the tool is producing code that needs more correcting, and almost no dashboard shows it.

Every document here is opinionated in that direction. Where a template depends on a product fact GitHub may change, it links to the Academy lesson that tracks it rather than restating it, so a template does not quietly go stale between releases.

What is in it

Version 1.0.0 — 23 files. Markdown and CSV, so they open in anything and diff in Git.

Planning

FileWhat it is
business-vs-enterprise-decision-matrix.mdForces a written requirement before comparing tiers, and a recorded decision after
licensing-worksheet.csvSeats, premium-request overage, rollout effort and administration, first year and steady state
pilot-plan.mdScope, weekly observations, decision criteria agreed in advance, and named failure conditions
readiness-assessment.mdA scored questionnaire with four blocking questions, so it can return "not yet"

Governance

FileWhat it is
acceptable-use-policy.mdThe one-page version for the wiki people actually open
agent-permissions.mdFour permission tiers, with the restricted tier defined as operations an agent never performs
ai-assisted-development-policy.mdThe full policy, built on one rule: you are the author of everything you commit
content-exclusion-policy.mdWhat qualifies, who decides, and the three things exclusion does not do
mcp-server-approval-process.mdA request form and an eight-point review, turned around in days rather than weeks

Security

FileWhat it is
copilot-security-review-checklist.mdEight sections mapping to what a reviewer will be asked to sign off
prompt-injection-checklist.mdMaps untrusted inputs, bounds the blast radius, and includes tests to actually run
secret-handling-guidelines.mdOne rule, a debugging table, and what to do in the first sixty seconds after a mistake

Configuration

FileWhat it is
copilot-instructions.example.mdA worked instruction file, with the reasoning for each choice
custom-agent-examples.mdThree scoped agents — migration review, test authoring, dependency triage
mcp-configuration-examples.mdRead-only, write-capable and one configuration deliberately shown as wrong
frontend.mdRepository instructions for a component frontend, accessibility included
terraform.mdRepository instructions for a Terraform codebase

Rollout

FileWhat it is
30-60-90-rollout-plan.mdPhased plan with exit criteria per phase and the failure mode of each
developer-onboarding-checklist.mdOne page, issued with the seat
training-agenda.mdSixty minutes, hands-on, including ten minutes deliberately spent on where it fails

Measurement

FileWhat it is
adoption-kpis.csvTwenty-three metrics with baseline and 30/60/90 columns, including the ones dashboards omit
developer-feedback-survey.mdEight questions, anonymous, under four minutes
productivity-measurement-framework.mdWhy the percentage you will be asked for is not obtainable, and what to report instead

Price

Choose a GitHub Copilot Enterprise Deployment Toolkit option

Checking availability…

Sign in to continue

Sign in with an email link first, so the purchase attaches to an account you can actually get back into. No password to choose.

Payment is handled by Stripe. This site never sees your card details.

You already have this.

Go to your downloads

Not on sale yet.

Payment is not switched on, so there is nothing to click. Rather than show a button that fails, this says so. The account page has a mailing-list box that covers product updates — tick it and you will hear when this opens.

The service that handles purchases is not responding right now. Everything free on this site is unaffected.

$149 for one person adapting the templates for their organisation. $299 for an organisation licence, which lets anyone there use and adapt them, including inside internal documentation. One payment; there is no subscription and no renewal.

Licence, in a sentence

Adapt them and use them inside the organisation that bought the licence, including in internal policy systems and wikis. Do not redistribute them, resell them, or hand them to a third party as a consulting deliverable. Adapted documents are yours and need no attribution. The full terms are in the download.

Questions

Is this legal advice?

No. These are templates that give your legal and security review a starting document instead of a blank page. They are not a substitute for the people accountable for those things where you work, and they say so.

How is this different from the free Academy?

Every Academy lesson, lab, assessment, tool, dataset and research page on this site is free and stays free. Pro and the Toolkit add implementation material; they never remove anything. The Academy explains how Copilot behaves — that is the knowledge, and it is free. This is the paperwork an organisation has to produce before it can act on that knowledge, which is a different job and a much less enjoyable one.

What happens when GitHub changes something?

Templates are revised and the changelog says what moved and why, so you can diff your adapted copy against ours. Updates to the version you bought are included. See what has changed recently.

Can I see one first?

The reasoning behind them is public: the security and enterprise cluster and the risks and mitigations lesson are the free material these templates are built on. If those are not useful to you, this will not be either.

Refunds?

Write within 14 days and you get one, without a conversation about why.