Copilot gains desktop control and reusable agent workflows
GitHub adds computer use and coded workflows with permissions and checkpoints

GitHub brought desktop app control to Copilot CLI and the Copilot app on macOS and Windows on October 1. The computer use feature is in public preview.
The same dayโs dynamic workflows release lets developers encode repeatable processes with agent steps. This public preview covers the CLI, app and SDK.
Desktop access needs explicit boundaries
Copilot can read app content, click controls and edit text, including in software without an API. The feature starts disabled.
GitHubโs documentation says approval prompts depend on the surfaceโs permission settings. Saved app permissions apply across the CLI and app on one computer. Removing a saved approval affects future sessions, leaving active access intact. Enterprise policies can disable computer use. On macOS, Accessibility and Screen Recording permissions are required.
The CLI enables it with /computer on. GitHub warns that changing interfaces can cause mistakes or repeated actions. It recommends direct tools when those can complete the task more predictably. Visible app content can include sensitive information, so GitHub advises reviewing what context the application exposes.
A process written in code
Dynamic workflows combine programmed steps with agent judgment, run work sequentially or concurrently, and pass structured results between stages. Checkpoints can pause work for review. Requests for human input depend on client support.
Workflows are available across Copilot plans. The app needs no setup, while CLI users must enable experimental features with /experimental on.
GitHubโs workflow documentation adds important limits. Reusing the rules does not guarantee identical agent answers. AI credit limits are approximate because work already underway can exceed them. CLI subagents inherit session grants, while extension code can execute outside their approval prompts.
The terminal workflow run command does not display approval prompts. Required agent permissions must be granted before starting. Authors can also limit concurrent agents, total agents and active runtime.
What teams should test first
Our reading is that the releases address connected problems in workplace automation. One concerns reaching the application where a task happens. The other concerns defining how a repeatable task should proceed. Treating those as separate design decisions gives a team clearer questions to ask during a trial.
Start with one routine task and a known expected result. Record what information it touches, what changes it may make and where a person should inspect the output. Then test an interrupted run and a deliberately incomplete input. Those checks can reveal whether the process fails visibly enough for someone to recover it.
Illustrative January 2015 photograph by AlexKingCreative under Creative Commons CC0. Resized and converted to WebP. The photograph shows a Magic Mouse on a MacBook Pro, without a Copilot session.



