Before you start
- Select the workspace and environment you intend to configure.
- Use an operator role that permits the requested change. Connection management and policy publication require an admin or owner; Control checks your role again when you apply a change.
- Bring your own accounts and credentials for the providers your application will call. Available connectors and tools depend on your workspace.
Enter credentials only in the connection forms. Never paste a vendor key,
OAuth token, or Obol virtual key into the conversation.
Configure a coding agent
1
Open Configure
Open Copilot and select Configure. Start or continue setup from the
displayed controls. If guided setup is disabled, a workspace owner can
enable it. You can use the forms even when assistant inference is unavailable.
2
Describe the intended work
Give the agent a name and choose a coding workflow. When chat is available,
you can ask: “Help me configure a coding agent with GitHub and sandbox
connections.” Describe the repositories and tasks it should access, and
whether it needs read, write, or destructive operations.
3
Connect GitHub and your sandbox
Select your GitHub connection and the exact tools the agent needs. Connect
your sandbox provider through an available connector, or
add your own MCP server or REST API.
Authenticate in the connection form and review the admitted tools.
A connected provider does not automatically grant the agent access.
4
Set model access and boundaries
If the agent uses models, connect a
model provider and select its allowed models.
Review tool access, policy, routing, budgets, and rate limits. Production
destructive actions require approval unless policy explicitly grants them.
5
Review and apply
Inspect the proposed configuration before applying it. A proposal is bound
to the saved setup revision; if the workspace changes, refresh and prepare
a new proposal. Copilot’s explanation is not authorization to apply.
6
Install and verify
Copy a newly minted virtual key when it is shown, then install the gateway
addresses and key in your client. Run the intended model or tool call from
that client and check the observed verification result. A saved draft or a
successful assistant reply does not establish that your client is ready.
Configure and Operate
You choose the mode. Both apply paths require your explicit action and Control’s
permission checks. Setup key creation keeps the one-time secret separate from
stored operational change sets.
For tool results, read the receipt’s evidence class. A native route can carry
gateway_observed evidence; a federated route carries untrusted or
broker_attested evidence. See evidence trust.
Recover setup progress
If you see Setup needs attention, read the accompanying message before retrying. An interrupted response does not establish whether a change committed.- The dashboard was updated: reload the dashboard, reopen Configure or the agent builder, and inspect the saved setup before submitting another change.
- Control is unavailable: use Refresh progress when available to read the saved state. If the page itself is stale, reload it first.
- The proposal is stale: refresh the configuration and prepare a new proposal against the current revision.
- Assistant inference is unavailable: check the displayed readiness message. Continue with configuration forms where your workspace permissions allow it.
- A key was minted but its secret is missing: use the copy you saved, or revoke that key and mint a replacement.