Can it do the job?
The agent's ability to plan and complete a task.
See what an agent can access, change, and share to get the job done.
Nothing attempted. This test does not change the task outcome.
User intent → agent → tools → permission & scope
Broad authority is an illustrative configuration, not a claim about every agent.
The agent's ability to plan and complete a task.
The actions we authorize it to perform along the way.
The messages, files, people, and time windows it can reach.
The boundaries where a person approves the next action.
Case study: GitHub Copilot cloud agent. It can work on repository code and propose changes. Its documented authority is constrained, not “maximum privilege.” This case study is separate from the illustrative email, calendar, and expense scopes above.
It can read code and push changes to one designated branch: an existing pull-request branch when invoked there, or a new copilot/ branch. Branch protections still apply.
It cannot approve or merge pull requests. Workflows need a human’s approval by default; automatic workflow runs are an optional configuration.
A firewall limits internet access by default, with a dependency allowlist. Administrators can change it. Coverage excludes MCP server processes and setup steps, so this is not complete isolation.
Branch and approval controls ↗ · Firewall defaults and limits ↗
GitHub documents the cloud agent as disabled by default for Business and Enterprise subscribers, requiring administrator enablement; it is enabled by default for Pro, Pro+, and Max. Administrators can opt repositories out. Feature availability does not mean unrestricted authority in every repository.
Access and enablement policies ↗Microsoft reported 20 million GitHub Copilot users in July 2025. That is adoption of the Copilot product family, not a count of cloud-agent users. We selected an agent within that established product and reviewed official documentation; we did not audit a live account, inspect its consent screen, or test enforcement. We do not claim an exact OAuth scope list or that approvals issue single-use credentials.
Microsoft’s adoption disclosure ↗Real products combine controls. The three modes above isolate design choices so you can see their effects; they are not a ranking of vendors. Least privilege narrows authority. Just-in-time access limits when that authority is available. A confirmation prompt alone does not prove either is enforced.