At a glance
- GitHub Copilot for JetBrains can now push org-owned sandbox policies that lock over developer toggles.
- Claude Code v2.1.265 adds live plugin folders and a 1 GB tool-result cap. Pin v2.1.266 for the gateway fix.
- Copilot code review can submit a real approval toward required reviews, only if an admin turns it on.
- Speakeasy Kit is a compose-first coding runtime with one model-visible tool, and no built-in sandbox.
September 9 is a midweek governance-and-harness day. The useful signal is who controls agent sandboxes, how plugins and tool results scale, whether a bot can satisfy a review gate, and whether a leaner compose runtime cuts round trips.
Treat today as a control-plane day. Roll managed sandbox policy for JetBrains Copilot if you already lock MCP, pin Claude Code to v2.1.266 before you widen plugin folders, decide whether Copilot approvals belong in any required-review ruleset, and try Kit's one-tool compose loop on a size-matched coding task.
Top Stories
GitHub Copilot for JetBrains adds enterprise-managed sandbox policies
Practical dev impact: Stop treating JetBrains Copilot sandbox toggles as a per-developer preference. Admins can now push enablement, filesystem and network access, proxy, developer-tool, and macOS Keychain controls that lock over user settings. GitHub's September 8 changelog puts the policies in public preview. Sandbox UI under GitHub Copilot > Sandbox appears when the org enables the Editor Preview flag or sets a managed enable or disable. The same drop adds cross-file cursor jumps for next edit suggestions, global project files and folders in chat context, enterprise policy diagnostics to verify enforcement on a device, and /ide in Copilot CLI (public preview) so a terminal session can pull JetBrains selections, diagnostics, and file references. Connected shell commands can reuse IDE terminal env vars and the project's Python interpreter or venv. OpenTelemetry chat settings move to GA.
Claude Code v2.1.265 and v2.1.266: live plugin folders, 1 GB tool-result cap, gateway fix
Practical dev impact: Point --plugin-dir at a folder of plugin children that hot-reload as you add or remove manifests, watch the new 1 GB on-disk tool-result cap for truncated previews, and skip v2.1.265 if you set CLAUDE_CODE_USE_GATEWAY beside API-key auth. npm shows v2.1.265 published September 8 (about 19:05 UTC) and v2.1.266 the same day (about 23:32 UTC). v2.1.265 also restores prompt-cache reuse for resumed subagents and teammates, keeps interrupted tool calls marked interrupted after a crash, and fixes MCP http servers that only speak legacy HTTP+SSE by falling back to SSE. v2.1.266 undoes a v2.1.265 regression where undocumented CLAUDE_CODE_USE_GATEWAY alone forced Cloud-gateway sign-in and broke API key, apiKeyHelper, and custom-header setups with "Not signed in to the Cloud gateway". Prefer @anthropic-ai/claude-code@2.1.266 over latest or stable drift (stable still trailed at v2.1.236 when checked).
Copilot code review can approve pull requests when admins allow it
Practical dev impact: Every Copilot review now includes an approval assessment in the overview comment, and enterprises can optionally let Copilot submit a real approval that counts toward required approvals. GitHub shipped the public preview on September 1 for Copilot Pro, Pro+, Max, Business, and Enterprise. Approvals stay off by default. Enable at enterprise, organization, or repository scope, including path filters for what Copilot may approve. An assessment alone does not satisfy merge rules. Fresh commits dismiss Copilot's approval like a human reviewer's, so you re-request review after force-pushes or follow-up commits. Pair this with CODEOWNERS and required-reviewer rulesets rather than replacing them.
Speakeasy Kit ships a compose-first ACP coding runtime
Practical dev impact: If your harness burns a round trip per shell, edit, or test call, try Kit's single compose tool (Runlet programs that batch concurrent work, retries, edits, and ACP subagents) before you add another IDE agent. Speakeasy launched Kit on Product Hunt September 6 as an MIT static binary with a terminal client, ACP server, A2A endpoint, and subagent orchestrator. GitHub releases continued through v0.1.130 on September 8. Kit claims about half the input tokens and active time per hand-written line versus Codex CLI or Claude Code on size-matched production tasks (vendor comparison; run your own). It speaks ACP v1/v2 (stdio, HTTP/SSE, WebSocket), A2A v1, MCP, Agent Skills, and plugins, and can drive Claude, Codex, or Cursor as ACP subagents. Trust model is explicit: no sandbox or permissions framework. Run it inside a boundary you trust and set --root.
Practical Impact Analysis
The through-line today is who owns the agent control plane. JetBrains Copilot's managed sandbox policies close a gap VS Code and Copilot CLI already felt through managed-settings.json: filesystem, network, proxy, and keychain posture can be org-owned, locked in the IDE, and verified with policy diagnostics. If your security team already allowlists MCP servers in JetBrains, sandbox policy is the next checklist item, not a nice-to-have.
Claude Code's September 8 wave is operational, not a model drop. Live plugin folders matter for teams that ship internal skills as directories. The 1 GB tool-result cap matters for CI agents that dump huge logs into the transcript. The v2.1.266 gateway fix matters immediately if any host sets CLAUDE_CODE_USE_GATEWAY while authenticating with API keys. Pin the version in Docker and Actions the way you pin language runtimes.
Copilot approvals are a process change with blast radius. Turning them on for docs/** or generated lockfiles can clear merge queues. Turning them on for auth/** without path filters is how you invent a rubber stamp. Keep human required reviewers for high-risk paths, and treat the always-on approval assessment as a signal even when approvals stay disabled.
Kit is the counterweight to heavier, multi-tool harnesses. One compose program that fans out tests and edits is fewer chat turns and more structured work. It is not a security boundary. Bake it into a trusted container or sandbox if you evaluate it on production trees.
If you only do three things this morning: enable JetBrains Copilot policy diagnostics and decide a default sandbox posture, bump Claude Code pins to v2.1.266, and either leave Copilot PR approvals off with assessments-only or enable them behind path-scoped rules.
Tutorial
Pin Claude Code to v2.1.266, then load a local plugin folder with live reload. Use this when CI or laptops still float on latest or stable, or when you keep internal plugins as sibling directories.
- Pin
@anthropic-ai/claude-code@2.1.266and confirmclaude --version. - Create a parent folder of plugin children. Each child needs a plugin manifest.
- Start Claude Code with
--plugin-dirpointed at that parent. Add or remove a child while it is running and confirm it picks up the change. - On proxy or API-key hosts, do not rely on
CLAUDE_CODE_USE_GATEWAYalone. Prefer explicitANTHROPIC_BASE_URLplus auth, or omit the undocumented flag.
After upgrade, run a short -p task that resumes a subagent and confirm prompt-cache behavior looks normal in /cost. If you previously hit "Not signed in to the Cloud gateway" with API keys plus CLAUDE_CODE_USE_GATEWAY, retest on v2.1.266 before changing auth. Treat ~/cc-plugins like code: review manifests before pointing production agents at them.
Recommended AI prompt
Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever you use.
You are my staff engineer for coding-agent governance on 2026-09-09. GitHub Copilot for JetBrains can now push org-owned sandbox policies that lock over user settings, plus policy diagnostics and /ide linking. Claude Code v2.1.265 adds live --plugin-dir folders and a 1 GB tool-result cap. Pin v2.1.266, which fixes CLAUDE_CODE_USE_GATEWAY forcing Cloud-gateway sign-in beside API-key auth. Copilot code review always shows an approval assessment and can submit a real approval toward required reviews only when an admin enables it, with path filters and off by default. Speakeasy Kit is a compose-first ACP runtime with one compose tool and no built-in sandbox. Ask which IDEs, Claude Code pins, Copilot policies, and review rulesets we run. Then produce a JetBrains sandbox policy matrix, a v2.1.266 pin and plugin-folder rollout, a path-scoped decision on Copilot PR approvals, and a 30-minute Kit compose eval inside a trusted boundary. Keep it concrete and copy-paste ready.