AI coding governance

Copilot Code Review: Who Pays and Who Can Request It

•Make Better Editorial

GitHub's new Copilot code review billing and external-license controls explained for admins.

GitHub added two administration controls for Copilot code review on October 8, 2026: choosing whether licensed members or the repository-owning organization pays for reviews, and restricting requests made with Copilot licenses issued outside the organization. These are independent choices. Changing the payer does not grant review access, and restricting who can request a review does not decide who pays.

Member versus organization billing

Member is the default. Reviews associated with a licensed member consume that person's Copilot entitlement; when the applicable allowance runs out, a review may fail. Organization owners can instead charge the organization that owns the repository. Organization billing requires AI credits paid usage to be enabled, while a budget is optional. The policy applies to manually requested and automatic reviews. Central billing can simplify management, but organization budgets can still stop reviews when exhausted.

External licenses and automated triggers

By default, someone with a paid personal Copilot license or a license from another organization can request a review in a repository they can access. Admins can restrict these requests to authorized users. Organization-level restrictions cannot be overridden by repository admins. GitHub notes that automatic reviews triggered through organization or repository rulesets may continue even when a person's own automatic-review setting cannot trigger one. Test manual and ruleset-based requests separately.

A useful cost scenario

GitHub estimates Lite reviews use roughly $0.05–$1 in AI credits and Balanced reviews $0.25–$5, depending on the change and context. At 100 Balanced reviews, the published range implies $25–$500 of AI-credit consumption. This is a scenario calculation, not a fixed price or forecast. Agentic reviews may also consume GitHub Actions minutes, which must be budgeted separately.

Rollout checklist

First confirm the intended billing owner in organization Copilot settings. If charging the organization, enable AI credits paid usage and decide on a budget. Next decide whether personal or external Copilot licenses should be allowed to request reviews. Test both permitted and restricted accounts, including manual and ruleset-triggered reviews. Track actual credits, Actions minutes and failures before enabling review across many repositories. Keep ordinary tests and human approvals; these controls govern access and spending, not AI accuracy.

Bottom line

This update complements GitHub's earlier code review API release. That API made reviews programmable; the new controls determine which requests are allowed and where their costs land.

Sources & useful resources