Skip to main content

Copilot code review billing: bill the member or the organisation?

GitHub now lets organisation owners bill Copilot code reviews to the organisation instead of each member's quota, and block reviews requested with outside Copilot licences. How the two settings work and how to choose.

Share -
An engineer in a dim teal-lit office studies a large monitor of bar charts, line graphs and ring charts, with more dashboards glowing in the background

GitHub now lets organisation owners bill Copilot code reviews to the organisation rather than each requesting member's own Copilot quota, and lets them refuse reviews requested with a personal or outside licence. Teams that rely on Copilot review in their pull request flow should decide who pays, set a budget, and close the outside-licence route.

What was released

New billing and licence controls for Copilot code review were announced by GitHub on 8 October 2026 in the GitHub changelog. There are two settings. The first changes who pays for a review requested by a member who holds a Copilot licence. The second controls whether a review can be requested with a Copilot licence that your organisation or enterprise did not provide.

What actually changed

Until now, a review requested by a licensed member was always billed to that member's own Copilot entitlement. According to the announcement, that is still the default, and it has a sharp edge: if the member's quota is exhausted, the code review fails.

  • Choose how members with a Copilot license are billed. The setting has two values. Member (the default) keeps billing the member's own entitlement. Organization bills the organisation that owns the repository, so reviews no longer consume or exhaust member quotas. Choosing Organization requires AI Credits paid usage to be enabled for the organisation, and you can optionally set a budget. The setting sits in organisation settings under Copilot, then Policies.
  • Only allow Copilot code review to be triggered by authorized users. By default, anyone with a paid Copilot licence can request a Copilot review in repositories they can access. With this setting on, review requests must come from people whose Copilot licence was provided by your organisation or enterprise, so a personal licence no longer works. Organisation owners and repository admins can turn it on, and if it is turned on at organisation level, repository admins cannot turn it off.

GitHub's code review documentation covers how the authorised-users setting applies to personal repositories, automatic reviews and API requests.

Member or organisation billing: how to choose

This is CodeDTX's advice, not GitHub's. The question is whether code review is a personal tool or part of your delivery pipeline.

  • Keep Member billing when review is occasional and developer-initiated, and you want each person's usage to stay visible against their own allowance.
  • Switch to Organization billing when review is a required step, for example automatic reviews on every pull request or reviews requested by a coding agent or a script through the API. When one developer runs out of quota, their reviews fail, and a required step that silently stops running is a pipeline problem, not a personal one.
  • Set the budget before you switch. Organisation billing moves review spend from many small, capped allowances into one shared account. Without a budget, a busy week of agent-generated pull requests shows up only on the bill. Our guide to controlling what an AI agent costs to run covers how to set limits and alerts that people actually see.

Why the outside-licence control matters

Contractors, open source contributors and staff with their own Copilot subscription can all request reviews today. That makes it hard to say which licence terms and data settings applied to a given review. Turning on the authorised-users setting at organisation level gives you one answer: every Copilot review in your repositories ran under a licence you manage. For teams that need to show who or what reviewed a change, that is easier to defend in an audit, and it fits the record-keeping in what an AI agent audit trail contains.

What to check before you change either setting

  1. Find out who requests reviews today. If outside contributors or contractors rely on their own licences, the authorised-users setting will stop their requests. Give them a managed seat, or accept that their pull requests get human review only.
  2. Check automatic and API-triggered reviews. If you request reviews programmatically, as described in our post on the Copilot code review API, read GitHub's notes on how the setting treats API requests before turning it on.
  3. Decide whether review is allowed to fail open. With Member billing, an exhausted quota means no review. If a missing review should block a merge, make that an explicit branch rule rather than assuming the review always runs.
  4. Keep the policy change with people. Billing scope and budgets are organisation policy. Agents and automation that request reviews should not hold the permissions to change them, a principle covered in AI agent skills security and governance.

When not to switch

If your organisation has not enabled AI Credits paid usage, Organization billing is not available until you do, and that is a budget decision in its own right. Small teams where every member has headroom in their quota gain little from moving spend into a shared pool. And if open source contributors are a core part of how your repositories work, turning on the authorised-users setting at organisation level may cost you more review coverage than it gains in control; apply it to the repositories that hold sensitive code first.

Frequently asked questions

What happens when a member's Copilot quota runs out during a code review?

Under the default Member billing setting, GitHub bills a Copilot code review to the requesting member's own Copilot entitlement, and if that quota is exhausted, the code review fails. Organisation owners can avoid this by switching the billing setting to Organization, which bills the organisation that owns the repository instead. That option requires AI Credits paid usage to be enabled for the organisation.

Where do you change Copilot code review billing for an organisation?

Organisation owners find the setting in organisation settings, under Copilot and then Policies. It is called Choose how members with a Copilot license are billed, with two values: Member, the default, and Organization. Switching to Organization needs AI Credits paid usage enabled, and GitHub lets you optionally set a budget so shared review spend has a ceiling.

Can you stop people using a personal Copilot licence to review your code?

Yes. Organisation owners and repository admins can turn on the setting Only allow Copilot code review to be triggered by authorized users. Review requests must then come from people with a Copilot licence provided by your organisation or enterprise, so personal licences no longer work. If the setting is turned on at organisation level, repository admins cannot turn it off for their repositories.

Should teams switch Copilot code review to organisation billing?

It depends on how you use review. If Copilot review is a required step in your pull request flow, or agents and scripts request it through the API, organisation billing stops reviews failing because one person ran out of quota. Set a budget first so spend stays visible. If review is occasional and developer-led, keeping the Member default is reasonable.

Share this post

Contact us to build the right product

Talk to our engineers about your application, the systems it connects to, and what you want to build next.

Get in touch
Two people discussing work with a laptop