Rolling out a coding agent to your teams: the rules to set before day one
Claude Code, GitHub Copilot, Cursor or Codex read your code, run commands and propose changes. Before opening them to your teams: the plan and your data, shared settings, the sandbox, logs and human review.
A coding agent (Claude Code, GitHub Copilot, Cursor, OpenAI Codex and their equivalents) does more than complete a line: it reads the repository, runs commands, changes files and opens pull requests. Before opening it to your teams, five decisions matter: the plan and what it says about your data, the settings imposed on everyone, what the agent can run, what is logged, and who reviews.
Teams have not waited: according to the 2025 Stack Overflow survey, 84% of developers use or plan to use AI tools, but 46% distrust the accuracy of their output, against 33% who trust it. The frame therefore has to come quickly, and stay simple.
What a coding agent changes compared with autocompletion
Autocompletion suggests text, which the developer accepts or not. The agent acts on the workstation or in a remote environment with the rights it is given: it can read configuration files, run scripts, install dependencies, call services. A booby-trapped file or ticket can then slip it instructions (prompt injection), and it has the means to carry them out.
In April 2026, CERT-FR advised against deploying autonomous assistants on workstations in production. Its bulletin targets office assistants, not coding agents, but its recommendations apply to them by analogy: a sandbox, least-privilege rights, human approval of system commands.
Choosing the tool and plan: what the terms say about your code
- Claude Code : Anthropic’s commercial terms (in force since 17 June 2025) rule out training models on customer content; standard retention is 30 days, and zero data retention exists for some Enterprise accounts.
- GitHub Copilot : GitHub does not use Business and Enterprise data to train its models; since 24 April 2026, data from individual plans may be used unless the user opts out.
- Cursor : the vendor states it does not train on customer data, holds a SOC 2 Type II attestation, and lets you enforce its privacy mode for a whole team.
The rule that follows: company accounts only, never a personal account on company code. Terms change: reread them at every renewal.
Shared settings imposed on every team
Each tool lets the administrator set rules the user cannot lift: a managed settings file for Claude Code (deployed on workstations or from the admin console), organisation policies for Copilot, a requirements file for Codex, enterprise controls for Cursor. At a minimum, set:
- the commands allowed, those that require confirmation and those that are forbidden (Claude Code checks forbidden rules first, then confirmations, then allowed ones);
- a ban on the modes that remove every confirmation: Claude Code’s documentation points out that this mode offers no protection against prompt injection;
- the MCP servers and extensions that are allowed, and only those;
- the models allowed, and the use of the company plan.
Secrets and production out of the agent’s reach
The sandbox limits what the agent can touch. Claude Code’s is enforced by the operating system, but it is off by default and covers commands only: it restricts writes to the working folder and filters outbound internet traffic, while reads still reach most of the disk unless they are denied. Codex turns internet access off by default. In every case:
- turn the sandbox on and enforce it through managed settings;
- deny reads of keys and secret files;
- leave no production credentials on development workstations;
- give the agent dedicated tokens, limited to the repository and the actions it needs.
Logging every action
Claude Code can export its metrics and events (sessions, tools used, permission decisions, costs) to your monitoring tool through OpenTelemetry, with prompt text masked by default; its hooks run your own checks before or after each action, and can block it. Copilot keeps an audit log of policies and of its agents’ activity, which does not include prompt text. Cursor offers audit logs in its Enterprise plan. The goal: know who started what, with what result, and spot abnormal use.
Human review stays mandatory
ANSSI and its German counterpart, the BSI, wrote it as early as October 2024: coding assistants do not replace experienced developers, and generated code must be checked. GitHub’s agent applies this principle by design: it works in an ephemeral environment, pushes to its own branch, and its pull requests must be reviewed and merged by a person, who cannot be the one who asked for them.
Whatever the tool, the same rule applies: protected branches, tests and mandatory security analysis, and human review before any merge. Our page Software development automation describes how we bring agents into your toolchain with these approvals.
Training the teams
- what the agent can do, and what it must not do;
- how to review a change proposed by an agent;
- recognising prompt injection in a ticket, a file or a page;
- the data you never paste into a prompt.
Going further: our articles on securing AI agents and on platform engineering, and the page Agentic AI under your control.
Frequently asked questions
Can the agent read our whole repository?
By default, it reads what is reachable from its working folder, and often more. Deny rules and the sandbox narrow that scope; Copilot’s content exclusion does not apply to the Edit and Agent modes of Copilot Chat.
Is our code used to train the model?
Not with the company plans of Claude Code, GitHub Copilot and Cursor, according to their current terms. Individual plans can work differently: one more reason to keep them away from company code.
Claude Code, Copilot or Cursor: what criteria to choose on?
The terms on your data, the settings an administrator can enforce, the sandbox, traceability, and integration with your code platform and your CI/CD pipeline. The right choice is the one you can frame.
Should autonomous mode be banned?
The mode that removes every confirmation, yes, except in an isolated, disposable environment. A mode where the agent moves on its own for harmless actions and asks for the rest can be justified, if it is framed by managed settings and the sandbox.
Sources
Facts and figures checked on 3 October 2026.
- Claude Code, permissions and permission modes.
- Claude Code, managed settings.
- Claude Code, sandboxing.
- Claude Code, monitoring with OpenTelemetry.
- Claude Code, data usage.
- Anthropic, commercial terms, in force since 17 June 2025.
- GitHub, managing Copilot policies.
- GitHub, Copilot cloud agent risks and mitigations.
- Cursor, data use, 3 September 2026.
- Cursor, security, 25 August 2026.
- OpenAI Codex, approvals and security.
- Stack Overflow, 2025 Developer Survey, AI.
- ANSSI and BSI, recommendations on AI coding assistants, 4 October 2024.
- CERT-FR, bulletin CERTFR-2026-ACT-016, 13 April 2026 (in French).