What changed
An enterprise or organization owner can now choose to bill the organization instead of the member. Billing the organization requires AI credits paid usage, but a budget is optional. The other new control lets owners and repository admins block reviews requested through licenses that come from outside the organization.
| Control | What it does | Default |
|---|---|---|
| Choose how members with a Copilot license are billed | Picks who pays for reviews tied to licensed members: the member or the organization | Member |
| Only allow Copilot code review to be triggered by authorized users | Blocks review requests made with external Copilot licenses | Off, so external licenses can request reviews |
Billing: Member or Organization
The Member option is the default. It bills the member's own Copilot entitlement. If the member's quota is exhausted, the code review fails. That is a bad outcome on a busy pull request, and it is the problem the new option is meant to fix.
The Organization option bills the organization that owns the repository. GitHub's changelog says this is meant to avoid consuming or exhausting member quotas. Per GitHub's changelog, you find it in organization settings under Copilot and then Policies. GitHub's configuration documentation describes the same setting in the organization's Copilot code review settings.
Some details to know before you switch:
- The choice applies to both manually requested and automatic code reviews, and it changes billing only.
- On its own, it does not grant access to Copilot code review. Switching to Organization does not give anyone new review rights.
- AI credits paid usage must be enabled for the organization first. A budget is optional, but you should set one anyway.
- Enterprises get a third choice. GitHub's documentation lists Member, Organization, and "Let organizations decide." With the last one, organization owners pick their own billing policy. If your organization sits under an enterprise policy, you may not have a free choice locally.
What the bill looks like
GitHub's billing documentation says each review consumes AI credits, and the amount depends on the model used and the number of tokens processed. The billing docs define the credit as 1 AI credit = $0.01 USD. For organizations, each assigned Copilot license comes with included monthly credits that can be pooled at the billing-entity level.
GitHub's code review overview gives rough estimates: about $0.05 to $1 in AI credits for a typical Lite review, and $0.25 to $5 for a typical Balanced review. GitHub says consumption rises with pull request size and repository custom instructions. It also says the ranges may change as models evolve. Treat these as planning figures, not prices. The estimates also exclude GitHub Actions minutes, which cover the agentic parts of a review such as gathering project context.
What happens when a budget runs out
For Copilot Business and Enterprise, GitHub documents that code review access follows the budgets for whichever billing source is selected. If usage is billed to a user, reviews are blocked when that user reaches their budget. If usage is billed to an organization, reviews are blocked when the applicable organization budget, cost center budget, or enterprise spending limit is exhausted. Reviews are blocked along with other AI credits-consuming features.
So the Organization option moves the failure point from one developer's quota to a shared organizational limit. It does not remove the failure point. If you pick it, you should set the budget deliberately and watch it.
Who can request a review
By default, an external Copilot license is one not provided by the organization or enterprise that owns the repository, such as a personal license or a license from another organization. By default, people can use an external license to request a review.
Enabling Only allow Copilot code review to be triggered by authorized users closes that gap. The GitHub changelog says if the setting is enabled for your organization, you cannot turn it off for the repository. Repository admins can still enable it for a single repository.
GitHub's documentation lists these effects when the setting is on:
- Copilot is not offered as a reviewer to people who are not authorized, and API review requests from those people do not start a review.
- In personal repositories, only the repository owner or a direct collaborator can request a review.
- Automatic reviews from personal settings do not run for unauthorized people. Automatic reviews configured by repository or organization rulesets still run.
That last point matters. The setting is not a kill switch for all automatic review activity. If you want to stop ruleset-driven automatic reviews, you have to change the rulesets themselves.
A suggested rollout
This is my own practical reading of the documentation, not GitHub guidance.
- Decide what problem you have. Are developers running out of quota? That is a billing problem. Are outside or personal licenses triggering reviews in your repositories? That is an access problem. Some teams have both.
- Check paid usage. Confirm AI credits paid usage is enabled for the organization before choosing Organization billing.
- Set a budget. Decide on an organization, cost center, or enterprise limit. Remember that hitting it blocks reviews along with other AI credits-consuming features.
- Check enterprise policy. If your enterprise uses a fixed Member or Organization policy, local owners cannot override it.
- Review your rulesets. Automatic reviews set by rulesets keep running whatever the authorization setting says.
- Tell your developers. If you enable the authorization restriction, contributors who used a personal license will lose the ability to request reviews. They will want to know why.
Analysis
Organization billing is a sensible fix for a real annoyance. When a developer's personal quota decides whether a team's pull request gets reviewed, a failed review is hard to diagnose. Pooling the cost under the organization is easier to budget for. The tradeoff is that spending becomes less visible per person, so administrators need to use the budget controls.
The authorization setting is a governance feature. It gives organizations a way to keep review activity tied to licenses they manage. This is general industry reasoning, not something GitHub states. Teams that care about knowing whose entitlement is being used, or that want review activity to stay within company-managed licensing, will probably welcome it.
One caution applies to both settings. Neither changes whether Copilot's feedback is correct. GitHub's own documentation says Copilot can make mistakes and that its feedback should be validated and supplemented with human review.
Bottom line
- Billing now has two modes: Member (default) and Organization. Organization billing needs AI credits paid usage and can have an optional budget.
- The billing setting changes who pays. It does not change who has access.
- The authorized-users setting blocks review requests from external licenses. Once an organization enables it, repository admins cannot turn it off.
- Ruleset-driven automatic reviews are not affected by the authorization setting.
References
- Copilot code review: New organization billing options and controls GitHub Changelog · 2026-10-08T19:43:05+00:00
- Configuring code review by GitHub Copilot - GitHub Docs docs.github.com
- GitHub Copilot billing - GitHub Docs docs.github.com