GitHub Copilot can now run an agent plan defined in code instead of inventing the whole process from one prompt. That makes orchestration repeatable, but it also makes bad permissions repeatable.
GitHub released dynamic workflows in public preview on October 1. The capability is available through Copilot CLI, the Copilot app, and the Copilot SDK on all plans. A workflow can mix deterministic steps, agents, sequential or parallel execution, checkpoints, and structured results.
A workflow is not the same as fleet
GitHub’s dynamic workflow documentation distinguishes the feature from /fleet. Fleet starts delegated agents from a prompt. A dynamic workflow defines the process in code, making the order, dependencies, and expected outputs easier to review and rerun.
That distinction matters for release checks, issue triage, and repository maintenance. A team can pin a sequence rather than rely on an agent to rediscover it. The code still needs tests, versioning, and an owner.
Checkpoints are the control surface.
A useful checkpoint should test an observable condition: a clean diff, passing tests, an approved issue label, or a maximum change size. “The agent says it is finished” is not a meaningful gate. Save structured results that a later step can verify without interpreting prose.
Parallel branches can shorten a run, but they can also edit overlapping files or duplicate expensive research. Define file ownership and merge rules before turning independent agents loose on the same repository.
Programmatic execution changes the permission model.
The programmatic CLI reference says direct execution does not show interactive approval prompts. Grant required permissions in advance, and deny actions without approval. This is safer than silently escalating, but an overly broad permission set can authorize the entire workflow.
Create a dedicated profile for the workflow. Grant only the tools, repositories, and command families used by its steps. Do not copy an unrestricted interactive-agent configuration into an unattended run.
Usage credits need a task budget.
Agents and subagents consume plan usage. A loop, retry storm, or wide parallel fan-out can spend credits without producing an accepted result. Track calls, elapsed time, and retries by workflow version. Stop the run when a cost or iteration ceiling is reached.
- Pin the workflow code and dependencies in version control.
- Use explicit inputs and typed outputs between steps.
- Require checkpoints before writes, merges, and external actions.
- Limit tools, repositories, commands, retrievals,s and parallel branches.
- Keep an immutable run log and the final reviewed diff.
- Test resume and rollback paths before scheduling unattended work.
Dynamic workflows complement rather than replace the multi-model routing described in our HydraFusion guide. One controls the process; the other can influence which models contribute. Both need a measurable acceptance gate.