Microsoft announced Azure canvases for GitHub Copilot on September 30, and the pitch is simple: instead of bouncing between the Azure portal, the CLI, and your editor, the Azure tools you need sit in a shared workspace next to your Copilot conversation. Three canvases ship first: one for building and debugging Azure Functions skills, one for browsing resources, and one for checking what your cloud actually costs.
What a canvas is, mechanically
Canvases are a feature of the GitHub Copilot app, the standalone desktop app GitHub made generally available in June 2026. A canvas is a bidirectional work surface that opens in the app’s right side panel. The agent writes into it while it works. You can edit, reorder, approve, or redirect on the same surface, and both the human and the agent operate on the same shared state. Think of it as the difference between an agent narrating its work in chat and an agent filling in a form you can both touch.
That model first appeared in the app’s technical preview in June, where canvases were the headline addition. The Azure canvases extend it from code tasks into cloud operations, and Microsoft distributes them as plugins through the Awesome Copilot marketplace rather than baking them into the app.
The three launch canvases
The initial collection covers three distinct jobs, and each one has interesting constraints baked in.
Azure Resources Query browses your resources through read-only Resource Graph queries, with explicit subscription selection. The read-only default is the right call: an agent that can browse your estate is useful, an agent that can modify it by accident is a pager. You can see what exists across subscriptions without the agent holding broad write permissions.
Azure Cost Health Check surfaces cost data, forecasts, budget alerts, Advisor recommendations, and AI billing analysis, all read-only. Cost review is one of those tasks everyone agrees matters and nobody volunteers for. Handing it to an agent that summarizes and flags anomalies turns a quarterly spreadsheet chore into a five-minute conversation.
Azure Functions Hosted Skills is the developer-facing one. It lets you build, run, and debug Azure Functions Hosted Skills from a Copilot canvas, locally, without an Azure subscription for testing. It uses your GitHub identity for authenticated calls, and when you are ready it can deploy an isolated copy to Azure using azd, which provisions a managed identity and the right RBAC along the way. You can also expose the finished skill as an MCP tool, which means the thing you built in a canvas becomes callable infrastructure for other agents.
Why this design choice matters
The interesting engineering detail is what does not require a model call. Microsoft says routine interface operations in canvases execute in code without another model request. A table refresh, a filter, a query re-run: these are plain code paths, not inference calls. That lowers latency and, in principle, consumption of Copilot premium requests or AI credits. Microsoft has not published measured savings, so treat it as a design benefit rather than a benchmark, but the architecture point stands: good agent UX pushes deterministic work out of the model and into code.
Building canvases is not free, either. One GitHub author reported that a custom Site Studio canvas consumed roughly 2,000 AI credits and a modernization canvas about 3,000 to design well. The launch canvases are Microsoft’s, so you pay nothing to use them, but teams planning custom canvases should budget the authoring cost like any other tooling investment.
Governance before rollout
Two admin details are easy to miss. First, for Copilot Business and Enterprise, the GitHub Copilot app has its own policy, separate from the Copilot CLI policy, and it is enabled by default. If your org deliberately disabled the CLI, do not assume the app is locked down too. Check it.
Second, the canvases are powerful but scoped: the resource browser is read-only, the cost view is read-only, and the Functions canvas deploys with a managed identity rather than your personal credentials. That is a sensible permission posture, but subscription selection is still explicit, so the pilot question is which subscriptions your developers can reach and whether the read-only boundary is acceptable for your compliance posture.
What to do with it
- Install the Azure CLI and authenticate with az login, then open the GitHub Copilot app, go to Customize, then Plugins, and add the Azure canvases before starting a new session.
- Pilot the Resources Query canvas first. It is read-only, low risk, and immediately useful for answering “what do we actually run in that subscription?”
- If you write Azure Functions, try the Hosted Skills loop end to end, including the azd deploy path, and evaluate whether the local-first workflow beats your current one.
- Admins on Business or Enterprise: confirm the Copilot app policy status for your org before users adopt canvases around you.
- If you plan a custom canvas, scope it to one workflow and price the AI credit cost before committing.
The broader shift here is positioning. GitHub has been turning the Copilot app into an extensible agent workspace, and Azure is the first major cloud to build first-class tools inside it. The agent conversation stops being the product; the visible, steerable, shared surface around it is. Whether that pattern spreads to other clouds will depend on whether teams actually keep these canvases open past the first week, which is the only adoption test that counts.