GitHub Copilot · ~1 hr

6 Ways to Customise Your Code Review

Overview ~67 min left
Issues? DM me

6 ways to Customise your Code Review

GitHub Copilot mascot

What you'll walk away with

When to Customise

Generic reviews miss what matters, customise Copilot to catch the risks your team actually cares about.

Custom Instructions

Use Custom Instructions to tailor Copilot's behavior to your specific needs and preferences.

Agent Instructions

Write repo-wide rules in AGENTS.md so every agent reviews against the same conventions, architecture, and definition of done.

Agent Skills

Package a specialist review workflow as a reusable Skill so every reviewer, human or agent, applies the same domain expertise on demand.

MCP Servers

Connect an MCP server to pull in live context, like ticket details or internal docs, so reviews are grounded in more than just the diff.

Review Effort Level

Set the review effort level to match the stakes, quick pass for low-risk changes, deep pass for the ones that matter.

Memory

Give Copilot persistent memory of past review decisions and conventions, so it stops flagging the same settled debates every pull request.

Next Steps

Pick one customisation to try on your next pull request, then build out the rest of your review setup from there.

Duration: 2 minutes
Meet the company Moola Financial

When should you customise code review?

An Australian digital bank running Copilot Business with nothing configured.

Digital bank 200 engineers One monorepo APRA regulated Nothing configured

It's Tuesday. Three PRs are open.

Open 3
Partial refund endpoint High risk
#4102 · opened on Tue · Payments code, ledger migration, feature flag — linked to PAY-1421
Onboarding copy & marketing page Low risk
#4118 · opened on Tue · Content only — no application logic touched
Notification service refactor Looks routine
#4125 · opened on Tue · Cross-service change that quietly alters retry behaviour

This is the part worth spending time on, because everyone in the room has lived it. Each one is tagged with the lever that closes it.

Duration: 5 minutes

Fix it with Custom Instructions

Two files, checked into the repo. Each one maps back to a pitfall from the last step.

1A

Repository custom instructions

One file, applied to every review in the repo.

.github/copilot-instructions.md Whole repo

This is a Django and React monorepo.

Do not comment on import ordering or formatting — ruff and prettier handle those.

Flag any raw SQL that is not parameterised.

Every new API endpoint needs a permission class and a test.

The noise stops immediately, and reviewers start reading the review again. This is the single highest leverage change, and it takes ten minutes.

1B

Path specific instructions

A different bar for a higher risk part of the codebase.

.github/instructions/payments.instructions.md Scoped
--- applyTo: "services/payments/**" ---

Monetary values must use Decimal, never float.

Every write to the ledger must be inside a transaction.

Flag any new external HTTP call without an explicit timeout.

Flag any log or error path that could emit a full customer record or a raw PAN, email, or address.

#4102 the float on money, and the error path that logs the whole customer #4118 never sees a payments rule

Same reviewer, a different bar per area of the codebase. The APRA conversation moves from the audit sweep to the pull request.

Duration: 5 minutes

Fix it with Agent Instructions

Custom instructions only reach Copilot. AGENTS.md is the open standard a growing number of agents read — one file at the root of the repo, next to the code it describes.

2

Agent instructions

One file at the repo root, read by the tools that support the standard.

AGENTS.md Repo root

The monorepo layout — what lives where, and which package owns what.

The build and test commands, so an agent runs the right ones.

The architectural rule: packages/core must not import from packages/web.

Reads AGENTS.md today
Copilot code review Copilot cloud agent Copilot CLI
#4125 pulled up for a boundary violation it introduced while refactoring

The architecture rules stop drifting, because they live next to the code instead of in a Confluence page nobody opens.

Duration: 5 minutes

Fix it with Agent Skills

One folder in the repo. A procedure that only loads when the diff calls for it.

3

Agent Skills

A specialist checklist for database migrations, written once instead of living in one engineer's head.

.github/skills/code-review-database-migrations/SKILL.md On demand
--- name: code-review-database-migrations description: "Review checklist for schema migrations. Use when the diff contains a migration." ---

Check that the migration is reversible.

Check that it does not take a lock on a table with more than a million rows.

Check that any backfill is a separate migration from the schema change.

Check that the PR body contains a rollout and rollback note.

Two rules that catch people out

name must match the folder name, and the description is what Copilot matches on — write it as “use when…”. A review-focused folder name makes selection more likely.

#4102 ledger migration — the checklist is relevant #4118 no migration — nothing to select

Dead weight on #4118. Exactly right on #4102.

How you know it actually fired

Copilot AI 3m ago High

This migration drops ledger_entries.status in the same step as the backfill, so it is not reversible and takes a lock on a table with 14M rows. PAY-1421 requires a zero downtime deploy — split the backfill into its own migration and add a rollout and rollback note to the PR body.

Fix with Copilot
This comment was generated using the Jira MCP and this repository’s code-review-database-migrations agent skill.

Copilot names what it used. That footer is the answer to “how do I know the skill is working?” — and the fastest way to debug one that is not being picked up.

The distinction worth drawing out

Repo instructions

Always available

Considered on every review in the repo.

Path instructions

Automatic on match

Apply when the diff touches the paths you scoped them to.

Skills

Selected when relevant

Copilot picks the skill up when the description matches the change.

Duration: 5 minutes

Fix it with MCP Servers

Instructions tell Copilot what to care about. An MCP server tells it what is actually going on — the ticket that asked for the change, and the errors that code is throwing in production.

4

MCP servers

Two connections, enabled once at repository level.

Jira MCP server Intent

The ticket behind the branch — what the change was actually asked to do.

Sentry MCP server Reality

Live production errors — which files are already hurting, and how badly.

Two things the review could not say before #4102
Jira

PAY-1421 specifies that refunds must be idempotent, because the provider retries on timeout. This endpoint does not accept or check an idempotency key.

Sentry

This handler is in the file responsible for the highest volume production error this week.

Copilot AI 3m ago High

This endpoint accepts no idempotency key, so a provider retry creates a second refund. PAY-1421 requires refunds to be idempotent because the provider retries on timeout — check the key before the ledger write.

Fix with Copilot
This comment was generated using the Jira MCP and this repository’s code-review-database-migrations agent skill.
#4102 missing idempotency key caught against the ticket that required it

The reviewer stopped reviewing the diff and started reviewing the change.

Duration: 5 minutes

Match the depth to the risk with review effort level

Reasoning is a budget, not a setting you max out. Keep the default cheap, then raise the bar only where the risk actually lives.

5 Generally available Changelog · 7 Aug 2026 ↗

Three places you can set it

Organisation Lite

The default stays Lite for every repo. Cheap, fast, good enough for most changes.

Repository override Balanced

payments-api and auth-service are overridden to Balanced. The money and the front door get the deeper pass, always.

Per review Manual

Any reviewer can raise the effort for one review when a change smells riskier than it looks.

What the graduate clicks on #4125

Reviewers
Copilot Balanced
Lite Efficient review, low cost
Balanced Deep analysis, moderate cost
Max Most thorough, high cost
Coming soon
Applies to this pull request for everyone.

It is a per-pull-request setting, not a per-person one. Raising the effort raises it for every reviewer on that PR, so it is a decision about the change, not a personal preference.

Max is not shipped yet. When it lands, the ceiling goes up — the discipline of choosing does not change.

The same three PRs, three different budgets

#4102 Partial refund endpoint
Balanced

Gets the deeper reasoning pass and the cross service analysis.

Automatic — it lives in payments-api
#4118 Onboarding copy
Lite

Gets a fast, targeted review. Nothing here needs deep reasoning.

Automatic — org default
#4125 Notification refactor
Balanced

The graduate picks Balanced for this one review because the retry behaviour change worries them.

Manual — judgement call by the author

What it costs, roughly, per review

Lite $0.05 – $1 typical AI credit value per review
Balanced $0.25 – $5 typical AI credit value per review

Moola is not paying Balanced prices to review marketing copy. Estimates only — actual credit use varies with diff size and instructions, and excludes Actions minutes.

Duration: 5 minutes

Stop re-teaching it with Copilot Memory

Everything so far you had to write down. Memory is the one that learns on its own — Copilot retains repository level facts from past reviews and applies them to the next one.

6

Copilot Memory

Repository level facts, learned from earlier reviews.

Before you promise this
Public preview Admin enables the policy Users can opt out
Learned from an earlier PR No file · nobody wrote it down

config/features.yaml and web/src/flags.ts must stay in sync.

Kept as a repository level fact, re-validated against the branch before it is used, and dropped if nothing uses it for 28 days.

#4102 adds the refund flag to one file and not the other, and gets flagged

Nobody had to write that rule down anywhere.

Worth calling out — the trust boundary

Code review uses repository level facts only.

It does not apply the personal preferences of whoever requested the review.

The review does not change depending on who clicked the button.

Duration: 5 minutes

Where to start on Monday

You do not need all six. Pick the one that fixes the pitfall your team actually has, ship it on your next pull request, and add the rest as you go.

A sensible order

Today 5 minutes
  • Write a copilot-instructions.md for one repo. Name the linters you already run so Copilot stops repeating them.
  • Open the last review your team collapsed without reading. Every comment in it is a rule you can write down.
This month An afternoon
  • Add path specific instructions for your riskiest directory — the one holding money, auth, or customer data.
  • Move the shared conventions into AGENTS.md so every tool reads the same rules.
  • Raise review effort to Balanced on those repos only. Leave the org default on Lite.
This quarter Needs a decision
  • Turn your most-missed procedure into a Skill. Migrations and incident-prone paths are the usual first pick.
  • Connect MCP servers for your tracker and your error monitor, so reviews see intent and production reality.
  • Ask your admin to enable Copilot Memory, then stop re-teaching settled decisions.

The six, and what each one is for

Customisation Where it lives Fixes
1 Custom instructions .github/copilot-instructions.md
.github/instructions/*.instructions.md
P2 noise · P3 house rules · P4 the regulator
2 Agent instructions AGENTS.md P7 different tools, different rules
3 Agent Skills .github/skills/<name>/SKILL.md
name: must match the folder
P5 procedures that only apply sometimes
4 MCP servers Repository settings · read only P6 it cannot see intent
5 Review effort level Org → repo → per review P1 every PR gets the same treatment
6 Copilot Memory Admin policy, then automatic P8 the same lesson re-taught forever

There is no single setting that fixes review. What changes it is the right rules, live context, the right effort, and knowledge that survives the pull request — the difference between a review your team collapses and one they wait for.

Customisation improves relevance. It is not a deterministic policy engine, and it does not replace human review, CodeQL, rulesets, or your compliance controls.

🎉 That's the six — go customise one repo