The trigger moved into code.
GitHub announced API support for requesting Copilot code review on October 2. A caller can use REST or GraphQL and set an effort level for each request. GitHub also changed its built-in default to Balanced on September 28. An explicit Lite setting stays Lite.[1]
This turns review into an operation that an issue tracker, release service, or internal tool can start. It also creates a policy question. A convenient endpoint can make review volume automatic before anyone decides which changes need deeper analysis.
Triggering review is transport. Routing review is judgment.
Effort has a job and a cost.
GitHub describes Lite as its standard review. Balanced applies deeper analysis to complex logic, security-sensitive code, and cross-service changes. Max appears in settings with a coming-soon label and is not available yet.[2]
The levels do not cost the same. GitHub currently estimates that one Lite review uses $0.05 to $1 in AI credits. Its estimate for Balanced is $0.25 to $5. Those ranges can change as models change, and they exclude GitHub Actions minutes.[3]
Do not turn those estimates into a price calculator. Use them to make one point visible. The deeper lane spends more. A repository default needs a budget owner, and an API caller needs a reason when it overrides that default.
The runner changes what the reviewer can see.
Copilot code review can use GitHub Actions for repository context and tool use. GitHub says a review still runs if Actions is unavailable, but without those agentic capabilities. If an organization disables GitHub-hosted runners, it can supply self-hosted runners or receive a more limited review.[3]
A review receipt should record that distinction. "Copilot reviewed this" hides whether the run had project context, which runner path it used, and whether a spending limit blocked the request. GitHub says reviews can be blocked when the relevant user, enterprise, or cost-center budget is exhausted.[3]
Keep the merge gate separate.
GitHub warns that Copilot may miss problems or make mistakes. Its documentation says to validate the feedback and add human review.[3] That is the line an automated trigger must not erase.
Route by the change in front of you. A small documentation edit may fit Lite. Authentication, billing, migrations, cryptography, infrastructure, and cross-service behavior belong in a deeper lane with a named human reviewer. Large generated changes may deserve reduction before review, not more automated commentary after the fact.
The pit lane below prepares a request card. It does not call GitHub, inspect a pull request, spend credits, run Actions, request a reviewer, or approve a merge.