Skip to main content

ChatGPT/Copilot Prompt to Write Org-Wide Copilot Custom Instructions

Write GitHub Copilot custom instructions at org, repo, and personal level to align AI suggestions with company standards.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
Create a layered GitHub Copilot custom instructions setup for my mid-size fintech company (200 engineers) organization. 1) Organization-level instructions: enforce PCI-DSS for payment code, GDPR for user data, SOC 2 logging requirements across all repositories — security patterns, approved libraries, and data handling requirements. 2) Repository-level instructions for our backend API services, frontend SPAs, shared libraries repos: project-specific architecture, naming conventions, and file structure rules. 3) Personal-level instructions for senior backend, junior frontend, full-stack developers: preferred coding style, debugging approach, and documentation habits. 4) Write instructions that prevent Copilot from suggesting hardcoded secrets, dynamic code execution, innerHTML for user content, SQL string concatenation which violate our security policies. 5) Include framework-specific instructions for Spring Boot (Java), React (TypeScript), FastAPI (Python) that produce idiomatic code. 6) Add testing instructions that ensure generated tests follow Given-When-Then naming, no test interdependency, mock external services. 7) Create a review checklist teams can use to evaluate and update custom instructions quarterly. Provide the complete markdown content for each instruction level.

What this prompt does

This prompt produces a layered GitHub Copilot custom-instructions setup so AI suggestions align with company standards at three distinct levels. It is parameterized on [org_type] and asks for organization-level rules enforcing [compliance_rules], repository-level rules for your [repo_type] repos, and personal-level rules for [developer_role] developers. Because Copilot reads these instructions as context for every suggestion, the rules effectively ride along with each completion instead of being checked only later.

The structure works because governance is naturally layered, not monolithic. Organization-level instructions carry security and data-handling requirements across every repository; repository-level instructions encode project architecture, naming, and file-structure rules specific to each repo type; and personal-level instructions capture an individual developer's style and habits. On top of that, the prompt writes instructions that stop Copilot from suggesting [forbidden_patterns] such as hardcoded secrets or SQL string concatenation, adds framework-specific guidance for [frameworks_used] so generated code is idiomatic, enforces [test_conventions] on generated tests, and includes a quarterly review checklist. The deliverable is the actual Markdown content for each level. Blocking the patterns that violate policy at the instruction level beats catching them later in an audit.

When to use it

  • You are rolling Copilot out across a team and want suggestions to respect your standards from the start.
  • You need compliance and security rules to ride along with every suggestion, not be caught later in audit.
  • You have multiple repo types that each need different architecture and naming guidance.
  • You want to discourage specific dangerous patterns at the instruction level.
  • Your test suites should follow consistent conventions even when AI-generated.
  • You want a repeatable process to review and update the instructions over time.

Example output

Expect ready-to-commit Markdown for each layer. You get an organization-level instruction file with your compliance rules and approved libraries, repo-level files encoding architecture and naming for each [repo_type], personal-level guidance per [developer_role], explicit prohibitions on the [forbidden_patterns] you listed, framework-specific sections for [frameworks_used], test instructions reflecting [test_conventions], and a quarterly review checklist. Each block is meant to be dropped into the appropriate Copilot custom-instructions location, so the setup is genuinely deployable rather than theoretical.

Pro tips

  • Make [compliance_rules] specific and verifiable, such as PCI-DSS for payment code, so Copilot has concrete constraints rather than vague guidance.
  • List real anti-patterns in [forbidden_patterns] like hardcoded secrets or SQL string concatenation; discouraging them at the instruction level beats audit-time cleanup.
  • Keep repo-level rules genuinely repo-specific in [repo_type]; duplicating org-level rules just adds noise that dilutes the important parts.
  • Name your actual stack in [frameworks_used] so the idiomatic guidance matches what you ship rather than a generic default.
  • Treat instructions as living documents and use the quarterly checklist, because standards and forbidden patterns drift over time.
  • Remember instructions guide Copilot rather than enforce it, so pair them with linting and review for the rules that truly must hold.

Frequently Asked Questions

Do custom instructions guarantee Copilot will never suggest a forbidden pattern?
No. Instructions strongly bias suggestions toward your standards and away from listed `[forbidden_patterns]`, but they are guidance, not a hard gate. You should still pair them with linters and code review to actually enforce security-critical rules at merge time.
Why use three layers instead of one instruction file?
Because concerns differ by scope. Org-level rules carry compliance and security everywhere, repo-level rules carry architecture and naming for `[repo_type]`, and personal-level rules carry individual style. Layering keeps each instruction set focused and avoids one giant file that nobody maintains.
Can it enforce our testing conventions on generated tests?
Yes. One step writes instructions so Copilot follows the conventions you set in `[test_conventions]`, like Given-When-Then naming or mocking external services. This keeps AI-generated tests consistent with hand-written ones across the team.
How often should we revisit these instructions?
The prompt includes a quarterly review checklist, which is a sensible cadence. Standards, approved libraries, and forbidden patterns change as your stack evolves, so treating the instructions as living documents prevents Copilot from enforcing rules that are no longer current.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in GitHub Copilot Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support