Codex Permissions

Codex permissions are designed to balance speed and safety.

Two Independent Dimensions

The two main dimensions are:

  • Sandbox mode: what Codex can access.
  • Approval policy: when Codex must ask before acting.

Desktop App Permission Presets

The app commonly exposes presets such as:

  • Read-only: inspect and plan without writing.
  • Auto: make ordinary project edits while asking for sensitive actions.
  • Full access: broader local access for trusted workflows.

sandbox_mode Values

Common sandbox modes include read-only, workspace-write, and danger/full-access style modes. Use the narrowest mode that still lets the task finish.

sandbox_mode = "workspace-write"

approval_policy Values

Approval policy controls when Codex asks before running commands or using tools. Stricter policies are better for risky repos, production systems, or unfamiliar commands.

Network Access

Network access may be disabled or restricted depending on the environment. Enable it only when the task needs package downloads, live documentation, APIs, or external sites.

Common Combinations

ScenarioSuggested Setup
Planning or reviewRead-only + ask before writes
Normal local developmentWorkspace write + ask for risky commands
CI automationNarrow workspace + non-interactive safe commands
Throwaway prototypeBroader access, but still avoid secrets

About --yolo

--yolo-style full-access modes are convenient but risky. Use them only in trusted, disposable, or well-contained environments.

Debug Sandbox Blocks

If a command fails unexpectedly, check whether the sandbox blocked file access, network access, or process behavior.

Enterprise Baselines

Enterprise deployments can enforce managed policies so users cannot bypass required sandbox, approval, or rule settings.

Next Steps

Continue with AGENTS.md.

评论