Codex Permissions
Codex permissions are designed to balance speed and safety.
Two Independent Dimensions
The two main dimensions are:
- Sandbox mode: what Codex can access.
- Approval policy: when Codex must ask before acting.
Desktop App Permission Presets
The app commonly exposes presets such as:
- Read-only: inspect and plan without writing.
- Auto: make ordinary project edits while asking for sensitive actions.
- Full access: broader local access for trusted workflows.
sandbox_mode Values
Common sandbox modes include read-only, workspace-write, and danger/full-access style modes. Use the narrowest mode that still lets the task finish.
approval_policy Values
Approval policy controls when Codex asks before running commands or using tools. Stricter policies are better for risky repos, production systems, or unfamiliar commands.
Network Access
Network access may be disabled or restricted depending on the environment. Enable it only when the task needs package downloads, live documentation, APIs, or external sites.
Common Combinations
About --yolo
--yolo-style full-access modes are convenient but risky. Use them only in trusted, disposable, or well-contained environments.
Debug Sandbox Blocks
If a command fails unexpectedly, check whether the sandbox blocked file access, network access, or process behavior.
Enterprise Baselines
Enterprise deployments can enforce managed policies so users cannot bypass required sandbox, approval, or rule settings.
Next Steps
Continue with AGENTS.md.