Codex Security & Enterprise Management
Security for Codex is built from multiple layers: permissions, rules, hooks, managed config, and review.
1. Defense In Depth
Use sandboxing, approval policies, command rules, hooks, and human review together.
2. Personal Safety Practices
Recommended Default
Use workspace-write with approvals for sensitive commands in normal local development.
Be Careful With --yolo
Full-access modes are powerful and should be reserved for trusted, contained environments.
Network
Enable network access only when needed. Avoid sending secrets to external systems.
Computer Use
Avoid entering credentials or operating production systems unless the task explicitly requires it and the environment is safe.
3. Enterprise Managed requirements.toml
Managed requirements can enforce models, permissions, command rules, and other policy baselines.
4. Rules And Hooks Rollout
Use rules for command policy and hooks for lifecycle checks. Version and audit them.
5. MCP And Plugin Governance
Approve MCP servers and plugins before team-wide use. Review what data and actions they expose.
6. Automation And CI Safety
CI and recurring automations should run with narrow credentials and clear output expectations.
7. Audit And Observability
Keep logs, commits, PRs, and automation output available for review.
8. Security Checklist
- Use the narrowest useful permissions.
- Keep secrets out of prompts and logs.
- Review diffs before merging.
- Pin critical plugins and MCP servers.
- Document team conventions in
AGENTS.md.
Next Steps
Continue with Practical Examples.