Codex Security & Enterprise Management

Security for Codex is built from multiple layers: permissions, rules, hooks, managed config, and review.

1. Defense In Depth

Use sandboxing, approval policies, command rules, hooks, and human review together.

2. Personal Safety Practices

Use workspace-write with approvals for sensitive commands in normal local development.

Be Careful With --yolo

Full-access modes are powerful and should be reserved for trusted, contained environments.

Network

Enable network access only when needed. Avoid sending secrets to external systems.

Computer Use

Avoid entering credentials or operating production systems unless the task explicitly requires it and the environment is safe.

3. Enterprise Managed requirements.toml

Managed requirements can enforce models, permissions, command rules, and other policy baselines.

4. Rules And Hooks Rollout

Use rules for command policy and hooks for lifecycle checks. Version and audit them.

5. MCP And Plugin Governance

Approve MCP servers and plugins before team-wide use. Review what data and actions they expose.

6. Automation And CI Safety

CI and recurring automations should run with narrow credentials and clear output expectations.

7. Audit And Observability

Keep logs, commits, PRs, and automation output available for review.

8. Security Checklist

  • Use the narrowest useful permissions.
  • Keep secrets out of prompts and logs.
  • Review diffs before merging.
  • Pin critical plugins and MCP servers.
  • Document team conventions in AGENTS.md.

Next Steps

Continue with Practical Examples.

评论