Codex Security and Enterprise Management

Codex provides multi-layered security mechanisms and enterprise management features to ensure data security and support team collaboration.


Security Mechanism Overview

Codex security design is divided into multiple layers:

TierMechanismFunction
Sandbox isolationSandbox modeRestrict file and command access scope
Approval policiesApproval PolicyControl confirmation before operation execution
Rule engineRulesDefine command execution permissions
Network controlNetwork Access SettingsRestrict external network access
Data protectionEnterprise featuresAudit logs, data residency

Sandbox mode

Sandbox is the core security mechanism of Codex, restricting the Agent's operational scope.

Three Sandbox Modes

ModeFile modificationCommand ExecutionNetwork accessApplicable scenarios
read-onlyDenyDenyDenyCode Review, Analysis
workspace-writeWorkspace onlyAllowedDenyDaily Development (Recommended)
danger-full-accessAllowedAllowedAllowedSpecial scenarios (use with caution)

Set Sandbox Mode

Sandbox configuration

# Specified in CLI
codex --sandbox read-only
codex --sandbox workspace-write
codex --sandbox danger-full-access

# Configuration File
[mycode4 type="toml"]
# ~/.codex/config.toml
sandbox = "workspace-write"
[/mycode4]

Sandbox boundaries

  • Workspace boundaries: workspace-write mode only allows modifying files within the project directory
  • Command boundaries: read-only prohibits all command execution
  • Network boundaries: by default, network access during the Agent phase is prohibited

It is recommended to use workspace-write mode by default, and only use danger-full-access when necessary.


Approval policy

Approval policies control the confirmation behavior before Codex executes operations.

Four Approval Modes

ModeBehaviorRisk Level
suggestOnly provide suggestions, do not execute any operationsMinimum
interactiveAsk for confirmation before sensitive operationsLow
auto-editAutomatically edit files, commands require confirmationMedium
full-autoAutomatically execute all operationsHigh

Set Approval Policy

Approval configuration

# CLI Designation
codex --approval-mode interactive

# Switch during session
/approval suggest
/approval auto-edit

# Configuration File
[mycode4 type="toml"]
approval_policy = "interactive"
[/mycode4]

Rules engine

Rules use the Starlark language to define command execution policies.

Rule types

RulesDescription
prefix_ruleMatch Command Prefix
glob_ruleMatch file path patterns

Decision types

DecisionBehavior
allowAutomatically Approve Execution
promptAsk User for Confirmation
forbiddenDeny execution

Rule examples

Rule definitions

# ~/.codex/rules/default.rules

# Allow Git commands
prefix_rule(
    pattern = ["git"],
    decision = "allow",
    justification = "Git commands are safe for version control"
)

# Allow npm install
prefix_rule(
    pattern = ["npm", "install"],
    decision = "allow",
    justification = "Package installation is expected"
)

# Deny deleting root directory
prefix_rule(
    pattern = ["rm", "-rf", "/"],
    decision = "forbidden",
    justification = "Prevent system damage"
)

# Ask about sudo commands
prefix_rule(
    pattern = ["sudo"],
    decision = "prompt",
    justification = "Elevated privileges need review"
)

Network Access Control

Controls Codex's network access capabilities to prevent data leakage.

Cloud Network Control

PhaseDefault accessDescription
Setup scriptsAllowedNeed to Download Dependencies
Agent executionDenyDisabled by default, can be enabled

Domain whitelist

Network configuration

# Preset whitelist
domain_allowlist = "common-dependencies"
# Includes: github.com, npmjs.com, pypi.org

# Custom domains
domain_allowlist = [
    "github.com",
    "api.mycompany.com"
]

# Restrict HTTP methods
allowed_methods = ["GET", "HEAD", "OPTIONS"]

Security risks

Risks of enabling Agent network access:

  • Prompt injection: obtaining instructions from malicious web pages
  • Data leakage: sending code or secrets externally
  • Malicious dependencies: downloading packages containing malicious code

Enable Agent network access only when necessary, and restrict it using a domain whitelist.


Enterprise Management Features

The Enterprise plan provides enterprise-grade security and management features.

Enterprise Features Overview

FeaturesDescription
SCIMAutomatic user provisioning
SAML SSOSingle Sign-On Integration
MFAMulti-factor authentication
EKMEnterprise Key Management
RBACRole-based access control
Audit LogsComplete Operation Logs
Data residencySpecify data storage region

Managed configuration

Enterprise administrators can push unified configurations.

Managed Configuration Priority

Configuration Merge Order:

  1. Managed configuration (enterprise deployment) - highest priority
  2. Project configuration (.codex/config.toml)
  3. User configuration (~/.codex/config.toml) — lowest priority

Managed Configuration Example

Enterprise Managed Configuration

# Enterprise-issued managed configuration

# Mandatory sandbox mode
sandbox = "workspace-write"

# Mandatory approval policy
approval_policy = "interactive"

# Disabled models
disabled_models = ["gpt-5.4-mini"]

# Network whitelist
domain_allowlist = ["github.com", "internal-api.company.com"]

# Audit configuration
audit_logging = true

Audit Logs

The Enterprise plan provides complete audit log functionality.

Log content

Record typesDescription
Session recordsCreation, modification, and deletion of each session
Tool callsDetailed information on file reads/writes and command execution
Model callsAPI calls, token usage
User actionsUser authentication, permission changes

Log access

Audit Logs

# Access audit logs via enterprise management panel

# Exportable as:
- JSON format
- CSV format
- SIEM system integration format

Data residency

Enterprise can specify data storage regions.

Residency options

RegionDescription
United StatesDefault region
EuropeGDPR compliance
Other regionsConfigure according to enterprise needs

Data residency settings require contacting the sales team for configuration.


Team management

User provisioning

SCIM configuration

# Automatically manage users via IdP (e.g., Okta, Azure AD)

# Supported operations:
- Automatically create users
- Automatically update user attributes
- Automatically disable/Delete users

Role permissions

RolePermissions
AdminFull Administrative Permissions
MemberStandard Usage Permissions
ViewerRead-only permissions

Security Best Practices

Daily use

  • Use workspace-write sandbox mode by default.
  • Sensitive operations use interactive approval mode
  • Regularly review Rules configuration
  • API keys stored as Secrets

Enterprise deployment

  • Enable SAML SSO and MFA
  • Configure managed configuration for unified policies
  • Enable audit logging
  • Configure data residency based on compliance requirements
  • Use domain whitelist to restrict network access

FAQ

Q: How to prevent Codex from deleting important files?

Use read-only or workspace-write sandbox mode, and add Rules to prohibit deletion commands.

Q: How do enterprises configure uniformly?

Using the managed configuration feature, enterprise administrators can deploy unified configurations that override user settings.

Q: What information is included in audit logs?

Contains a complete record of all sessions, tool calls, model calls, and user operations.

Q: How to handle sensitive data?

Use Secrets to store sensitive information; it is only available in setup scripts and automatically removed during the Agent phase.

other extensions