Codex permission settings
Codex App can set three permission modes:
| Permission Mode | What it can do | Will it ask you | Suitable scenarios |
|---|---|---|---|
| Default Permissions | Can read and write the current project and execute basic commands | Will ask when encountering dangerous operations | Daily development (recommended) |
| Automatic Review | AI automatically assesses risk, and low-risk actions are executed directly | Ask only for high-risk actions | Improve Efficiency |
| Full access permissions | Almost equivalent to handing over control of the computer to Codex | Basically doesn't ask | Advanced users / isolated environment |

These three permission modes of the Codex App essentially control:
How much the AI can actually do on your computer, and whether it needs to ask you first.
1. Default permissions (recommended for regular users)
This is the safest and most balanced mode.
Codex can:
- Read project code
- Modify files in the current working directory
- Execute test commands
- Install some dependencies
But the following will usually pop up to ask you first:
- Access files outside the project directory
- Delete large numbers of files
- Network request
- System-level commands
- High-risk shell operations
You can understand it as:
"AI is like an intern; before doing many things, it has to ask for your approval."
Suitable for:
- Daily coding
- Learning projects
- Regular frontend development
- Users unfamiliar with AI agents
2. Automatic review (efficiency mode)
This is the mode many people like the most now.
Core logic:
The AI first judges the risk itself.
For example:
Low-risk operations
Execute directly:
- Modify a few code files
- Run lint
- npm test
- Format code
- Small-scale refactoring
High-risk operations
Will still ask you:
- rm deletion
- System directory operations
- Network access
- Database modification
- Large-scale file changes
So it has far fewer pop-ups than default permissions.
You can understand it as:
There's an automatic reviewer next to the AI.
Suitable for:
- High-frequency development
- Lots of repetitive modifications
- Long-running agent workflows
- Don't want to keep clicking "Allow"
3. Full access permission (dangerous mode)
This mode is the most powerful.
Codex basically gets:
- Full filesystem access
- Network access
- Arbitrary command execution
- Cross-directory operations
- No more frequent asking
Theoretically it can even:
- Delete files
- Modify system configuration
- git push
- ssh
- Operate database
- Call external APIs
Essentially close to:
sudo + 自动化 Agent
Many advanced users do use it this way long-term.
But the risks are real:
Some people have already:
- Deleted the wrong directory
- Wiped the disk
- PowerShell command misoperation
- Be affected by erroneous scripts
Some even lost 1.5TB of data.
So this mode is more suitable for:
- Docker
- Virtual machine
- Temporary environment
- CI/CD
- Sandbox development machine
Not very suitable for:
- Main work computer
- Machines with important data
One-sentence summary
| Mode | Analogy |
|---|---|
| Default Permissions | AI intern |
| Automatic Review | AI engineers + automated risk control |
| Full access permissions | Give AI sudo permissions |
Practical advice
Regular developers:
Default permission or automatic review
It's enough already.
Only when:
- Large-scale automation
- Multi-repository coordination
- Long-running autonomous agent
- Local sandbox environment
Only then is it recommended to enable full access permissions.
Many experienced users' current habit is actually:
平时自动审查( Auto Review ) 需要时临时切完全访问( Full Access ) 做完再切回来
This is the most reasonable workflow at present.
other extensions