Codex Security and Enterprise Management
Codex provides multi-layered security mechanisms and enterprise management features to ensure data security and support team collaboration.
Security Mechanism Overview
Codex security design is divided into multiple layers:
| Tier | Mechanism | Function |
|---|---|---|
| Sandbox isolation | Sandbox mode | Restrict file and command access scope |
| Approval policies | Approval Policy | Control confirmation before operation execution |
| Rule engine | Rules | Define command execution permissions |
| Network control | Network Access Settings | Restrict external network access |
| Data protection | Enterprise features | Audit logs, data residency |
Sandbox mode
Sandbox is the core security mechanism of Codex, restricting the Agent's operational scope.
Three Sandbox Modes
| Mode | File modification | Command Execution | Network access | Applicable scenarios |
|---|---|---|---|---|
| read-only | Deny | Deny | Deny | Code Review, Analysis |
| workspace-write | Workspace only | Allowed | Deny | Daily Development (Recommended) |
| danger-full-access | Allowed | Allowed | Allowed | Special scenarios (use with caution) |
Set Sandbox Mode
Sandbox configuration
codex --sandbox read-only
codex --sandbox workspace-write
codex --sandbox danger-full-access
# Configuration File
[mycode4 type="toml"]
# ~/.codex/config.toml
sandbox = "workspace-write"
[/mycode4]
Sandbox boundaries
- Workspace boundaries: workspace-write mode only allows modifying files within the project directory
- Command boundaries: read-only prohibits all command execution
- Network boundaries: by default, network access during the Agent phase is prohibited
It is recommended to use workspace-write mode by default, and only use danger-full-access when necessary.
Approval policy
Approval policies control the confirmation behavior before Codex executes operations.
Four Approval Modes
| Mode | Behavior | Risk Level |
|---|---|---|
| suggest | Only provide suggestions, do not execute any operations | Minimum |
| interactive | Ask for confirmation before sensitive operations | Low |
| auto-edit | Automatically edit files, commands require confirmation | Medium |
| full-auto | Automatically execute all operations | High |
Set Approval Policy
Approval configuration
codex --approval-mode interactive
# Switch during session
/approval suggest
/approval auto-edit
# Configuration File
[mycode4 type="toml"]
approval_policy = "interactive"
[/mycode4]
Rules engine
Rules use the Starlark language to define command execution policies.
Rule types
| Rules | Description |
|---|---|
| prefix_rule | Match Command Prefix |
| glob_rule | Match file path patterns |
Decision types
| Decision | Behavior |
|---|---|
allow | Automatically Approve Execution |
prompt | Ask User for Confirmation |
forbidden | Deny execution |
Rule examples
Rule definitions
# Allow Git commands
prefix_rule(
pattern = ["git"],
decision = "allow",
justification = "Git commands are safe for version control"
)
# Allow npm install
prefix_rule(
pattern = ["npm", "install"],
decision = "allow",
justification = "Package installation is expected"
)
# Deny deleting root directory
prefix_rule(
pattern = ["rm", "-rf", "/"],
decision = "forbidden",
justification = "Prevent system damage"
)
# Ask about sudo commands
prefix_rule(
pattern = ["sudo"],
decision = "prompt",
justification = "Elevated privileges need review"
)
Network Access Control
Controls Codex's network access capabilities to prevent data leakage.
Cloud Network Control
| Phase | Default access | Description |
|---|---|---|
| Setup scripts | Allowed | Need to Download Dependencies |
| Agent execution | Deny | Disabled by default, can be enabled |
Domain whitelist
Network configuration
domain_allowlist = "common-dependencies"
# Includes: github.com, npmjs.com, pypi.org
# Custom domains
domain_allowlist = [
"github.com",
"api.mycompany.com"
]
# Restrict HTTP methods
allowed_methods = ["GET", "HEAD", "OPTIONS"]
Security risks
Risks of enabling Agent network access:
- Prompt injection: obtaining instructions from malicious web pages
- Data leakage: sending code or secrets externally
- Malicious dependencies: downloading packages containing malicious code
Enable Agent network access only when necessary, and restrict it using a domain whitelist.
Enterprise Management Features
The Enterprise plan provides enterprise-grade security and management features.
Enterprise Features Overview
| Features | Description |
|---|---|
| SCIM | Automatic user provisioning |
| SAML SSO | Single Sign-On Integration |
| MFA | Multi-factor authentication |
| EKM | Enterprise Key Management |
| RBAC | Role-based access control |
| Audit Logs | Complete Operation Logs |
| Data residency | Specify data storage region |
Managed configuration
Enterprise administrators can push unified configurations.
Managed Configuration Priority
Configuration Merge Order:
- Managed configuration (enterprise deployment) - highest priority
- Project configuration (.codex/config.toml)
- User configuration (~/.codex/config.toml) — lowest priority
Managed Configuration Example
Enterprise Managed Configuration
# Mandatory sandbox mode
sandbox = "workspace-write"
# Mandatory approval policy
approval_policy = "interactive"
# Disabled models
disabled_models = ["gpt-5.4-mini"]
# Network whitelist
domain_allowlist = ["github.com", "internal-api.company.com"]
# Audit configuration
audit_logging = true
Audit Logs
The Enterprise plan provides complete audit log functionality.
Log content
| Record types | Description |
|---|---|
| Session records | Creation, modification, and deletion of each session |
| Tool calls | Detailed information on file reads/writes and command execution |
| Model calls | API calls, token usage |
| User actions | User authentication, permission changes |
Log access
Audit Logs
# Exportable as:
- JSON format
- CSV format
- SIEM system integration format
Data residency
Enterprise can specify data storage regions.
Residency options
| Region | Description |
|---|---|
| United States | Default region |
| Europe | GDPR compliance |
| Other regions | Configure according to enterprise needs |
Data residency settings require contacting the sales team for configuration.
Team management
User provisioning
SCIM configuration
# Supported operations:
- Automatically create users
- Automatically update user attributes
- Automatically disable/Delete users
Role permissions
| Role | Permissions |
|---|---|
| Admin | Full Administrative Permissions |
| Member | Standard Usage Permissions |
| Viewer | Read-only permissions |
Security Best Practices
Daily use
- Use workspace-write sandbox mode by default.
- Sensitive operations use interactive approval mode
- Regularly review Rules configuration
- API keys stored as Secrets
Enterprise deployment
- Enable SAML SSO and MFA
- Configure managed configuration for unified policies
- Enable audit logging
- Configure data residency based on compliance requirements
- Use domain whitelist to restrict network access
FAQ
Q: How to prevent Codex from deleting important files?
Use read-only or workspace-write sandbox mode, and add Rules to prohibit deletion commands.
Q: How do enterprises configure uniformly?
Using the managed configuration feature, enterprise administrators can deploy unified configurations that override user settings.
Q: What information is included in audit logs?
Contains a complete record of all sessions, tool calls, model calls, and user operations.
Q: How to handle sensitive data?
Use Secrets to store sensitive information; it is only available in setup scripts and automatically removed during the Agent phase.
other extensions