Sandbox & Approvals — CodexHow
Codex's sandbox and approval settings are two independent axes, not one dial — what it's allowed to touch, and what it has to ask permission for first. This section explains both, exactly as published, plus the presets that combine them for common cases: safe read-only browsing, a locked-down CI profile, and auto-review for eligible approvals. Get these two settings confused and you'll either grant more access than you meant to or get interrupted far more than you need to be.
Read the two "explained" guides first if you're new to this — sandbox mode and approval mode really are separate settings, and most of the confusion in the more specific guides that follow comes from treating them as one.
The Three Sandbox Modes, Explained
The Three Approval Modes, Explained
Setting Up a Read-Only CI Profile
Why Workspace-write Still Blocks Network Access
What Protected Paths Actually Protect
Trusting a New Project Directory
Configuring Auto-Review for Eligible Approvals
When to Use Danger-full-access, and When Not To
Approving a Destructive Tool Call Safely
Running Codex in a Locked-Down Container
Combining Sandbox and Approval Flags Correctly
Auditing What Codex Touched After a Session