Codex Permission Setup: Choosing a Folder, Approvals, and Network Access
Learn what Ask for approval actually allows in Codex, then use a beginner checklist to verify the folder boundary, file edits, and network access.
When people first use Codex, they often want to open every permission immediately: “Otherwise, will it be able to do anything?”
Reverse the question. Your first exercise should prove that the working method helps you—not that the tool can reach everything on your computer. Give it a small boundary and a low-risk task. When a specific action genuinely needs more access, inspect that request before approving it.
Separate the four choices you are making
OpenAI describes two layers of control. The sandbox sets the technical boundary for what Codex can access. Approval settings determine when it must stop and ask before particular actions. OpenAI recommends starting with Ask for approval for most work.
One detail matters: Ask for approval is not the same as read-only. In that mode, Codex can usually read and write files in the current workspace and run routine local commands. It asks before network access or work outside the workspace. Do not infer edit behavior from the label alone.
Your first setup therefore answers four questions:
| Choice | Beginner question |
|---|---|
| Folder | What is the smallest folder this task needs, and which files am I willing to expose? |
| File changes | Does the task need an edit, or can I begin with reading and recommendations? |
| Network | Does this task actually need online information, and do I know which source is required? |
| Approval | Which actions happen directly in this mode, and which actions stop for my confirmation? |
A smaller first exercise is easier to understand
Start with these constraints:
- Create a dedicated practice folder containing only public, self-written, or non-sensitive material.
- Confirm that the permission mode is
Ask for approval; do not chooseFull accessfor the first exercise. Full access expands what Codex can reach and may remove individual approval stops. - If you only want observation and your environment offers a
read-onlymode, use it. If that option is unavailable, work from a disposable copy and explicitly request no edits—but remember that a written request is not a technical permission lock. - Keep network access off at first. If Codex later needs the network, more files, or another permission, inspect what it plans to do and why before approving it.
This does not mean every task must stay restricted forever. Expand access only when the task requires it, you understand the expected change, and you know how to stop or recover.
When should you pause?
Pause if Codex asks to reach a folder you did not choose, run an action you cannot explain, or send real work material to an external service. Do not approve merely to avoid interrupting the flow.
Ask: “What will this step do? Which files can it touch? Why is network access required?” If the answer remains unclear, stop. Stopping is not a failed task. It is evidence that you are keeping the tool inside a boundary you can understand.
Practice: complete your initial Codex setup checklist
Practice folder:
The one task I want to do:
Permission mode shown on screen:
Can this mode edit files in the workspace? yes / no / unsure
Is network access enabled? yes / no / unsure
Which actions will ask me first:
If I do not understand, I will: ask / stop / get help
Acceptance check
Do not stop after writing the settings you want. Return to the interface and verify the folder, permission mode, and network state that are actually selected. You have completed the exercise when you can point to those three settings and explain which actions may happen directly, which require approval, and when you will stop.
Later lessons will use this checklist when you hand a low-risk task to AI. When a real job involves company data, accounts, or sharing permissions, you will also need a separate data-and-authority check.
Official references
The sandbox, approval, and network descriptions above are based on OpenAI's official documentation. Available modes can differ by account, platform, and organization. The checklist is Aaron's beginner practice method, not legal, security, or data-governance advice.