
Codex CLI approval policy: untrusted, on-request, never and the granular policy
In the *--full-auto* piece I covered the sandbox; here I turn the other dial: the **approval policy**, meaning when Codex stops and asks my permission before acting. The three values — *untrusted*, *on-request*, *never* — sound self-explanatory but they are not: *untrusted* only auto-runs ==the reads known to be safe==, and *never* does not switch off the sandbox at all. I also cover the two options quick guides skip: the granular per-category policy and Auto-review, which routes approval requests to an automatic reviewer instead of me.




















