Codex (OpenAI)
What Codex’s own help pages, docs and terms said on 1 October 2026, by the same six questions we ask of every agent. We didn’t test it for this page. “Not documented” means we didn’t find it on the vendor’s pages; it doesn’t mean the feature is missing.
Coding agent
- Can you limit it?
- OS sandbox, network off
- Does it ask first?
- Asks to leave the sandbox
- Can you stop it?
- Stop locally
- Is there a record someone outside can check?
- Not documented
- What about sub-agents?
- Inherit the sandbox
- Can you test it yourself?
codex exec, MCP by URL
What the vendor’s pages say
Codex runs in an OS sandbox with three modes; by default, "network access turned off", and .git "is protected as read-only" (sandboxing). Its --yolo flag is listed as "No sandbox; no approvals (not recommended)" (approvals). "Subagents inherit your current sandbox policy" (subagents). OpenAI's governance page says "conversation visibility alone does not establish a complete record of local actions" (governance). Scripted runs use codex exec --json, and codex mcp add takes a URL (MCP). We didn't find how to cancel or roll back a cloud task.
Every statement above was checked on the vendor’s own page on 1 October 2026; each links to its source.
Run this test on yours
Delegus Check gives your agent a permission and a one-hour test server, then shows every action it tries and what was refused. It works today with agents that accept a custom MCP server, including Claude on any plan.
Corrections
Vendors and readers: if anything here is out of date, write to hello@delegus.ai and we’ll fix it. Each change is listed here with its date.
- 1 October 2026: first published. All vendor statements checked that day.