Blog · October 10, 2026 · 8 min read · by Vilva Athiban P B

Why Codex CLI Asks for Permission Every Time, and How to Tune the Sandbox and Approval Policy Without Going Full Access

You give Codex a task, walk away, and come back to find it has been sitting on a prompt for twenty minutes: "Codex wants to runnpm test, allow?" Approve it, and three steps later there is another one. If Codex CLI seems to ask for permission every time, that is not a bug and it is not random. It is the result of two settings, the sandbox and the approval policy, and once you understand what each one controls you can decide exactly how much Codex gets to do on its own.

This guide explains why the prompts appear, what the current permission modes mean, the config.toml keys and CLI flags behind them, the ways to cut the prompts down without removing the guard rails, and how to make sure you actually see the prompts that remain. It is based on the current Codex documentation; where a value has been retired we say so, because a lot of older blog posts still quote it.

Two settings, not one

Codex separates what it is physically able to touch from when it stops to ask. The sandbox answers the first question: which files it can write and whether it has network access. The approval policy answers the second: when an action falls outside what the sandbox allows, does Codex pause and ask you, hand the request to an automatic reviewer, or refuse? A prompt is what happens when an action crosses the sandbox boundary and the policy says "ask".

That framing explains the most common complaint. The default sandbox for a version-controlled folder is workspace-write: Codex can edit files inside your project but has no network access unless you enable it, and cannot write outside the workspace. So every npm install, every curl, every git push, and every write to a file outside the repo crosses the boundary and triggers an approval. Nothing is wrong; the sandbox is doing its job, and the policy is doing what you (implicitly) asked.

The sandbox modes

  • read-only: Codex can read files and run commands inside a read-only sandbox. It may start here until you trust the working directory, either through the onboarding prompt or /permissions.
  • workspace-write: the default for version-controlled folders. Writes are limited to the workspace and network access is off unless enabled.
  • danger-full-access: no sandbox at all. The documentation marks it as not recommended, and the flag that turns it on has a name designed to make you think twice: --dangerously-bypass-approvals-and-sandbox (alias --yolo).

You set the mode with the --sandbox flag on the command line or sandbox_mode in ~/.codex/config.toml.

The approval policy

  • on-request: commands the sandbox allows run without asking; actions beyond the sandbox can require approval. This is the setting behind the recommended Auto preset.
  • never: Codex never prompts. It still works inside whatever sandbox mode you chose, so never plus read-only is a legitimate combination for CI. Pass it as --ask-for-approval never or -a never.
  • untrusted: retired. If an old config, profile or script still contains approval_policy = "untrusted", remove it; the docs warn the client may fail to start.
  • Granular: approval_policy = { granular = { ... } } keeps the categories you choose interactive and automatically rejects the rest. The categories are sandbox_approval, rules, mcp_elicitations, request_permissions and skill_approval.

The named modes in /permissions

In the CLI, /permissions opens a picker that wraps those settings into presets. The current documentation describes three plus a custom option:

  • Ask for approval: always ask to edit external files and use the internet. Sandbox stays workspace-write. The docs recommend starting here.
  • Approve for me: the same sandbox and an on-request policy, but eligible approval requests go to an automatic reviewer instead of to you (approvals_reviewer = "auto_review"; the default is "user"). Changing the reviewer does not widen the sandbox; it only changes who answers the question.
  • Full access: unrestricted access to the internet and any file on your computer.
  • Custom: whatever your config.toml says.

Which of these you see depends on the app version, the environment and any organisation-managed requirements, which can restrict the "Ask for approval" option. In the desktop app and IDE extension the same control sits below the composer.

What actually triggers a prompt

According to the approvals documentation, Codex pauses for: editing files outside the workspace; running commands that need network access; any action that leaves the sandbox or runs outside a trusted command set; app and MCP tool calls that advertise side effects; and destructive tool calls, when the tool annotates itself as destructive. If you are being asked constantly, one of those is firing constantly, and the fix is to address that category rather than to switch everything off.

Five ways to get fewer prompts without going full access

  1. Use the Auto preset explicitly. codex --sandbox workspace-write --ask-for-approval on-request. Inside the workspace Codex stops asking; outside it still does.
  2. Turn on network access for the workspace if package installs and API calls are what keep interrupting you:
    [sandbox_workspace_write]
    network_access = true
    The optional network_proxy feature can then constrain which domains that traffic may reach; it does not grant network access by itself.
  3. Add execution-policy rules for commands you always trust, so npm test or make lint run without a question while anything unexpected still asks.
  4. Route approvals to the automatic reviewer with approvals_reviewer = "auto_review" (the "Approve for me" mode) for sessions where you are not at the keyboard. If the option is missing or greyed out, the docs have a troubleshooting section for that.
  5. Save the combination as a profile and start with codex --profile name, so a permissive setup for a scratch repo never leaks into your production checkout.

One more cause worth checking: a project marked trust_level = "untrusted" under [projects."/path/to/project"] requires approval for commands unless an execution-policy rule allows them, and also disables project-local configuration. If a single repository asks far more than the others, look there first.

When you should keep the prompts

The prompts are the product working. "Ask for approval" is the recommended starting point precisely because an agent that can reach the network and write anywhere is an agent you have to supervise in real time. Keep the prompts for repositories with secrets, for anything that deploys, and for the first week with a new codebase, when you do not yet know what the agent will try. Use never only where you have accepted the risk, such as a read-only CI job, and treat --yolo as what its name suggests.

Make sure you see the prompt when it comes

Fewer prompts means the ones left are the important ones, and the failure mode flips: instead of being interrupted too often, you miss the single interruption that mattered and the agent waits silently for an hour. Codex can play a sound or send a notification when it needs you; we covered the built-in options in the Codex CLI notifications guide and the terminal-bell approach in making Codex ding when a response is needed. If you run Codex alongside Claude Code, the comparison of their notification systems explains why the two behave differently when they stop.

Keep reading

Desk Exercises for Programmers: 15 Moves to Do While Your AI Agent Codes

7 min read

Exercise While Coding: Turn Claude Code Wait Time Into Micro-Workouts

7 min read

Claude Code Notch Notifications on Mac: See When Claude Is Done Without Watching the Terminal

7 min read

Claude Code Tips and Tricks: 12 Ways to Use Claude Code Effectively

8 min read

Claude Code Multiple Sessions: How to Run Agents in Parallel Without Losing Track

6 min read

A Claude Code Workflow That Doesn't Involve Watching the Terminal

5 min read

Claude Code Hooks: A Practical Guide to Automating Your Agent Workflow

7 min read

Claude Code Auto Mode: Fewer Permission Prompts Without Living Dangerously

7 min read

Claude Code Subagents: How to Delegate Work to Specialized Agents

7 min read

Claude Code Context Management: Treat the Context Window Like a Budget

6 min read

Per-Subagent Model Selection: Route the Grunt Work Down, Keep the Judgment Up Top

7 min read

Skills and Plugins: How to Teach Claude Code Your Way of Working

7 min read

Claude Code Background Tasks: Run Long Commands Without Blocking Your Session

6 min read

Codex CLI Notifications: How to Get a Ding When Codex Is Done or Needs Input

7 min read

Cursor Notification When Done: Every Way to Get Notified When Cursor Finishes

6 min read

Claude Code Notifications: How to Get Notified When Claude Code Finishes or Needs Your Input

6 min read

Want to Be Notified When Claude Responds? How Claude Notifications Work on Web, Desktop, and Mobile

5 min read

Claude Code Notification Scripts: Copy-Paste Recipes for Every Platform

6 min read

Get a Ding the Moment Codex Needs Your Response

6 min read

Get Notified the Moment Claude Code Is Waiting for Your Input

6 min read

“Notifications Are Turned Off for Claude” — Here Is the Fix

6 min read

Codex Sound When Done: Make Codex CLI Play a Sound When It Finishes

6 min read

terminal-notifier + Claude Code: Native macOS Alerts When Your Agent Finishes

6 min read

Gemini CLI Notifications: How to Get a Sound or Alert When Gemini Finishes

6 min read

Get Claude Code Notifications on Your Phone

6 min read

Claude Code Remote Control, Explained

7 min read

preferredNotifChannel: Claude Code's Built-In Notification Setting

6 min read

Claude Code Notifications in tmux and Over SSH

7 min read

Claude Code Effort Levels: Why Your Setting Keeps Getting Ignored

8 min read

Codex vs Claude Code Notifications: How Each One Tells You It Is Done

8 min read

Claude Code Notifications Not Working: A Diagnostic Checklist

10 min read

Claude Code Notifications Inside Your Editor's Terminal

7 min read

CLAUDE_CODE_DISABLE_BACKGROUND_TASKS Explained

7 min read

CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP Explained

8 min read

Cursor Alerts Explained: Every Alert Cursor Raises, and How to Control Them

7 min read

Claude Code Environment Variables: The Groups That Actually Matter

10 min read

Claude Code Notifications on WSL and Windows

9 min read

Claude Code Checkpoints and /rewind

8 min read

Claude Remote Control: How It Works, Turning It Off, and Auto Mode

7 min read

Claude Code /loop: Poll a Deploy, Babysit a PR, and Get Told When It's Done

8 min read

Setting Up NotchFit With OpenAI Codex CLI: Hooks, $notchfit-plan, and the Daily Flow

7 min read

Claude Mods Explained: What the New Plugin Layer Can Do, and How to Turn On 'You Should Know'

9 min read

NotchFit vs Mac Break Reminder Apps: A Clock or a Signal From Your Coding Agent?

8 min read

Claude Code Headless Mode: Running claude -p in Scripts and CI, and the Three Signals That It Finished

10 min read

Building a Movement Habit at a Desk: Use the Agent Run as the Cue, One Set as the Unit, and Streaks Carefully

8 min read

Claude Code MCP Servers Explained: Adding Servers, Choosing a Scope, Handling Secrets, and Why Long Tool Calls Go to the Background

10 min read

/notchfit:plan Explained: How Claude Code or Codex Writes a Weekly Workout Plan the Notch Can Actually Run

8 min read

Claude Code Spinner Verbs Explained: What “Pondering” and “Brewing” Mean, How to Change Them, and Why You Should Stop Watching the Spinner

7 min read

Why NotchFit's Done and Permission Alerts Wait Until Your Set Ends, When That Costs You, and How to Turn the Workout Off

7 min read

How to Resume a Claude Code Session: --continue vs --resume, Naming Sessions, the Session Picker, Branching, and What Comes Back

9 min read

NotchFit on a Mac Without a Notch: How Pill Mode Works on Mac mini, iMac, Mac Studio and a MacBook With the Lid Closed

6 min read

How to Run a Claude Code Session in the Background: /background, claude --bg, Agent View, and Getting Back to It

9 min read

What a Notch App Can See: NotchFit's Local-First Design, What the Claude Code and Codex Hooks Send, and What Stays on Your Mac

7 min read

What to Do While Claude Code or Codex Works: A Simple Protocol for the Two-to-Twenty-Minute Gap in Every Agent Run

7 min read