GPT WORLD / INDEPENDENT CODEX FIELD MANUAL Source review · 2026-07-26

CODEX CONTROL MAP / 08 SURFACES

Map each Codex surface to its control.

Codex becomes dependable when every capability has a durable configuration surface, a clear authority boundary, and observable completion evidence.

Codex surfaceUse it forControl boundaryEvidence before trust
01Prompt + working directoryDefine the current task and repository contextGoal, context, constraints, done conditionCorrect root and a reproducible task
02Sandbox + approvalsBound generated commands and escalationsFilesystem, network, approval policy/status plus a least-privilege run
03AGENTS.mdShare durable repository guidanceGlobal, root, nested instruction chainLoaded sources and executable checks
04config.tomlSet user, project, and profile defaultsPrecedence and trusted-project gateEffective config inspected in-session
05MCPConnect external tools and contextTransport, auth, enabled tools, approvalsIdentity, failure path, narrow tool list
06Skills + pluginsPackage and distribute repeatable workflowsTrigger, scripts, dependencies, install scopePositive and negative trigger tests
07SubagentsParallelize independent evidence workParent permissions, task ownership, result contractThread results with no write collision
08codex exec + CIRun stable workflows non-interactivelySandbox, credentials, output schema, trigger trustMachine-readable output and isolated writes