CODEX CONTROL MAP / 08 SURFACES
Codex の各 surface を control に対応させる。
すべての capability に durable configuration surface、明確な authority boundary、observable completion evidence があって初めて Codex は信頼できます。
Codex surface用途Control boundary信頼する前の証拠
01Prompt + working directory現在の task と repository context を定義Goal、context、constraints、done condition正しい root と再現可能な task
02Sandbox + approvalsGenerated commands と escalation を制限Filesystem、network、approval policy/status と least-privilege run
03AGENTS.mdDurable repository guidance を共有Global、root、nested instruction chainLoaded sources と実行可能な checks
04config.tomlUser、project、profile defaults を設定Precedence と trusted-project gateSession 内で effective config を確認
05MCP外部 tools と context を接続Transport、auth、enabled tools、approvalsIdentity、failure path、狭い tool list
06Skills + pluginsRepeatable workflows を package / distributeTrigger、scripts、dependencies、install scopePositive / negative trigger tests
07SubagentsIndependent evidence work を並列化Parent permissions、task ownership、result contractWrite collision のない thread results
08codex exec + CIStable workflows を non-interactive 実行Sandbox、credentials、output schema、trigger trustMachine-readable output と isolated writes