Skip to content

In Home directory Sandbox is set to 'workspace-write' instead of 'read-only' #10395

@kingtistel

Description

@kingtistel

What version of Codex is running?

codex-cli 0.93.0

What subscription do you have?

Business

Which model were you using?

gpt-5.2-codex

What platform is your computer?

Darwin 25.2.0 arm64 arm

What terminal emulator and version are you using (if applicable)?

iTerm2

What issue are you seeing?

When starting codex-cli in the Home directory -- or any directory not under version control -- after the first time, codex is started with Sandbox: workspace-write and Approval: untrusted instead of read-only / on-request.

Image

What steps can reproduce the bug?

  1. Start codex in Home directory -- or any directory not under version control -- for the first time,
  2. You're presented with a question to select the approval policy -- defaulted to require approval,
Image
  1. Accept the default,
  2. Check status with /status -- it shows Sandbox: read-only and Approval: on-request,
  3. Exit and relaunch codex
  4. Check status with /status -- it now shows Sandbox: workspace-write and Approval: untrusted.

What is the expected behavior?

Expected is that each time starting codex from Home directory or any directory not under version control:

  1. Be asked our approval selection,
    -OR-
  2. Start with the previously selected choice.
    (¿ How would we change our selection in this flow is chosen ?)

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    CLIIssues related to the Codex CLIbugSomething isn't workingsandboxIssues related to permissions or sandboxing

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions