Parent
#1710
Question
The user wants a middle ground on approvals: richer than exec-style flags-only, not necessarily today's full interactive RPC bridge. What policy is acceptable for v1 on each candidate transport?
Context per option: codex exec has no mid-run approvals, only sandbox/bypass flags; codex mcp-server approval semantics are unverified (see the mcp-server research ticket); the own-the-loop path makes approval policy entirely ours to design (easiest place for a real middle ground).
Grill on: which action classes may run unattended (reads, workspace writes), which must pause for the user (network, outside-workspace writes, destructive commands, git mutations), and whether policy is per-turn, per-thread, or global.
Answer
Recorded on resolution: the approval policy matrix for v1, stated transport-agnostically where possible.
Parent
#1710
Question
The user wants a middle ground on approvals: richer than exec-style flags-only, not necessarily today's full interactive RPC bridge. What policy is acceptable for v1 on each candidate transport?
Context per option:
codex exechas no mid-run approvals, only sandbox/bypass flags;codex mcp-serverapproval semantics are unverified (see the mcp-server research ticket); the own-the-loop path makes approval policy entirely ours to design (easiest place for a real middle ground).Grill on: which action classes may run unattended (reads, workspace writes), which must pause for the user (network, outside-workspace writes, destructive commands, git mutations), and whether policy is per-turn, per-thread, or global.
Answer
Recorded on resolution: the approval policy matrix for v1, stated transport-agnostically where possible.